Line 09 · Vendor & supply-chain risk
Third-party risk you can prove — not a questionnaire an intern ticked "yes" on.
Your vendors hold your data. This verifies their actual security posture, quantifies the concentration risk, and gives your lawyer the clauses that transfer it — the documentation procurement and auditors ask for.
Offers
Fixed price, guaranteed
Vendor Security Assessment
$2,000–$4,000 + HSTPer vendor · annual re-assessment
- Criticality classification: business impact, data sensitivity, access level
- Evidence verification: SOC 2 Type II, pen-test summaries, certifications, insurance
- Technical verification: external scan, TLS grade, email authentication, breach history
- Contract-clause recommendations (liability, indemnity, 24-hour breach notice)
- A scored vendor risk register and heat map
GuaranteeFixed price per vendor. Every finding evidence-backed. Contract redlines go to your lawyer, not filed as legal advice.
Who buys
Procurement, GCs and CFOs who need due-diligence on file
Defensible documentation you can show an auditor or insurer, and a clear picture of where your supply-chain risk concentrates.