NEW · The Founders' Circle Grant — full-platform access for select companies. Redeem a grant →
Home  /  Platform  /  Vendor Risk Hub
● Vendor Risk Hub

Score every vendor. In minutes, not weeks.

Drop a domain, walk away, come back to a live scorecard and an AI-authored assessment already on its way to the vendor. Continuous monitoring is included — not a second contract.

30min
domain to live scorecard
100%
AI-drafted assessments
250–900
LiveThreat rating scale
daily
continuous re-scan
What's inside

Vendor Risk Hub capabilities.

Every capability shares one data model and one tamper-evident audit trail with the rest of the platform.

LT

LiveThreat Monitoring

Outside-in scoring every day. We own the scoring stack — no licensed third-party data, no separate invoice.

QFX

QFX Assessment Engine

AI-authored questionnaires from a one-line description, 100% auto-scored, framework-mapped.

SBM

SBOM & Supply Chain

Ingest SBOMs in CycloneDX/SPDX; continuous CVE matching routes findings to ServiceNow or Jira.

CUE

SOC 2 / CUEC Extraction

Drop a vendor's SOC 2 PDF; auditor, period, every TSC, every CUEC and exception extracted.

PRT

Vendor Portal

Branded responder portal auto-reminds vendors; you're notified on submission.

SCR

Security Scorecards

250–900 rating, A–F grade, risk-vector breakdown — for any vendor, no questionnaire required.

Continuous monitoring, included.

Most TPRM platforms stop at the questionnaire — then you go buy scorecards somewhere else. Verisq doesn't. Because we own LiveThreat, continuous external monitoring is part of the platform: every vendor, every day, no second contract.

  • Proprietary scoring stack — we own it, not license it
  • Daily re-scan: new CVEs, breach alerts, cert expiry, drift
  • Discrepancy alerts when self-attestation conflicts with signal
  • No separate invoice, no second procurement cycle
Vendor Risk Hub live
Signal A
Signal B
Signal C

One Hub. One platform behind it.

The Vendor Risk Hub is one of five purpose-built workspaces sharing a single data model and audit trail. Start with SOC 2, expand across the platform.