Products · Vendor Assessments

Vendor risk assessments your vendors actually complete.

Send SIG, CAIQ, or custom security assessments through a portal built for the vendor on the other end, with AI-assisted responses when they opt in. Responses are auto-scored against your criteria, validated by your reviewers, and carried straight into remediation on the same vendor record. Built to cut assessment cycle time by more than half compared to spreadsheet and email chases, an illustrative target.

What you get

From sent to scored to remediated, on one record.

SIG, CAIQ, and custom templates

Start from industry-standard SIG or CAIQ templates or build custom assessments matched to your own criteria and vendor tiers. Scope the depth to the vendor's criticality so a low-risk supplier is not answering 300 questions.

  • SIG and CAIQ templates ready to send
  • Custom questionnaires built to your criteria
  • Assessment depth scoped by vendor tier

A portal vendors want to finish

Vendors respond in a dedicated portal with clear progress and the ability to attach evidence inline. When a vendor opts in, AI-assisted drafting helps them answer faster from their own documentation. Faster completion for them means faster closure for you.

  • Dedicated vendor portal with progress tracking
  • AI-assisted vendor responses, strictly opt-in
  • Evidence attached inline as they answer

Automatic scoring against your criteria

Every response is scored automatically against the criteria you defined, not a generic rubric. Weak or contradictory answers are flagged for follow-up, and the assessed posture feeds the vendor's three-layer risk score alongside criticality and live exposure.

  • Scoring runs against your defined criteria
  • Weak and contradictory answers flagged
  • Assessed posture feeds the vendor risk score

Evidence collected, not just claimed

Assessments collect the artifacts behind the answers: certifications, reports, policies, attestations. Evidence attaches to the specific response and to the vendor record, so a claim and its proof never separate. Once linked to an approved assessment, evidence is immutable.

  • Evidence requested per question, not per email
  • Artifacts linked to both response and vendor record
  • Immutable once linked to an approved assessment

Reviewer validation with final say

AI scoring accelerates the read, but your reviewers hold precedence. A reviewer can override any AI score, and the override always wins. Every decision is attributed and audit-logged, which is what makes the result defensible when someone asks how a vendor was approved.

  • Reviewer decisions always override AI scores
  • Every override attributed and audit-logged
  • Approval trail defensible to auditors

Remediation and reassessment, connected

Failed criteria generate remediation tasks that vendors track and close in the same portal. When a reassessment completes, it resets the continuous monitoring baseline, so assessments and monitoring stay one connected program instead of two disconnected calendars.

  • Remediation tasks generated from failed criteria
  • Vendors close tasks in the same portal
  • Completed reassessments reset the monitoring baseline
How it works

Three steps from setup to value.

1

Build and send

Pick SIG, CAIQ, or a custom template, scope it to the vendor's tier, and send it through the vendor portal. The vendor gets a clear task list, not a spreadsheet attachment.

2

Score and validate

Responses are auto-scored against your criteria as they arrive, with evidence attached inline. Your reviewers validate the results, and their decisions always override the AI.

3

Remediate and reassess

Findings become remediation tasks on the same vendor record, tracked to closure in the portal. Each completed reassessment re-anchors continuous monitoring, so the next year is covered too.

This page covers the assessments you send to vendors. For the security questionnaires your customers send to you, see the Questionnaire Engine, which drafts cited answers from your own controls and evidence. And for what happens in the months after an assessment closes, see Continuous Vendor Monitoring.

See it run on your data.

30-minute walkthrough. No credit card.