Manage vendor risk
Know the risk you inherit from your supply chain
You inherit the security of every company you buy software from. The payroll platform holds your employee data. The analytics SDK sits inside your product. The support tool reads tickets that contain whatever your customers pasted into them.
What's actually happening
For most companies the vendor list is really a card statement, and vendor management is a questionnaire someone sent during onboarding, received answers to, and filed. Nobody has looked at it since. The certificate expired. The vendor added three subprocessors. Two engineers connected a new tool via OAuth last quarter without telling anyone, which is how most of the list gets longer.
Then one of them is breached, and the questions arrive in this order: what data did they hold, which of our systems could they reach, and what do we tell our customers. Most teams take days to answer, and the delay is what the customer remembers.
How we help
We build the register from sources that reflect reality rather than intention: finance records, SSO logs, cloud accounts and OAuth grants. Then we tier vendors by the data they touch and what breaks if they go down, because a design tool and a payment processor do not deserve the same scrutiny.
Assessment matches the tier. Questionnaires for the ones that need them, a proper read of their SOC 2 report or ISO certificate and pen test summary rather than a tick that a document exists, and an external scan of the vendor's own attack surface to see whether their practice matches their paperwork. The three views combine into one score you can defend in a board meeting.
Monitoring continues after onboarding: certificate expiry, new exposure, breach news. We also give you the contract language for security obligations and breach notification timelines, and a response playbook so that when a vendor is compromised you answer in hours.
The work behind it
The service pages covering what we just described.
Send us your vendor list and we will tell you what is on it.
A 30 minute call is usually enough to tell you what this takes and what it costs. No pitch deck.