Vendor Risk Assessor
Automates risk assessment in vendor onboarding
// The problem
Each new vendor = security questionnaire + cert collection (SOC2, ISO, GDPR) + checks = 2-4 weeks. Procurement, security, legal run separately.
// What it does
Vendor name/url → auto intelligence: public security posture, certificates, Crunchbase, financial health, breach history, sub-processors. Risk score + recommendation.
// Value
An enterprise SaaS re-risk-assessed 200 vendors in 3 months (used to take 18 months).
⏱ Setup time: 3-5 gün
// How it works
- 01
Vendor şirket adı + URL + işlev (CRM/email/analytics/etc)
- 02
Public scan: trust center, security.txt, sertifika listesi
- 03
Crunchbase: funding, employee count, founded
- 04
Breach history (HaveIBeenPwned + news)
- 05
Sub-processor listesi (kendi vendorları)
- 06
Risk skoru + procurement onayı için öneri
- 07
Vendor questionnaire (eksik bilgi için) otomatik gönderilir, yanıtlar parse edilir
// Real example
Murat yeni bir analytics tool seçmek istiyor. Vendor Risk: "PostHog: SOC2 Type 2 ✓, ISO 27001 ✓, KVKK uyumlu ✓, breach yok, 3 sub-processor (AWS, Stripe, Vercel), risk skoru 18/100 (düşük). Onaylanabilir." Eskiden bu 2 hafta procurement çalışmasıydı.
// Trigger
Manuel / procurement workflow
// Output channels
// Integrations
// Limits (honest)
- ×Çok özelleşmiş sektörler için (savunma, sağlık) ek manuel doğrulama
- ×Self-hosted vendor'lar için public scan yetersiz
- ×Vendor questionnaire yanıtlamazsa eksik bilgiyle skorlanır (low confidence)
// SSS
01.Yanlış green light verir mi?+
Risk skoru her zaman gerekçeli ve insan onayına sunulur. Asla otomatik onay vermez.
02.Mevcut vendor'lar için?+
Bulk import + toplu risk skorlama. Risk dağılım dashboard.
// Tech stack
// Don't see the one you need? Tell us — we ship in 2 days.
Request this agent →// More in this category