Vendor risk management, both sides, one evidence graph
The only third-party risk management platform where the vendor you assessed and the vendor you answered live in the same audit trail, anchored to the same 1,468 universal controls that back your compliance program.
The obvious question
“How is this different from other TPRM software or questionnaire response tools?”
The category is bifurcated by design. Most tools ship one side and gesture at the other. The two that ship both do it on their own network’s evidence graph, separate from wherever your compliance evidence actually lives.
- Strength
- Deep on assessing vendors
- What’s missing
- Nothing on outbound; you still run a separate trust portal
- Strength
- Deep on questionnaire response
- What’s missing
- Nothing on assessing your own vendors; you still run separate TPRM
- Strength
- Same evidence graph as your compliance program
- Why it matters
- The vendor you assessed and the vendor you answered live in the same audit trail
Vendor onboarding and assessment, without the ceremony
Three onboarding paths so procurement doesn’t wait on you: manual add for one vendor, bulk CSV/JSON for a portfolio migration, or auto-enrollment that discovers vendors from your connected SaaS and cloud integrations. Whichever path the vendor lands via, it drops into a real 7-state assessment workflow with a passwordless portal for external vendors to fill out their side.
- Add vendors one at a time, bulk-import from CSV or JSON up to 1,000 at a time, or auto-discover them from your connected SaaS and cloud integrations
- 14-input inherent risk assessment across 5 dimensions
- External vendors fill assessments through a passwordless portal. Magic-link login plus TOTP MFA. No account to set up, no password to reset, faster completion, enterprise-grade authentication out of the box
- Structured Q&A follow-ups when a vendor answer needs clarification. No dropping into email threads.
- Full review workflow: submit → review → approve, reject, or send back to vendor with specific feedback
Every transition emits an event. Auditor sees who moved it, when, and why. Passwordless magic-link + TOTP for external vendors filling out the assessment.
Answer security questionnaires without slowing the deal. SIG, CAIQ, or custom.
Bring your SIG, SIG Lite, CAIQ, or a custom questionnaire. We accept XLSX, CSV, or DOCX exports from any of them. The AI response engine drafts every answer grounded in your actual policies, framework controls, control evidence, and scanner findings. Not a generic knowledge base. The same evidence your auditor sees.
- Grounded in your published policies, framework controls, control evidence, and scanner findings. Five-source retrieval per question.
- Second-pass evaluator grades every answer on 5 dimensions before a human sees it
- Response library grows on every APPROVED answer (pgvector semantic search)
- Bring your SIG, SIG Lite, CAIQ, or a custom questionnaire. We accept XLSX, CSV, or DOCX exports.
- Auto-flag low-confidence + refusal-phrase + no-evidence answers to review; block-send under 0.5 quality
Yes, we maintain a comprehensive Incident Response Plan (IRP) that covers detection, response, and recovery procedures. The plan is reviewed and updated annually, with the last update completed in Q4 2024.
The AI grades its own answers before your reviewer sees them
The AI response category has one problem buyers keep naming: one hallucinated answer permanently damages trust. Every incumbent leads with confidence scores + citations. We do that, plus a second-pass Evaluator that grades every answer on five dimensions before a human sees it: alignment, deflection, admission, comprehensiveness, quality. Answers below 0.7 overall auto-flag to review; below 0.5 block send.
- Five graded dimensions per answer, each 0–1
- Deflection and admission are inverse-scored, so low is good
- Auto-flag under 0.7 · block send under 0.5
- Reviewer sees the rubric alongside the answer, not just the score
- Alignment0.94Cites the correct policy section.
- Deflection0.12↓ betterAnswers the actual question, doesn't dodge.
- Admission0.08↓ betterDoesn't over-commit; scope-appropriate.
- Comprehensive0.87Covers all three sub-questions asked.
- Quality0.91Clear, concise, well-structured.
The most transparent vendor risk score in the category
Every vendor risk score in this platform is math you can walk into: 14 weighted inputs across 5 dimensions rolling up to a 0–100 inherent score, then reduced by control effectiveness weighted by evidence confidence to produce residual. No proprietary rating, no undocumented model, no "trust us it’s AI-powered."
- Inherent risk: 14 weighted factors across data sensitivity, system access, business impact, compliance surface, financial exposure
- Questionnaire risk: security 40% / privacy 30% / operational 30% weighted average, per-question weight from base × importance × confidence × evidence
- Residual risk: inherent × (1 − control effectiveness × evidence confidence)
- Four tiers: LOW ≤30 · MEDIUM 31–60 · HIGH 61–85 · CRITICAL 86–100
- Every input, weight, and rollup is inspectable. Not a proprietary rating.
- Data sensitivity28% weight55/100Accesses PII · Accesses PHI · Accesses PCI · IP + trade secrets
- System access22% weight40/100Network access · Admin access · Integration depth
- Business impact20% weight50/100Critical service · Single-source · Revenue impact tier
- Compliance surface15% weight20/100International data · Physical access
- Financial exposure15% weight30/100Contract value tier
Every number here is math you can walk into. No proprietary score, no black box.
Category-first
Two sides of vendor risk. One evidence graph.
Whistic and HyperComply pitch “one workflow, one data model, one audit trail” for their inbound + outbound combo. Our graph is the same one your compliance evidence already lives on. The vendor answer becomes framework evidence, the vendor assessment becomes an artifact your auditor already knows how to sample.
- AI-drafted from your policies + evidence
- Second-pass evaluator grades every answer
- Approved answers become knowledge-base entries
- 14-input inherent risk on onboarding
- Vendor answers via passwordless portal
- Approved answers become framework evidence
- Policies
- Attestations
- Scanner findings
- Control state
- Vendor answers
- Inbound answers
Continuous Monitoring
Continuous vendor risk monitoring, tuned to tier
- Certificate expiry alerts at 90 / 60 / 30 / 7 days out
- Contract renewal alerts at 90 / 60 / 30 days out
- Reassessment cadence tuned per tier: critical 90d · high 180d · medium 365d · low 730d
- Auto-enrollment: connect a SaaS or cloud, vendors get discovered from the connection
- GO / CONDITIONAL / NO GO decision badges on every vendor card. Residual ≥70 = NO GO, ≥40 = CONDITIONAL.
Certificate expiries, contract renewals, and reassessment due dates all get monitored on schedules scaled to the vendor’s risk tier. Critical vendors get 90-day cycles, low-risk vendors get two-year cycles. Every vendor card carries a GO / CONDITIONAL / NO GO decision badge so procurement doesn’t have to interpret raw scores at contract time.
- Amazon Web ServicesCloud InfrastructureSOC 2 Type IIISO 27001FedRAMP High62inherent18residual$142K / yrReview in 274dGO
- StripeSaaS · Financial ServicesPCI DSSSOC 2 Type II55inherent22residual$38K / yrReview in 118dGO
- Acme AnalyticsSaaS · Data ProcessorSOC 2 Type II71inherent48residual$62K / yrCert expires in 14dCONDITIONAL
When your vendor is breached, we rank what to do first
Panorays alerts the vendor. SecurityScorecard SCDR coordinates cross-vendor response. Nobody else in the category tells the BUYER: “your Okta got breached. Because Okta touches your Salesforce, BigQuery, and Snowflake, do these three things first.” Deterministic 21-control library, patch-first rule enforced in code (0.85 exposure-reduction factor vs. 0.45 for protective controls), optional AI tailoring reshapes the ranked list to your specific business-function dependencies.
- Deterministic ranking + optional grounded AI tailoring
- Patch leads when there’s one. Not a “consider patching” nudge.
- Business-function scoping from your confirmed vendor → system → function graph
- AI cites $/hr revenue impact only when the profile is confirmed
- Fails closed to the deterministic top-3 if AI errors or grounding fails
Deeper on how the tailoring works and what the ranked output looks like: Refraction on Allotrope
- 1PATCHRotate Okta service-account credentials for SalesforceBlocks reuse of any stolen tokens on your top-value CRM integration before the attacker can pivot from Okta into Salesforce data.Commit
- 2PROTECTIVEAudit BigQuery reader roles granted via Okta groupsYour data warehouse permission model inherits from Okta groups. Confirm no over-provisioned reader access on customer-PII datasets.Commit
- 3DETECTIVEReview last 30 days of SCIM provisioning eventsAny unusual account provisions or role escalations Okta pushed in the last 30 days need eyes on them; that's the attacker's typical persistence window.Commit
Vendor incidents declare themselves
Every vendor you add gets 8 detection sources automatically watching for trouble: CVE databases, government advisory feeds, security news, vendor status pages, breach registries. Relevance is scored per vendor so you don’t get paged for every industry headline. Confirmed matches auto-declare incidents into your response queue, starting the clock before the breach hits the trade press.
- 8 detection sources per vendor, provisioned automatically the moment you add them
- CVE databases, government advisory feeds, security news, vendor status pages, breach registries
- Signals scored for per-vendor relevance so noise doesn't wake you at 3 AM
- Confirmed matches auto-declare incidents into your response queue
- Every incident lifecycle event lands on the tamper-evident audit record
Trustworthy Autonomy takes both sides further. The agents can run a vendor assessment start to finish and act on incident alerts on their own, without waiting for a human click. See Trustworthy Autonomy
- NVDCVE-2026-XXXX in nginx affecting your CDN vendor0.92AUTO-DECLARE
- CISA KEVNew KEV entry for Ivanti VPN in known-exploited catalog0.95AUTO-DECLARE
- GitHub AdvisoryGHSA on log4j-adjacent dependency shared by 3 vendors0.81AUTO-DECLARE
- NewsAPI (Event Registry)Reuters: 'Okta discloses breach affecting authentication'0.88AUTO-DECLARE
- Curated security RSSBleepingComputer, TheHackerNews, SecurityWeek, CISA feeds0.72AUTO-DECLARE
- Google AlertsLong-tail coverage of vendor-name-specific mentions0.65REVIEW
- Vendor status pagesCloudflare status page: incident lifecycle events0.78AUTO-DECLARE
- XposedOrNot breach registryNewly disclosed credential exposure affecting a vendor0.83AUTO-DECLARE
Common questions
The questions vendor-risk buyers actually ask
Ready for TPRM software that ships with the questionnaire response engine?
Assess your vendors and answer your customers on the same evidence graph. Get every vendor answer into audit-ready evidence in one pass.