Continuous, evidence-driven vendor risk — not a spreadsheet you update once a year.
TPRM is questionnaires nobody reads and risk scores that go stale the day after onboarding.
Automated questionnaires via a vendor portal, AI-powered evidence analysis of SOC 2 reports, pen tests and ISO certs, residual-risk scoring with analyst decisions, and live breach correlation that re-scores a vendor the moment they are compromised.

Vendor risk inventory with security scoring

Every vendor gets an external posture assessment — DNS, TLS, headers, email auth, open ports, breach history, subdomain takeover, cloud exposure and code-leak — rolled into one grade, alongside a CVE matrix matched against their detected stack. No questionnaire required to start.

Inherent risk is calculated from environment access, integration depth, data types and business dependency — then blended with the external posture and control evidence into a residual risk an analyst confirms, with a review cadence so it never goes stale.
Automated send, reminders and weighted scoring via a vendor portal.
Reads SOC 2 / pen-test / ISO PDFs and extracts the findings that matter.
Analyst accept / mitigate / transfer decisions with expiry.
A vendor breach instantly re-scores your exposure.
The vendor's tech stack matched against live CVEs.
DORA-aligned view of critical-vendor dependence.
Send the portal questionnaire and request evidence.
AI reads the evidence; analysts score residual risk.
Accept, mitigate or transfer — with a review deadline.
Breach and CVE signals keep the score live.
TPRM wired into the same threat-intel and CVE pipeline as the rest of the platform — so vendor risk is live, not a snapshot.
See Third-Party Risk · TPRM alongside the rest of your security program — correlated, not siloed.