| Tier 1 | Vendors that host, store, process, transmit, or can access customer data, production systems, sensitive internal information, credentials, CI/CD secrets, source data, or other high-impact systems. | Reviewed before onboarding where practical, approved by an appropriate owner, and reviewed at least annually or upon material change. |
| Tier 2 | Vendors that may receive limited customer context, internal documentation, product planning data, code snippets, telemetry, error context, or employee information, but do not broadly host core customer data or production systems. | Reviewed before onboarding and on renewal, material scope change, incident, or security concern. |
| Tier 3 | Vendors used for low-risk corporate operations with no expected customer data, production access, sensitive internal data, or material operational dependency. | Reviewed as needed based on risk and use. |