Free · instant · no signup
Grade a vendor's posture before you sign
Enter a vendor's domain. We grade the same public security signals an attacker or an examiner would check first — then give you the questions to ask that a public check can't answer.
External hygiene only. A good grade is necessary, not sufficient — see the questions below.
- Do you have a current SOC 2 Type II (or ISO 27001) report we can review?
- Is MFA enforced for all employee and administrative access?
- What is your incident-response and breach-notification commitment, and in what timeframe?
- Which subprocessors touch our data, and where is it stored?
- How do you handle offboarding and data return/deletion at contract end?
- When was your last penetration test, and can we see the summary?
Try a vendor you're evaluating. The grade takes about 20 seconds and reads only public DNS and HTTP settings — nothing intrusive.
Why it matters
Your risk is the sum of your vendors' risk
Most reported security incidents trace to a third party. Regulators increasingly expect documented due diligence proportionate to the data and access each vendor has — and "we sent a questionnaire" isn't the same as evidence. This check gives you a fast, objective first read so you know which vendors deserve a deeper look.
Turn a vendor list into a risk-ranked program
We build tiered third-party risk programs: inventory, due diligence proportionate to access, contract clauses, and ongoing monitoring — the version examiners accept as evidence.