The obvious objection

Vannus is a US company selling analysis of US legal reach.

Which means the statute we report on reaches us too. That is a fair thing to raise before you spend anything here, and there is no version of answering it that involves us being an exception.

So this page is our own entry. Same scoring functions as every tool in the catalog, same evidence gate on every field, nothing adjusted because it is us. Below the grade is everything we hold about you, how long we hold it, and how to make us delete it.

Our grade, from the same pipeline
D
45/100 · fragile
4 of 6 dimensions assessed
● US corporate control

Produced by verification.score_tool() and sovereignty.assess_sovereignty() — the functions that grade the catalog — passed through the same to_public_dict() boundary a vendor's entry goes through. We do not get a wider window into our own scoring than a vendor gets into theirs.

Why the grade is what it is

A D is the correct answer. We hold no certifications, we have no integration surface, and one person operates the whole thing — those are the axes, and the methodology is doing its job by marking us down on them. A page that graded Vannus an A would tell you nothing worth paying for, and you would be right to stop reading.

What the grade measures is resilience: whether a tool endures and whether you could leave it. It is a different question from who controls the vendor, which is the row above it. On that second question we are plainly under US corporate control, and we publish that about ourselves in the same words we use about everyone else.

Where we are weak

We are within reach of the same statute we report on.

PRAXIS AI LLC is a United States company. The CLOUD Act reaches a provider subject to US jurisdiction over data in its possession, custody or control. That includes us. If a US legal process compelled production of a customer's tool list, we would be subject to it exactly as the vendors we grade are. We are not offering a way around that, and any vendor that claims to sell one is worth reading twice.

A purchased report is retained, not zero-retention.

24 months, so the link keeps working and so we can correct the record if we got something wrong. If you would rather we held nothing, ask for erasure the day you receive it — the report is yours and it is a file.

One person operates this.

That is a single point of failure and the resilience grade below reflects it. There is no second engineer, no on-call rotation and no acquirer waiting. If continuity matters to you, weigh that honestly.

Coverage is partial and we say where.

Sovereignty fields are researched for some of the catalog, not all of it. Where a field was never established we publish "not assessed" rather than a default, because a default that reads as a finding is how a rating product does real damage to a real company.

What we hold about you
If youWe holdFor how long
A purchased Exposure ReportYour email address, the organisation name you gave, the tool list you submitted, the report we generated from it, a salted hash of your IP, and the timestamp at which you accepted the Terms.24 months from purchase, then deleted. Sooner on request — see below.
A free stack check at /api/stack/rateNothing. The request body is not written to any database, log or backup, and the response carries Cache-Control: no-store. Your IP sits in an in-memory rate-limit bucket and is purged within minutes.Not retained at all.
A free-tier auditThe same fields as a purchased report.The share link stops resolving 7 days after creation. The underlying row is retained until erased on request — expiry blocks access, it does not delete.
A Stack Watch subscriptionYour email, the stack you asked us to watch, and the Stripe customer identifier. Card details are entered on Stripe-hosted pages and are never transmitted to or stored by Vannus.For the life of the subscription, then per the retention schedule in the Privacy Policy.
A Concierge engagementWhatever you send us, held in Vannus's operational email account.The longer of 3 years or what tax and accounting law requires.

What we do not do

Deleting your data

Email support@vannus.co and ask us to delete your data. We will erase the report, the tool list, the organisation name, the email and the IP hash. The Privacy Policy commits to 30 days; the operation itself takes one call, so in practice it happens the day we read the message. Payment records live at Stripe and in accounting, contain no part of your tool list, and are kept as long as tax law requires.

The raw output, so you can check it

Verbatim from the scoring functions. If the prose above ever disagrees with this block, the block is right.

{
  "assessment": {
    "dimensions_assessed": 4,
    "dimensions_total": 6,
    "grade": "D",
    "model_provenance_assessed": false,
    "rated": true,
    "resilience_score": 45,
    "single_upstream_dependency": null,
    "summary": "In Vannus's editorial judgment under the published methodology, Vannus scores in the Fragile tier \u2014 buyers should review the full scorecard before committing.",
    "tier": "fragile",
    "tool_name": "Vannus"
  },
  "sovereignty": {
    "badge_label": "US corporate control",
    "country_of_origin": "USA",
    "data_jurisdiction": "US",
    "is_us_controlled": true,
    "recommendation": "Under US corporate control, so within reach of US legal process including the CLOUD Act. For a US buyer that is usually the intended posture.",
    "training_data_usage": "never",
    "trust_tier": "us_controlled",
    "warnings": [],
    "zdr_compliant": false
  }
}

If you think anything on this page or anywhere in the catalog is factually wrong — about us or about a vendor we grade — the correction route is right of reply. It is free and does not require a lawyer. Our methodology is at structural neutrality.