What the library is
The document library is vendor documentation that Coverbase collects and curates itself, so a vendor’s evidence is often waiting for you before you’ve asked anyone for it. It’s keyed to the company rather than to your organization. Coverbase resolves each vendor record to a canonical company, and every customer assessing that same company sees the same library.Collected by us
Reviewed before publishing
Never sourced from customers
Where the documents come from
There are two routes, both run by Coverbase and neither triggered by a customer asking for anything.- We ask the vendor. Our agent requests documentation from the company directly, on Coverbase’s own behalf. This is how the library gets hold of material that isn’t published anywhere.
- We retrieve what the vendor publishes. Trust centers (Drata, Vanta, SafeBase, custom portals), certification registries, and official disclosures. Anything ungated is downloaded, and for gated material the agent completes the access request.
What never goes into the library
This isn’t only a policy. It’s how the system is built:- Only Coverbase staff can add a document to the library. The write path is closed to customer organizations completely, so a document can’t land there from your side even by accident.
- Everything in the library was obtained by Coverbase on our own initiative, not in response to any customer’s request or upload.
- Your own vendor documents live in a separate, org-scoped store, under the tenant isolation described in Data protection. They appear on your vendor’s Documents tab in their own section, above the library.
How documents are curated
Collected
Classified and dated
Reviewed
Aged out
Where you’ll see it
The card carries a short explanation of its own. Click the question mark next to the heading for the same answer this page gives, without leaving the vendor.
The Coverbase library documents card on a vendor, with the in-app explainer open.
On a vendor
On an assessment

4 Import from Coverbase Library, with the count of documents already held for this vendor. The other cards on this tab collect evidence from your own files, the vendor portal, and the vendor's trust center.
Frequently asked questions
Could a document we uploaded show up in another customer's library?
Could a document we uploaded show up in another customer's library?
Why does a vendor we've never contacted already have documents?
Why does a vendor we've never contacted already have documents?
Is a library document as good as one the vendor sent us directly?
Is a library document as good as one the vendor sent us directly?
A library document is wrong, stale, or shouldn't be there. What do we do?
A library document is wrong, stale, or shouldn't be there. What do we do?