Skip to main content

Vendor Code of Conduct

Last updated: May 31, 2026

Document owner: General Counsel and Head of Procurement
Policy steward: Third-Party Risk Management (TPRM) Program
Review cadence: Semiannual and before critical vendor onboarding updates
Effective date: 2026-05-31
Applies to: All suppliers, contractors, service providers, and sub-tier vendors supporting EthicPages
Primary contact: ethicpages+contact@invictosoft.com (subject: Vendor Code of Conduct)

Purpose and applicability

EthicPages depends on a network of vendors to operate responsibly, securely, and sustainably. This Vendor Code of Conduct defines minimum ethical, legal, environmental, labor, and data protection standards that all vendors must meet as a condition of doing business with EthicPages.

This Code applies to direct suppliers and, where relevant, their subcontractors and other sub-tier providers that materially contribute to products or services delivered to EthicPages. Vendors are responsible for implementing equivalent standards in their own supply chains when supporting EthicPages commitments.

This Code should be read together with our Privacy Policy, Security Overview, Data Processing Agreement, Responsible Disclosure Policy, Modern Slavery Statement, and ESG Commitments.

Core vendor obligations

Vendors must comply with all applicable laws and regulations in each jurisdiction where they operate, including labor, anti-corruption, sanctions, environmental, tax, export, privacy, and data protection laws.

Obligation categoryBaseline expectation
Legal complianceOperate in full compliance with applicable law and maintain necessary licenses and authorizations
Ethical conductMaintain honest, transparent, and accountable business practices
Human rightsRespect internationally recognized human rights standards
Data security and privacyApply appropriate technical and organizational controls for confidentiality, integrity, and availability
Supply chain responsibilityFlow down relevant obligations to material subcontractors
Incident transparencyPromptly notify EthicPages of events affecting risk posture

Labor and human rights standards

EthicPages requires vendors to uphold fair labor and human rights protections across their operations and supply chains.

Labor standardRequirement
No forced laborProhibit slavery, servitude, debt bondage, prison labor abuses, and human trafficking
No child laborComply with legal minimum age requirements and ILO conventions
Fair wages and benefitsPay at least legal minimum wages and statutory benefits
Working hoursComply with maximum working hours and rest requirements under local law
Non-discriminationNo unlawful discrimination based on protected characteristics
Freedom of associationRespect lawful worker rights to organize and collective bargaining where permitted
Harassment-free workplaceProhibit abuse, threats, intimidation, and retaliation

Vendors must maintain mechanisms for employees and contractors to raise concerns confidentially and without retaliation.

Health and safety expectations

Vendors must provide safe and healthy working environments, including:

  • Hazard identification and risk mitigation controls.
  • Emergency preparedness procedures and incident response protocols.
  • Occupational health training relevant to role-based risk exposure.
  • Access to appropriate protective equipment where needed.
  • Documented incident reporting and corrective action processes.

Where operations include physical facilities, vendors should maintain inspection and prevention programs suitable to operational hazards.

Anti-bribery, anti-corruption, and conflicts

EthicPages has zero tolerance for bribery, facilitation payments, kickbacks, embezzlement, and fraudulent business practices.

Anti-corruption areaVendor expectation
Bribery prohibitionNo offering, giving, soliciting, or accepting improper benefits
Facilitation paymentsProhibited unless there is an imminent health/safety emergency and legally reportable
Gifts and hospitalityMust be infrequent, modest, and never intended to influence decisions
Books and recordsMaintain complete, accurate records and accounting controls
Conflicts of interestDisclose actual or potential conflicts related to EthicPages engagements
Third-party intermediariesConduct due diligence and monitor intermediary corruption risks

Any attempted or suspected bribery linked to EthicPages business must be reported immediately to ethicpages+contact@invictosoft.com.

Trade compliance and sanctions

Vendors must comply with applicable sanctions, export controls, anti-money laundering regulations, and trade restrictions. Vendors may be asked to certify screening controls and provide attestation that they do not knowingly engage prohibited parties in EthicPages-related work.

Environmental responsibility

EthicPages expects vendors to operate with environmental care and to reduce adverse impacts where practical.

Environmental areaRequired baseline
Regulatory complianceMeet all applicable environmental laws and permit requirements
Resource efficiencySeek reductions in energy, water, and material waste intensity
Waste managementHandle, store, transport, and dispose of waste responsibly
Emissions awarenessTrack and reduce material emissions where feasible
Continuous improvementEstablish goals and accountability for environmental performance

Vendors supporting infrastructure-heavy services should provide available sustainability disclosures when requested.

Data protection and information security

When vendors process EthicPages data (including customer data), they must meet strict privacy and security expectations.

Control domainMinimum expectation
Access controlRole-based least privilege and secure credential management
EncryptionEncryption in transit and at rest for sensitive data
Incident responseDefined process for detection, triage, containment, and communication
Vulnerability managementTimely patching and risk-based remediation practices
Data minimizationProcess only data needed for defined contractual purpose
Retention and deletionRetain data only as required and securely delete when no longer needed
Subprocessor oversightWritten agreements and due diligence for sub-tier processors

Where required, vendors must execute appropriate contractual terms, including data processing agreements and transfer safeguards.

AI, automation, and model usage expectations

If a vendor uses AI systems to deliver services that touch EthicPages or customer data, the vendor must:

  1. Disclose relevant AI use cases and processing boundaries.
  2. Implement safeguards against unauthorized data leakage.
  3. Avoid training public models on restricted or confidential data unless explicitly authorized.
  4. Provide transparency on data retention and deletion controls.
  5. Maintain incident procedures for model misuse or harmful output.

These obligations complement our AI Usage Policy and processor requirements.

Audit rights and assurance

EthicPages reserves risk-based rights to request evidence of vendor compliance with this Code and contractual obligations.

Assurance methodExamples
Questionnaire-based due diligenceSecurity and compliance assessments during onboarding and renewals
Document reviewCertifications, policy excerpts, penetration summaries, incident postmortems
AttestationsExecutive or compliance officer attestations regarding controls
Targeted auditsFocused reviews where risk indicators, incidents, or material changes arise
Remediation plansCorrective action deadlines for identified gaps

Vendors must cooperate in good faith with reasonable audit and remediation requests tied to legitimate risk management needs.

Incident notification requirements

Vendors must promptly notify EthicPages of security, privacy, legal, or ethical incidents that may affect EthicPages, customer data, or service continuity.

Incident typeNotification expectation
Security incident affecting EthicPages dataWithout undue delay, ideally within 24 hours of confirmation
Suspected unauthorized accessImmediate preliminary alert followed by structured updates
Regulatory inquiry or legal order affecting servicePrompt disclosure unless prohibited by law
Material subcontractor breachPrompt notice and risk impact summary
Business continuity disruptionTimely update with restoration timeline

Notifications should be sent to ethicpages+contact@invictosoft.com with subject line indicating severity.

Reporting violations and non-retaliation

EthicPages expects transparent reporting of actual or suspected violations of this Code.

ReporterReporting channelProtection expectation
Vendor personnelInternal vendor channel and/or EthicPages emailNo retaliation for good-faith reports
Subcontractor personnelVendor escalation path and/or EthicPages emailEscalation rights preserved
External stakeholdersEthicPages contact channelConcern logged and reviewed

EthicPages prohibits retaliation against anyone raising a good-faith concern.

Consequences of non-compliance

Failure to comply with this Code may lead to corrective action requirements, increased oversight, commercial suspension, or termination.

Non-compliance levelPotential response
Minor and remediableWritten corrective action plan with deadline
Repeated gapsEnhanced monitoring, conditional renewal controls
Material violationCommercial suspension, contract breach escalation
Severe ethical or legal breachImmediate termination and potential legal action

EthicPages applies proportionate responses based on risk severity, customer impact, and remediation intent.

Documentation and records

Vendors must maintain records sufficient to demonstrate adherence to this Code and related legal obligations. EthicPages may request relevant records as part of due diligence or incident response.

Training and awareness

Vendors are expected to provide role-appropriate training on:

  • Anti-corruption and ethical conduct.
  • Labor and human rights protections.
  • Data protection and secure data handling.
  • Incident reporting and escalation procedures.

Training should be refreshed periodically and aligned with operational risk.

Continuous improvement and collaboration

EthicPages recognizes that responsible vendor management is a continuous process. We encourage vendors to proactively share control improvements, certifications, and lessons learned from incidents or audits.

We prioritize collaborative remediation over punitive action when issues are disclosed transparently and corrected quickly.

Legal and policy cross-links

This Code aligns with and is supported by:

Contact

For questions, attestations, incident notifications, or compliance concerns, contact ethicpages+contact@invictosoft.com with an appropriate subject line:

  • Vendor Code of Conduct
  • Vendor Incident Notification
  • Vendor Compliance Attestation
  • Vendor Ethics Concern

Revision history commitment

EthicPages may update this Code to reflect legal developments, risk priorities, or operating model changes. Material updates are reflected in the "Last updated" field and may be referenced in procurement and vendor communications.

By continuing to provide services to EthicPages, vendors acknowledge and agree to uphold the standards in this Code, including supply-chain flow-down expectations and timely cooperation on audits, investigations, and corrective actions.

Template for operational transparency; not legal advice. Consult qualified counsel for your jurisdiction.