The architecture behind the trust.
Two capabilities competitors cannot easily copy: dual-signal Posture Divergence Detection, and auditor-grade integrity enforced in the data layer, not just the UI.
Frequently asked questions
What does one data model mean for GRC and vendor risk?
Controls, policies, evidence, risks, vendor assessments, and questionnaire responses are stored as linked records in one platform, not in separate tools joined by exports. A piece of evidence can support a control, an internal assessment, and a customer questionnaire answer at once. Internal posture and vendor posture are reported from the same records your auditor reviews.
How does Posture Divergence Detection work?
Each vendor is scored on three layers: business criticality, assessed posture from questionnaires, and live external exposure from continuous monitoring. Posture Divergence Detection compares the assessed and live layers and flags a vendor when they disagree. Flags are tiered Minor, Moderate, or Severe, so your team can see which gaps need attention first.
What makes the auditor role different from a read-only permission setting?
The AUDITOR role is enforced on the server, not only hidden in the interface. An auditor can read records, leave reviewer comments, and submit reviews, and cannot create, edit, or delete anything. Published policies are stored as immutable PolicyVersion records, and every change in the platform is written to the audit log.
Which integrations does ThirdSentry support, and what do they automate?
ThirdSentry has 16 native integrations, including AWS, Azure, GCP, Okta, Google Workspace, GitHub, and Jira, plus a unified-API layer that reaches many more providers. Connectors collect evidence and link it to controls. Automated control testing, where connector data is scored to a pass or fail verdict, currently covers SOC 2 and NIST 800-53. A reviewer can always override the result.
How is the platform priced?
Pricing is a flat fee with unlimited users, and AI features are included on every tier. There are four tiers: Launch, Foundation, Professional, and Enterprise. The main thing that changes the price is the number of frameworks you run, so adding team members, auditors, or reviewers does not raise the bill.