Skip to content

SaaSint Vendor Risk

Vendor risk, evidenced and audit-ready.

SaaSint Vendor Risk keeps every vendor's security and compliance evidence in one place: questionnaires, documents with expiry reminders, explainable risk scores and reports your auditor can trace.

No card required.

For teams reviewing vendors under

POPIAGDPRISO 27001SOC 2NIS2DORA

Why it matters

Your vendors' security is your security. When an auditor asks, the answer shouldn't live in forty spreadsheets.

The platform

Assess, evidence, prove. One place.

01

Assess

Ask every vendor the same questions, the same way.

  • Questionnaire builder with Yes/No, choice and free-text questions
  • Secure links: vendor contacts answer without an account
  • Flag the answers that signal risk, by severity
02

Evidence

Keep the documents that back the answers, and know when they lapse.

  • SOC 2 reports, certificates and DPAs per vendor
  • Expiry dates with email digests at 30 days, 7 days and on the day
  • Private storage, downloads through 60-second links
03

Prove

Show your auditor the risk, and the reasons behind it.

  • Scores from 0 to 100, every point traced to a finding
  • Heatmap of the tier you assigned against computed risk
  • PDF reports, and an append-only audit log enforced by the database

Explainable scores

Every point has a reason you can show.

A flagged answer, an expired report, an assessment older than a year: each adds points you can trace. The heatmap sets the risk you computed against how critical you said each vendor is, so the vendors that matter most stand out.

How we work

Explainable, not magic

Scores come from published rules, not a black box. Every point on a vendor's score names the answer, document or date that caused it.

Honest about certification

We're not SOC 2 certified yet, and we say so. We build to SOC 2-aligned practices and publish exactly what's done and what's planned.

Lean to adopt

No consultants, no rollout project. Add vendors, send a questionnaire, upload evidence, and your first report is ready the same day.

Security

Held to the standard we help you check.

A compliance tool has to earn trust itself. Customer data is separated in the database, not just in our code, and we tell you plainly what we've certified and what we haven't, yet.

  • Tenant isolation enforced by Postgres row-level security
  • Append-only audit log, enforced by the database
  • Vendor links stored only as hashes, revocable at any time
  • Evidence in private storage, served by 60-second links
  • Payments by Dodo Payments; card details never reach us

See your vendor risk in one view.

14 days free, up to 25 vendors, no card. Or talk to us about a larger programme.