Catch vendors the moment reported posture stops matching reality.
Three signals on every vendor: business criticality, reported posture, live external exposure. The moment they stop agreeing, you know.
Vendor risk that knows when answers stop matching.
Three-layer scoring
Business criticality, assessed posture, live external exposure. One score, three layers of context.
- Business criticality at onboarding
- Assessed posture from questionnaire responses
- Live external exposure from continuous monitoring
Posture Divergence Detection
Divergence past threshold updates the risk record and opens remediation automatically.
- Severity tiered Minor / Moderate / Severe
- Auto-updates parent risk record
- Auto-generates remediation tasks
Full vendor lifecycle
Onboarding to offboarding, on the same data model as your internal controls.
- Onboarding to offboarding lifecycle
- Counter-back capped at 5 rounds
- Per-vendor RAG namespace isolation
Vendor Intelligence
Auto-enriched profiles: funding, ownership, tech stack, incidents. No more spreadsheet chasing.
- Auto-enriched profiles from multiple sources
- Funding, ownership, and parent company tracked
- Security incident + breach feed per vendor
Subcontractor Insights
Map fourth-party dependencies and see where concentration risk really lives.
- Fourth-party concentration analysis
- Sub-processor disclosure tracking (GDPR)
- Cascading risk visualization
Vendor questionnaire engine
SIG, CAIQ, and custom templates. AI-assisted responses, auto-scored against your criteria.
- SIG, CAIQ, and custom templates
- AI-assisted vendor response (when they opt in)
- Auto-scored against your criteria
Three steps from setup to value.
Onboard vendors
Add vendors manually or via CSV. Set criticality, assign owners.
Assess + monitor
Send assessments through the vendor portal while continuous monitoring runs in parallel.
Catch divergence + remediate
Divergence past threshold fires a tiered alert, updates the risk, and generates remediation.
When the questionnaire and live exposure disagree, you find out first.
Three-layer scoring on every vendor: Business Criticality, Assessed Posture, and Live External Exposure. When the gap exceeds threshold, divergence fires automatically. The parent risk record updates, a remediation task is generated, and your owners get notified before the next reassessment cycle.
Compliance automation platforms evaluate vendor evidence against criteria but don't reconcile it against live signals. Ratings-only platforms measure external posture but not assessed posture. ThirdSentry connects both to the same vendor risk record and remediation workflow.
Reported posture is strong (87) but live exposure degraded to 42. Reassessment fired automatically.