Back to Features
Vendor Risk Management

Vendor risk management, both sides, one evidence graph

The only third-party risk management platform where the vendor you assessed and the vendor you answered live in the same audit trail, anchored to the same 1,468 universal controls that back your compliance program.

Both sides
TPRM + questionnaire response, natively
1,468
Universal controls, cross-mapped
0–100
Transparent risk score, no black box

The obvious question

“How is this different from other TPRM software or questionnaire response tools?”

The category is bifurcated by design. Most tools ship one side and gesture at the other. The two that ship both do it on their own network’s evidence graph, separate from wherever your compliance evidence actually lives.

Inbound-only TPRM tools
OneTrust · UpGuard · Panorays · Prevalent
Strength
Deep on assessing vendors
What’s missing
Nothing on outbound; you still run a separate trust portal
Outbound-only trust centers
SafeBase · HyperComply · Trustero
Strength
Deep on questionnaire response
What’s missing
Nothing on assessing your own vendors; you still run separate TPRM
vCISO Lite
Both sides, one platform
Strength
Same evidence graph as your compliance program
Why it matters
The vendor you assessed and the vendor you answered live in the same audit trail
Third-Party Risk Assessment

Vendor onboarding and assessment, without the ceremony

Three onboarding paths so procurement doesn’t wait on you: manual add for one vendor, bulk CSV/JSON for a portfolio migration, or auto-enrollment that discovers vendors from your connected SaaS and cloud integrations. Whichever path the vendor lands via, it drops into a real 7-state assessment workflow with a passwordless portal for external vendors to fill out their side.

  • Add vendors one at a time, bulk-import from CSV or JSON up to 1,000 at a time, or auto-discover them from your connected SaaS and cloud integrations
  • 14-input inherent risk assessment across 5 dimensions
  • External vendors fill assessments through a passwordless portal. Magic-link login plus TOTP MFA. No account to set up, no password to reset, faster completion, enterprise-grade authentication out of the box
  • Structured Q&A follow-ups when a vendor answer needs clarification. No dropping into email threads.
  • Full review workflow: submit → review → approve, reject, or send back to vendor with specific feedback
Three onboarding paths
Manual add
One vendor at a time from the Vendors tab. Business context + risk factors on the same screen.
Bulk CSV / JSON
Up to 1,000 rows. Three modes: create-only, renew with diff-and-confirm, skip-existing.
Auto-enrollment
Connect a SaaS or cloud. Vendors get discovered from the connection and land ready for scoping.
Into a 7-state assessment workflow
Draft
With vendor
In progress
Submitted
Under review
Approved
Completed

Every transition emits an event. Auditor sees who moved it, when, and why. Passwordless magic-link + TOTP for external vendors filling out the assessment.

Security Questionnaire Response

Answer security questionnaires without slowing the deal. SIG, CAIQ, or custom.

Bring your SIG, SIG Lite, CAIQ, or a custom questionnaire. We accept XLSX, CSV, or DOCX exports from any of them. The AI response engine drafts every answer grounded in your actual policies, framework controls, control evidence, and scanner findings. Not a generic knowledge base. The same evidence your auditor sees.

  • Grounded in your published policies, framework controls, control evidence, and scanner findings. Five-source retrieval per question.
  • Second-pass evaluator grades every answer on 5 dimensions before a human sees it
  • Response library grows on every APPROVED answer (pgvector semantic search)
  • Bring your SIG, SIG Lite, CAIQ, or a custom questionnaire. We accept XLSX, CSV, or DOCX exports.
  • Auto-flag low-confidence + refusal-phrase + no-evidence answers to review; block-send under 0.5 quality
AI Response Generation
Generating
Q12Do you have a documented incident response plan?
AI-Generated Response

Yes, we maintain a comprehensive Incident Response Plan (IRP) that covers detection, response, and recovery procedures. The plan is reviewed and updated annually, with the last update completed in Q4 2024.

Evidence: Incident Response Plan v2.0.1
Model-reported 98% confidence · grader-verified before send
Anti-hallucination

The AI grades its own answers before your reviewer sees them

The AI response category has one problem buyers keep naming: one hallucinated answer permanently damages trust. Every incumbent leads with confidence scores + citations. We do that, plus a second-pass Evaluator that grades every answer on five dimensions before a human sees it: alignment, deflection, admission, comprehensiveness, quality. Answers below 0.7 overall auto-flag to review; below 0.5 block send.

  • Five graded dimensions per answer, each 0–1
  • Deflection and admission are inverse-scored, so low is good
  • Auto-flag under 0.7 · block send under 0.5
  • Reviewer sees the rubric alongside the answer, not just the score
Second-pass evaluator
Grades every answer
Q12Do you have a documented incident response plan?
  • Alignment0.94
    Cites the correct policy section.
  • Deflection0.12↓ better
    Answers the actual question, doesn't dodge.
  • Admission0.08↓ better
    Doesn't over-commit; scope-appropriate.
  • Comprehensive0.87
    Covers all three sub-questions asked.
  • Quality0.91
    Clear, concise, well-structured.
Overall risk score0.86
Passes for send. Human reviewer sees this rubric before hitting Approve.
Answers below 0.7 overall auto-flag to review; below 0.5 block send.
Transparent Risk Scoring

The most transparent vendor risk score in the category

Every vendor risk score in this platform is math you can walk into: 14 weighted inputs across 5 dimensions rolling up to a 0–100 inherent score, then reduced by control effectiveness weighted by evidence confidence to produce residual. No proprietary rating, no undocumented model, no "trust us it’s AI-powered."

  • Inherent risk: 14 weighted factors across data sensitivity, system access, business impact, compliance surface, financial exposure
  • Questionnaire risk: security 40% / privacy 30% / operational 30% weighted average, per-question weight from base × importance × confidence × evidence
  • Residual risk: inherent × (1 − control effectiveness × evidence confidence)
  • Four tiers: LOW ≤30 · MEDIUM 31–60 · HIGH 61–85 · CRITICAL 86–100
  • Every input, weight, and rollup is inspectable. Not a proprietary rating.
Risk score breakdown
14 inputs · 5 dimensions · 0–100 scale
  • Data sensitivity28% weight55/100
    Accesses PII · Accesses PHI · Accesses PCI · IP + trade secrets
  • System access22% weight40/100
    Network access · Admin access · Integration depth
  • Business impact20% weight50/100
    Critical service · Single-source · Revenue impact tier
  • Compliance surface15% weight20/100
    International data · Physical access
  • Financial exposure15% weight30/100
    Contract value tier
Inherent risk
42/100
MEDIUM
→
× (1 − control eff. 0.55)
× evidence factor 0.91
→
Residual risk
21/100
LOW

Every number here is math you can walk into. No proprietary score, no black box.

Category-first

Two sides of vendor risk. One evidence graph.

Whistic and HyperComply pitch “one workflow, one data model, one audit trail” for their inbound + outbound combo. Our graph is the same one your compliance evidence already lives on. The vendor answer becomes framework evidence, the vendor assessment becomes an artifact your auditor already knows how to sample.

Outbound
You answer a customer's questionnaire
  • AI-drafted from your policies + evidence
  • Second-pass evaluator grades every answer
  • Approved answers become knowledge-base entries
Inbound
You assess a vendor
  • 14-input inherent risk on onboarding
  • Vendor answers via passwordless portal
  • Approved answers become framework evidence
Same audit-ready record
One evidence graph, chain-anchored
Also carries your policies, attestations, scanner findings, control-state history. Every artifact your auditor cares about, in one graph.
  • Policies
  • Attestations
  • Scanner findings
  • Control state
  • Vendor answers
  • Inbound answers

Continuous Monitoring

Continuous vendor risk monitoring, tuned to tier

  • Certificate expiry alerts at 90 / 60 / 30 / 7 days out
  • Contract renewal alerts at 90 / 60 / 30 days out
  • Reassessment cadence tuned per tier: critical 90d · high 180d · medium 365d · low 730d
  • Auto-enrollment: connect a SaaS or cloud, vendors get discovered from the connection
  • GO / CONDITIONAL / NO GO decision badges on every vendor card. Residual ≥70 = NO GO, ≥40 = CONDITIONAL.

Certificate expiries, contract renewals, and reassessment due dates all get monitored on schedules scaled to the vendor’s risk tier. Critical vendors get 90-day cycles, low-risk vendors get two-year cycles. Every vendor card carries a GO / CONDITIONAL / NO GO decision badge so procurement doesn’t have to interpret raw scores at contract time.

Vendor portfolio
3 of 47 shown · sorted by review urgency
GOCONDNO GO
  • Amazon Web Services
    Cloud Infrastructure
    SOC 2 Type IIISO 27001FedRAMP High
    62
    inherent
    18
    residual
    $142K / yr
    Review in 274d
    GO
  • Stripe
    SaaS · Financial Services
    PCI DSSSOC 2 Type II
    55
    inherent
    22
    residual
    $38K / yr
    Review in 118d
    GO
  • Acme Analytics
    SaaS · Data Processor
    SOC 2 Type II
    71
    inherent
    48
    residual
    $62K / yr
    Cert expires in 14d
    CONDITIONAL
Reassessment cadence tuned per tier: critical 90d, high 180d, medium 365d, low 730d. Cert expiries alert at 90 / 60 / 30 / 7 days out. Contract renewals at 90 / 60 / 30.
Category-first capability

When your vendor is breached, we rank what to do first

Panorays alerts the vendor. SecurityScorecard SCDR coordinates cross-vendor response. Nobody else in the category tells the BUYER: “your Okta got breached. Because Okta touches your Salesforce, BigQuery, and Snowflake, do these three things first.” Deterministic 21-control library, patch-first rule enforced in code (0.85 exposure-reduction factor vs. 0.45 for protective controls), optional AI tailoring reshapes the ranked list to your specific business-function dependencies.

  • Deterministic ranking + optional grounded AI tailoring
  • Patch leads when there’s one. Not a “consider patching” nudge.
  • Business-function scoping from your confirmed vendor → system → function graph
  • AI cites $/hr revenue impact only when the profile is confirmed
  • Fails closed to the deterministic top-3 if AI errors or grounding fails
Active incident · High severity
Okta: auth service compromise
Detected via CISA KEV · 14 min ago · affects your Salesforce, BigQuery, Snowflake integrations
Tailored to your stack
  1. 1
    PATCHRotate Okta service-account credentials for Salesforce
    Blocks reuse of any stolen tokens on your top-value CRM integration before the attacker can pivot from Okta into Salesforce data.
    $47K/hr revenue exposure·LOW effort·−85% exposure
    Commit
  2. 2
    PROTECTIVEAudit BigQuery reader roles granted via Okta groups
    Your data warehouse permission model inherits from Okta groups. Confirm no over-provisioned reader access on customer-PII datasets.
    PII exposure limit·MEDIUM effort·−45% exposure
    Commit
  3. 3
    DETECTIVEReview last 30 days of SCIM provisioning events
    Any unusual account provisions or role escalations Okta pushed in the last 30 days need eyes on them; that's the attacker's typical persistence window.
    Persistence catch·LOW effort·−15% exposure
    Commit
Patch leads by design. The fix has a 0.85 exposure-reduction factor vs. 0.45 for protective controls. AI tailoring uses your confirmed vendor → system → business-function graph, and only cites $/hr values when the profile is verified.
Auto-declaration

Vendor incidents declare themselves

Every vendor you add gets 8 detection sources automatically watching for trouble: CVE databases, government advisory feeds, security news, vendor status pages, breach registries. Relevance is scored per vendor so you don’t get paged for every industry headline. Confirmed matches auto-declare incidents into your response queue, starting the clock before the breach hits the trade press.

  • 8 detection sources per vendor, provisioned automatically the moment you add them
  • CVE databases, government advisory feeds, security news, vendor status pages, breach registries
  • Signals scored for per-vendor relevance so noise doesn't wake you at 3 AM
  • Confirmed matches auto-declare incidents into your response queue
  • Every incident lifecycle event lands on the tamper-evident audit record
Fully autonomous, one tier up

Trustworthy Autonomy takes both sides further. The agents can run a vendor assessment start to finish and act on incident alerts on their own, without waiting for a human click. See Trustworthy Autonomy

Detection sources · watching every vendor automatically
Every signal gets scored for relevance to your specific vendor. High-confidence matches auto-declare an incident; noisy or unrelated ones go to a review queue instead of paging you.
  • NVD
    CVE-2026-XXXX in nginx affecting your CDN vendor
    0.92
    AUTO-DECLARE
  • CISA KEV
    New KEV entry for Ivanti VPN in known-exploited catalog
    0.95
    AUTO-DECLARE
  • GitHub Advisory
    GHSA on log4j-adjacent dependency shared by 3 vendors
    0.81
    AUTO-DECLARE
  • NewsAPI (Event Registry)
    Reuters: 'Okta discloses breach affecting authentication'
    0.88
    AUTO-DECLARE
  • Curated security RSS
    BleepingComputer, TheHackerNews, SecurityWeek, CISA feeds
    0.72
    AUTO-DECLARE
  • Google Alerts
    Long-tail coverage of vendor-name-specific mentions
    0.65
    REVIEW
  • Vendor status pages
    Cloudflare status page: incident lifecycle events
    0.78
    AUTO-DECLARE
  • XposedOrNot breach registry
    Newly disclosed credential exposure affecting a vendor
    0.83
    AUTO-DECLARE
Every vendor gets all 8 feeds enabled automatically the moment you add them. Nothing to configure, nothing to bolt on. Noise goes to the review queue, not your phone at 3 AM.

Common questions

The questions vendor-risk buyers actually ask

The category is bifurcated. Most tools either assess your vendors (OneTrust, UpGuard, Panorays) or answer questionnaires from your customers (SafeBase, HyperComply). Whistic and HyperComply do both but on their own network's evidence graph. We do both AND the graph is the same one your compliance program lives on. When your vendor answer satisfies a control, it flows to the SOC 2 / ISO 27001 / PCI panels your auditor already looks at. That's the wedge.

Ready for TPRM software that ships with the questionnaire response engine?

Assess your vendors and answer your customers on the same evidence graph. Get every vendor answer into audit-ready evidence in one pass.