You send every vendor the same 200-question spreadsheetAnd read none of the answers

Sizes each vendor questionnaire to its criticality, reads every piece of evidence against the one control it belongs to, and turns the whole book into a graded portfolio you can actually reason about.

Try it

Interactive demo with a scored vendor portfolio, no signup, no cloud account

How It Works

Score, scope, review, rank.

01

Score

Each vendor is rated across five weighted dimensions before a question is asked, producing an inherent criticality tier from Low to Critical.

02

Scope

The tier sets the questionnaire budget, 25 questions for a low-criticality vendor, 120 for a critical one, drawn from an eleven-framework bank, with held certifications short-circuiting the domains they attest.

03

Review

Every uploaded document is mapped to exactly one control and judged against that control’s checks, so an expired-but-genuine attestation is caught rather than filed as evidence.

04

Rank

Answers roll into a maturity score, gated at 70 percent coverage, which shifts inherent criticality into a residual tier, recomputed on every save with a written rationale.

What You Can Do

Everything the platform does.

Criticality scored before questions

Five weighted dimensions, operational, data sensitivity, regulatory, financial and lock-in, produce an inherent tier that sizes everything downstream. A payment processor and a font CDN are not assessed the same way.

See it in the demo

Right-sized questionnaires

The tier sets a question budget, so a vendor answers what matters for its risk rather than a fixed spreadsheet. Certifications skip the domains they attest, each skip carrying a written rationale.

See it in the demo

An 11-framework, 3,896-question bank

PCI DSS, ISO 27001, SOC 2, the cloud and AI ISO standards, GDPR, HIPAA, and the RBI, SEBI and MAS financial-sector frameworks, one bank behind every questionnaire.

See it in the demo

One answer, every framework

Answer a control once and it satisfies every framework that references it, with the confidence shown per framework. Anything below 85 percent is routed to human review rather than silently accepted.

See it in the demo

Evidence mapped, then judged

Each file is mapped to exactly one control and reviewed only against that control’s checks, never “the file exists”. A signed attestation that is fifteen months out of date is marked non-compliant, with the reason.

See it in the demo

Maturity with a coverage gate

Answers are tier-weighted into a 0-100 maturity score, but maturity only counts once 70 percent of scoped controls are answered. Below that it is gated, because a strong score from three answers evidences nothing.

See it in the demo

Residual risk you can read

Residual is inherent criticality shifted by maturity band, recomputed on every save, and every residual carries a sentence of rationale rather than a bare coloured pill.

See it in the demo

A graded portfolio

An A-to-F portfolio grade computed live from residual risk, a residual-tier distribution, a trend line, and the vendor book ranked by exposure, with concentration and outstanding assessments surfaced.

See it in the demo

A copilot over the whole book

Ask which critical vendors have a stale attestation, or where risk concentrates, and get an answer reasoned across every vendor, role-scoped so a vendor contact sees only their own record, and audit-logged.

See it in the demo

Business Outcomes

What it changes.

Sized

Vendors answer questions proportional to their risk, so the questionnaire gets completed instead of abandoned at question forty.

Read

Evidence is judged against the control it belongs to, so an expired attestation is caught rather than counted.

Honest

A vendor with too few answers is shown as gated, not given a maturity score its coverage cannot support.

See your vendor book as a graded portfolio.

Add a vendor and the assessment sizes itself, reads the evidence and computes residual risk in minutes.