Products · Vendor Risk

Catch vendors the moment reported posture stops matching reality.

Three signals on every vendor: business criticality, reported posture, live external exposure. The moment they stop agreeing, you know.

What you get

Vendor risk that knows when answers stop matching.

Three-layer scoring

Business criticality, assessed posture, live external exposure. One score, three layers of context.

  • Business criticality at onboarding
  • Assessed posture from questionnaire responses
  • Live external exposure from continuous monitoring

Posture Divergence Detection

Divergence past threshold updates the risk record and opens remediation automatically.

  • Severity tiered Minor / Moderate / Severe
  • Auto-updates parent risk record
  • Auto-generates remediation tasks

Full vendor lifecycle

Onboarding to offboarding, on the same data model as your internal controls.

  • Onboarding to offboarding lifecycle
  • Counter-back capped at 5 rounds
  • Per-vendor RAG namespace isolation

Vendor Intelligence

Auto-enriched profiles: funding, ownership, tech stack, incidents. No more spreadsheet chasing.

  • Auto-enriched profiles from multiple sources
  • Funding, ownership, and parent company tracked
  • Security incident + breach feed per vendor

Subcontractor Insights

Map fourth-party dependencies and see where concentration risk really lives.

  • Fourth-party concentration analysis
  • Sub-processor disclosure tracking (GDPR)
  • Cascading risk visualization

Vendor questionnaire engine

SIG, CAIQ, and custom templates. AI-assisted responses, auto-scored against your criteria.

  • SIG, CAIQ, and custom templates
  • AI-assisted vendor response (when they opt in)
  • Auto-scored against your criteria
How it works

Three steps from setup to value.

1

Onboard vendors

Add vendors manually or via CSV. Set criticality, assign owners.

2

Assess + monitor

Send assessments through the vendor portal while continuous monitoring runs in parallel.

3

Catch divergence + remediate

Divergence past threshold fires a tiered alert, updates the risk, and generates remediation.

Posture Divergence Detection

When the questionnaire and live exposure disagree, you find out first.

Three-layer scoring on every vendor: Business Criticality, Assessed Posture, and Live External Exposure. When the gap exceeds threshold, divergence fires automatically. The parent risk record updates, a remediation task is generated, and your owners get notified before the next reassessment cycle.

Three layers, one score
Severity tiered alerts
Auto-routes to owners

Compliance automation platforms evaluate vendor evidence against criteria but don't reconcile it against live signals. Ratings-only platforms measure external posture but not assessed posture. ThirdSentry connects both to the same vendor risk record and remediation workflow.

AC
Acme Cloud Storage
Tier 1 · Cloud infrastructure
Severe divergence
Business criticality88/100
Assessed posture87/100
Live external exposure42/100
Posture Divergence Detection
Δ 45 pts

Reported posture is strong (87) but live exposure degraded to 42. Reassessment fired automatically.

See it run on your data.

30-minute walkthrough. No credit card.