Vendor Risk Scorer

Assess third-party vendor security across 8 weighted domains

Score vendor security posture across 8 weighted domains: Data Handling, Access Control, Compliance, Incident Response, Network Security, Secure Development (SDLC), Governance, and Physical Security. Generates a weighted overall score, risk tier classification, engagement recommendation, and identifies priority improvement areas. Supports 7 vendor types for contextualized assessment.

Vendor Risk Assessment

Security Domain Scores

Rate the vendor on each security domain (0 = not assessed, 1 = critical gaps, 7 = excellent).

How well does the vendor protect data? (encryption, classification, retention, DLP)
MFA, RBAC, SSO, privileged access management, password policies
SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, regulatory alignment
IR plan, notification SLA, disaster recovery, business continuity
Firewall, IDS/IPS, segmentation, vulnerability management, patching
Secure coding practices, code review, SAST/DAST, dependency scanning
Security policies, risk assessments, security team, board oversight
Data center security, physical access controls, environmental protections
Enjoy these free tools?

Support the project and help keep it ad-light.

Buy Me a Coffee