Your suppliers play by your rules. Vendor risk assessment ranks everyone who can reach your data by what they would cost you.

  • Every supplier that can reach your data, ranked by what it would cost you
  • Evidence, rather than a certificate nobody has read the scope of
  • Contract wording and remediation asks you can send as they are

We start from who can actually reach your data

The list nobody has

Integrations, VPN accounts, admin logins and file shares handed over once and never withdrawn. Most estates cannot produce this list. That is finding one.

Ranked by consequence, not by size

A small firm holding your customer database outranks a large one that prints your brochures. The order comes from what a failure would cost you.

Evidence instead of assurances

A certificate whose scope statement excludes the service you actually buy is the most common thing we find. We read the scope, not the logo.

Something you can act on

Notification periods, the right to audit, and rules for their own sub-processors - written so you can put them in front of the supplier.

What we look at, supplier by supplier

Access
Accounts, VPNs and APIs each supplier holds - and whether any of it is still needed.
Data
What leaves the business to them, in what form, and which country it comes to rest in.
Certification
What the certificate actually covers. The scope statement, read rather than filed.
Practices
Patching, incident notification, background checks, and who they subcontract to.
Concentration
Which single failure would stop more than one part of your business at once.
Contract
Notification periods, right to audit, and what happens to your data when it ends.

How it works

01

Establish who is connected

We build the list from your own systems, not from memory: who holds an account, an integration or a copy of your data, including the unnamed.

02

Assess and rank

Each one is assessed on access, evidence and practices, then ranked by what its failure would cost you. The order is consequence, not size.

03

Hand over the asks

You get the remediation requests and the contract wording per supplier, ready to send. We can run the conversations with them if you would rather not.

What you get

A ranked list, and the asks that go with it

Every supplier scored on what a failure would cost you rather than on size, each with its specific evidence gap. Plus the remediation requests and contract wording, ready to send.

Find out which supplier is the one to worry about

We start from the ones that can reach your data, and rank them by what a failure would actually cost you.