SaaSint Vendor Risk
Vendor risk, evidenced and audit-ready.
SaaSint Vendor Risk keeps every vendor's security and compliance evidence in one place: questionnaires, documents with expiry reminders, explainable risk scores and reports your auditor can trace.
No card required.
For teams reviewing vendors under
Why it matters
Your vendors' security is your security. When an auditor asks, the answer shouldn't live in forty spreadsheets.
The platform
Assess, evidence, prove. One place.
Assess
Ask every vendor the same questions, the same way.
- Questionnaire builder with Yes/No, choice and free-text questions
- Secure links: vendor contacts answer without an account
- Flag the answers that signal risk, by severity
Evidence
Keep the documents that back the answers, and know when they lapse.
- SOC 2 reports, certificates and DPAs per vendor
- Expiry dates with email digests at 30 days, 7 days and on the day
- Private storage, downloads through 60-second links
Prove
Show your auditor the risk, and the reasons behind it.
- Scores from 0 to 100, every point traced to a finding
- Heatmap of the tier you assigned against computed risk
- PDF reports, and an append-only audit log enforced by the database
Explainable scores
Every point has a reason you can show.
A flagged answer, an expired report, an assessment older than a year: each adds points you can trace. The heatmap sets the risk you computed against how critical you said each vendor is, so the vendors that matter most stand out.
How we work
Explainable, not magic
Scores come from published rules, not a black box. Every point on a vendor's score names the answer, document or date that caused it.
Honest about certification
We're not SOC 2 certified yet, and we say so. We build to SOC 2-aligned practices and publish exactly what's done and what's planned.
Lean to adopt
No consultants, no rollout project. Add vendors, send a questionnaire, upload evidence, and your first report is ready the same day.
Security
Held to the standard we help you check.
A compliance tool has to earn trust itself. Customer data is separated in the database, not just in our code, and we tell you plainly what we've certified and what we haven't, yet.
- Tenant isolation enforced by Postgres row-level security
- Append-only audit log, enforced by the database
- Vendor links stored only as hashes, revocable at any time
- Evidence in private storage, served by 60-second links
- Payments by Dodo Payments; card details never reach us
See your vendor risk in one view.
14 days free, up to 25 vendors, no card. Or talk to us about a larger programme.