NEW · 10 Vendors Free Forever — no expiration, no card

You have 400 vendors.
You assessed twelve this year.

The other 388 are a question your auditor is going to ask. Verisq scores them all — and monitors them daily, no extra invoice — the AI does the work, your team handles the edge cases.

Onboarded in 12 hours. Per-vendor scoring in 30 minutes. 100% AI-drafted, reviewed only where it matters. No analysts to hire. No consultants to onboard.

FREE · 10 VENDORS · NO CARD

SCORECARD TIME
30min
Vendor domain → live scorecard. Long enough to be thorough, short enough to be useful.
No questionnaire required. No vendor in the loop.
AUTO-SCORING
100%
Drafted by QFX AI. Reviewer accepts, overrides edge cases only, justifies in one click.
Most assessments close with zero override.
<12hrs
Signup → ready to assess. Tenant configured, integrations connected, frameworks live.
Half a day. Same morning, you're operating.
"
CONTINUOUS MONITORING — INCLUDED

Most TPRM platforms stop at the questionnaire.
You go buy the scorecards somewhere else.

Verisq doesn't. Continuous external monitoring is part of the platform — every vendor, every day. No separate invoice. No second contract to negotiate. No procurement cycle to run twice.

That's because we own LiveThreat. Most vendor risk platforms don't own their scorecard data — they license it from a third party and pass the cost on. We built the scoring stack ourselves, so it's just part of what you get.

See how LiveThreat works →
01

The AI does the work

Auto-scoring at 100%. Auto-authored questionnaires from a single description. Auto-extracted SOC 2 reports. Auto-discovered data inventories. Auto-generated RoPAs. Auto-derived findings flowing to the risk register. Every step that was a labor unit becomes a review unit.

02

You handle edge cases only

One operator runs what used to take a team of analysts. The platform routes ambiguous answers, low-confidence AI scores, and contested findings to a review queue. Everything else closes itself. Your reviewer's job becomes the part that actually requires judgment.

03

The audit trail proves it

Every AI-drafted score, every reviewer override, every implied rating accepted, every state transition — captured with actor, model version, prompt path, before-state, after-state, and signature. When the auditor asks "did a human review this," the log answers definitively.

WHAT VERISQ TAKES OFF YOUR PLATE

Six things you used to do
by hand. Now you don't.

Every row is a labor unit Verisq removes. Not a feature. A removed task.

Build the questionnaire from scratch — pull controls, draft questions, weight scoring, define logic
AI drafts it from your one-line description. Sectioned, scored, framework-mapped, ready to send.
Send and chase the vendor for two weeks — manual reminders, escalation emails, status spreadsheets
Vendor portal auto-reminds. You're notified on submission. No spreadsheet.
Score 200 questionnaire items by hand — read every answer, look up evidence, assign weights
100% AI-drafted. You touch 5–15 edge-case items, accept the rest in bulk.
Read every SOC 2 PDF your vendor sends — extract auditor, period, scope, every CUEC by hand
Drop the PDF. Auditor, period, every TSC, every CUEC, every exception extracted automatically.
Re-key everything for the next framework — assess against ISO, then SOC 2, then CSF, then 800-53
One assessment, eight frameworks. Cross-framework propagation surfaces equivalent ratings for review.
Hire a GRC analyst to run the program — recruit, onboard, train, retain (and replace when they leave)
One operator and a review queue. The platform scales the work, not the headcount.

↓ Here's how Verisq does it

HOW IT WORKS

Two timelines. Both measured in hours, not weeks.

First, get the platform live. Twelve hours from signup to ready-to-assess. Then, every vendor you add: thirty minutes from domain entered to scorecard live and assessment dispatched. Two distinct workflows, both run themselves.

Onboard the platform → ready to assess

< 12 hours

From the moment your team signs up. No multi-week implementation, no professional services contract, no consultant hand-holding.

Sign up.

Work email, company name, SKU. No credit card on the Free tier. Tenant provisioned in seconds.

Auto-configure tenant.

Eight frameworks seeded. Risk tiers auto-populated. Default email templates branded with your logo. No setup wizard to walk through.

3
T+4 hr
YOU (OPTIONAL)

Connect integrations.

SSO, ServiceNow, Jira, Teams, PagerDuty — connect what you use. Each takes 5–10 minutes. Skip what you don't.

4
T+12 hr
READY TO ASSESS
VERISQ

Tenant live. Frameworks live. You're operational.

Same morning, you're operating. Add your first vendor. Timeline 2 starts.

TIMELINE 2 · PER VENDOR

Score a vendor → assessment dispatched

30 minutes

Every vendor you add. Drop a domain in, walk away, come back to a live scorecard and an assessment already on its way to the vendor. Then continuous monitoring takes over forever.

1
T+0:00
YOU

Add a vendor domain.

Type acmecorp.com in the add-vendor field. That's the entire input. No questionnaire to pick, no upload, no integration setup.

2
T+5 min
VERISQ

Discover & enrich.

DNS, WHOIS, RDAP, subsidiary mapping, alias detection. Pulls company identity, M&A history, executives, jurisdiction. ~50 fields populated.

3
T+25 min
VERISQ

Scan & score.

External attack-surface scan — IPs, ports, certs, sub-services, CVE correlation, breach feed. Outputs the LiveThreat scorecard: 250–900 rating, A–F grade, risk vector breakdown.

4
T+30 min
SCORECARD + ASSESSMENT LIVE
VERISQ

Scorecard live. Assessment auto-authored and dispatched.

Scorecard renders. AI authors the questionnaire from the vendor profile, mapped to your frameworks. Sent to the vendor responder portal. You don't draft a question. You don't pick a template.

FROM MINUTE 30 ONWARD
When the vendor responds, AI auto-scores 100% of items — you review edge cases only. LiveThreat re-scans daily. New CVEs, breach alerts, certificate expiry, scorecard drift all surface as findings without you re-sending a thing.
See LiveThreat →
JUST WANT THE SCORECARD?
Stop at minute 30. Step 4 still gives you the full scorecard. Don't dispatch the assessment if you don't need it. Many DNBL Free users live here.
DOING M&A?
Same four steps, but the AI prompt profile shifts to deal-team vocabulary, 7-day deadlines tighten, multi-target dispatch lets you run parallel timelines for competitive deals.
WHAT THE AI HANDLES FOR YOU

Sixteen things you used to do by hand.

Every card below is a labor unit Verisq removes. Click any card for the dedicated page.

THE ASSESSMENT ENGINE

QFX Assessment Framework

The questionnaire engine that powers every program. AI-authored, auto-scored, framework-mapped. Full conditional logic, evidence capture, signature workflow, save-and-resume on the responder side. The engine name your auditor will hear in every conversation.

FOUR PROGRAMS · ONE ENGINE

Multi-Category QFX

QFX runs four programs — TPRM, Privacy Reviews, M&A Diligence, Controls Maturity — each with its own subject noun, decision verbs, AI prompt profile, and downstream output handler.

REPLACES TEMPLATE DESIGN

AI-Assisted QFX Authoring

Describe what you need, pick a category and framework, generate. Sectioned questionnaires with control mappings, scoring weights, and conditional logic — drafted automatically by the QFX AI, ready to send.

REPLACES FRAMEWORK CROSS-MAPPING

Cross-Framework Propagation

Assess once. Cover everywhere. Rate a control in one framework; equivalent ratings surface in mapped frameworks for reviewer acceptance. Thousands of mapped pairs across the seeded catalog.

REPLACES ANNUAL VENDOR REVIEWS

LiveThreat Continuous Monitoring

Outside-in scoring, every day. Continuous external risk scoring and breach intelligence via proprietary, industry-aligned methodology. Discrepancy alerts when self-attestation conflicts with external signal.

REPLACES MANUAL CVE TRIAGE

SBOM Continuous Monitoring

Every CVE, every component, every day. Ingest SBOMs in CycloneDX or SPDX. Pull from JFrog Xray, GitHub Dependency Graph, AWS Inspector. Findings auto-route to ServiceNow AVR or Jira.

REPLACES THE RISK SPREADSHEET

RiskOps

Risks as first-class objects with a six-state lifecycle and five treatment strategies. Auto-generated from assessments, scans, breach feeds, and SOC 2 exception extraction. Accept-strategy plans capture executive approval for SOX and ISO 31000 evidence. Bidirectional sync with ServiceNow and Jira.

REPLACES THE TWO-WEEK DILIGENCE PACK

M&A Diligence Pack

Deal-team vocabulary (Green-light / Red-flag), 7-day deadlines, multi-target dispatch for competitive deals, AI prompt profile tuned for in-flight breaches and regulatory exposure.

REPLACES THE QUARTERLY SURVEY DRILL

Internal Controls Assessment

Self-assessment that the board will read. Controls Maturity programs with CMMI-aligned 1–5 tier ladder, recurring annual cadence, prior-cycle pre-population, longitudinal posture trends.

REPLACES READING SOC 2 PDFS BY HAND

SOC 2 / CUEC AI Extraction

Drop a SOC 2 PDF; the platform extracts auditor, period, scope, every TSC, every CUEC, every exception, every subservice org. Auto-creates findings for failed CUECs.

REPLACES DISCONNECTED PRIVACY PROCESSES

PrivacyOps

Automated database discovery and classification across 241 master attributes in 23 PII categories. RoPA generation in three regulatory formats from one inventory. End-to-end DSAR automation through the public privacy center. The same data inventory feeds discovery, RoPA, DSAR, retention, and consent-aware marketing.

REPLACES ANNUAL ROPA REBUILDS

Automated RoPA Generation

Article 30 done. CCPA disclosure done. Record of Processing Activities derived from the data flow inventory and exported in GDPR Article 30, CCPA/CPRA, or framework-agnostic formats — three regulatory exports from one inventory.

REPLACES THE ENGINEERING TICKET QUEUE

End-to-End DSAR Automation

Subjects authenticate to the privacy center, request access, and download their own data. Discovery and classification feed the DSAR workflow without an engineer touching production. Ten-stage lifecycle, jurisdiction-aware SLAs, regulatory evidence package on demand.

REPLACES MANUAL CONSENT RECONCILIATION

Compliant Marketing Lists

Consent-aware list construction. Suppression of withdrawn consent and opted-out subjects propagates automatically. Legal-basis tagging on every export.

REPLACES RETENTION-POLICY DRAFTING

Retention Policy Library

Pre-defined policies anchored to regulatory citations (GDPR, HIPAA, SOX, CCPA, ePrivacy) and assignable to datastores or master attributes. Notifications fire before expiry. Marketing-class data eligible for auto-deletion; sensitive categories require operator approval through the deletion runbook.

REPLACES FRAMEWORK SETUP

Eight Frameworks + FedRAMP

Seeded, cross-mapped, and ready. NIST CSF 2.0, ISO 27001:2022, SOC 2, 800-53 r5 with FedRAMP Low/Moderate/High, GDPR, HIPAA, PCI DSS 4.0, CIS v18. Tenant-private frameworks for internal standards layer on top.

FRAMEWORK INTELLIGENCE LAYER

Eight frameworks. Fully cross-mapped.

Assessing one framework establishes posture across mapped controls in all the others. Non-destructive — it surfaces candidates for reviewer acceptance, never auto-writes across frameworks.

NIST CSF
v2.0 · 2024
6 functions · 22 categories · 108 subcategories
800-53
Rev 5 + FedRAMP
20 families · 500+ controls · L/M/H baselines
ISO 27001
2022
4 themes · 93 controls (11 new in 2022)
SOC 2
2017 (revised)
5 categories · 61 trust services criteria
PCI DSS
v4.0 · 2022
12 requirements · 78 sub-requirements
CIS
v18 · 2021
18 controls · 153 safeguards
GDPR
2018
Articles 5–47 as control objectives
HIPAA
1996+
Privacy · Security · Breach Notification
+ Yours
TENANT-PRIVATE
Add internal standards alongside the seeded eight
DRIFT
REPORT
Weekly digest of divergence between mapped pairs
See cross-framework propagation →
THE OBJECTION THAT CLOSES DEALS

Audit trails worth defending.

Every action — every override, every decision, every implied rating accepted, every AI generation, every state transition, every data flow auto-derived, every DSAR fulfilled — captured with actor, timestamp, before/after state, and free-text justification.

Compliance Pack Export bundles the full trail in a signed archive auditors can verify independently.

See audit defensibility →
Append-only audit log — every state transition captured forever
AI Generation Log — model, prompt version, path, when, by whom
Decision Audit — verb, notes, signature, IP, user agent, findings opened
Privacy Operation Audit — every classification, flow, DSAR, retention notification
Compliance Pack Export — signed manifest, independently verifiable
Retention & legal holds — indefinite by default, hold pins entities
10
PERMANENT FREE PLAN · NO EXPIRATION
10 vendors. Free. Forever.

Scorecards, scans, send-only assessments. Lifetime cap of 10 vendors — upgrade when you need #11. No card.

Start Free →

By Friday, you can have all 400 vendors scored.

Onboard in 12 hours. Score thirty vendors a day. The AI does the work; your team reviews the edge cases. The audit packet writes itself as you go.