Platform

One platform for third-party risk

Everything from vendor onboarding to audit-ready evidence — built to run continuously, not once a year.

Vendor risk management

A living register of every third party you depend on — scoped to your organisation and shared across your team.

  • Tiering and Low/Medium/High/Critical risk ratings
  • Domains, IP addresses, fourth parties and contacts
  • Documents with expiry tracking and evidence
  • A roll-up summary and risk profile per vendor
Acme Cloud
Low
Globex Financial
Medium
Umbrella Health
High

Email security posture

Automated DNS checks that grade how well each domain is protected against spoofing and interception.

  • SPF policy strength and DKIM key detection
  • DMARC enforcement (none / quarantine / reject)
  • MTA-STS and DNSSEC checks
  • An A–F grade that feeds each vendor's rating
A
acme.com
C
globex.io
E
umbrella.co

Audits & controls

Run your compliance programs against real frameworks and keep evidence in one place.

  • SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, DPDP
  • Control status workflow with evidence upload
  • Live implementation-progress tracking
  • Overdue-control alerts so nothing lapses
SOC 2 Type II72%
18 Implemented 5 In progress 2 Failed

And everything around it

Questionnaire library

Reusable assessment templates you build once and reuse across vendors.

Vulnerability tracking

CVEs scored by CVSS and EPSS, mapped to a vendor's domains and IPs.

Digest notifications

Weekday email summaries of what needs attention across your org.

Roles & teams

Admin, Analyst and Viewer roles; data scoped to your organisation.

Secure by default

Every page behind authentication, tenant-isolated per organisation.

Fourth-party visibility

Track your vendors' vendors and the concentration risk they carry.

See it on your own vendors

Get started in minutes, or have our team walk you through it.