<?xml version="1.0" encoding="UTF-8"?>
<!--
  Public pages only. Anything under /app, /admin, /api or the auth flows is
  excluded here and in robots.txt: it is gated, tokenised, or both.

  URLs use https://www.ordervanta.com because that is the canonical origin —
  Vercel 308s the apex there, and listing the apex would point Google at a
  redirect for every entry.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://www.ordervanta.com/</loc>
    <lastmod>2026-07-31</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://www.ordervanta.com/pricing</loc>
    <lastmod>2026-07-31</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://www.ordervanta.com/research</loc>
    <lastmod>2026-07-31</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://www.ordervanta.com/company</loc>
    <lastmod>2026-07-31</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://www.ordervanta.com/privacy</loc>
    <lastmod>2026-07-31</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://www.ordervanta.com/terms</loc>
    <lastmod>2026-07-31</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://www.ordervanta.com/disclosures</loc>
    <lastmod>2026-07-31</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
</urlset>
