Assess vendors on their evidence, not just their answers.

Rivedix TPRM sends framework-based questionnaires, checks the answers against the documents vendors upload, scans their public footprint, and follows every finding until it is closed.

Sign in with a one-time code sent to your work email. No password to manage.

SOC 2 · CC6.1 Logical accessSample data
  1. Question

    Is multi-factor authentication enforced for all administrative access?

  2. Vendor answer

    Compliant

  3. Attached evidence

    access-control-policy.pdf, page 7: “MFA is required for staff email accounts.” The admin console is not mentioned.

  4. Finding drafted by AI

    High

    Answer is not supported by the evidence for the admin console.

    Waiting for your reviewer to confirm before it goes to the vendor.

One answer, followed from question to finding.
Frameworks
7
ISO 27001, SOC 2, HIPAA, GDPR, CCPA, DPDP, AIS-189/190, plus your own questions
Scan categories
5
Headers, TLS, open ports, CORS and WAF coverage
PDF report types
6
Executive summary, scorecard, risk register, audit readiness and more
Access control
Audited
Role permissions with per-user overrides, and a log of sensitive actions

Capabilities

Everything a vendor review needs, in one place

From the first questionnaire to the audit report, each step keeps its history so you can show how a decision was made.

  • Questionnaires built from your frameworks

    Pick the frameworks that apply to a vendor and get one merged questionnaire. Overlapping questions across frameworks are combined, and every clause reference is kept.

  • AI findings from answers and evidence

    Vendor answers are checked against the documents they upload. Missing, irrelevant or contradicting evidence becomes a finding with a severity and a suggested remediation.

  • External security scans

    Scan a vendor’s public domain for HTTP header, TLS, open port, CORS and WAF issues. Scores roll up into the vendor’s trust score.

  • Risk register with sign-off

    Track each finding to closure with due dates, vendor Q&A threads, and a recorded risk acceptance when your team decides to live with a gap.

  • Reports for leadership and auditors

    Export executive summaries, vendor scorecards, risk register exports, assessment reports and audit-readiness reports as PDF.

  • Roles, permissions and an audit trail

    Permissions are granted per role, with per-user overrides. Sensitive actions are written to an audit log you can filter and inspect.

Product tour

See what your team works in

Governance / Risk register
Sample data
Open findings
38
Critical
6
Overdue
14
Awaiting vendor
9
IDFindingVendorSeveritySourceStatusDue
RR-1042Admin console has no MFA enforcementNorthwind CloudCriticalAssessment · AIOverdue3 days late
RR-1038Subprocessor listed without a signed DPAContoso PayHighAssessment · AIIn progressDue in 2 days
RR-1031Legacy API endpoint accepts TLS 1.0Fabrikam AnalyticsMediumSecurity scanUnder reviewDue in 12 days
RR-1027SOC 2 Type II report expires within 30 daysTailspin DataHighManualOpenDue in 9 days
RR-1019Missing HSTS header on marketing subdomainLitware SystemsLowSecurity scanOpenDue in 30 days

Roadmap

From new vendor to closed finding

  1. 1

    Add the vendor

    Record what the vendor does and which data they touch. An inherent risk tier is calculated for you.

  2. 2

    Send the assessment

    Choose frameworks, review the generated questions, add your own, and send them to the vendor’s contacts.

  3. 3

    Review the evidence

    Vendors answer and upload proof in their portal. AI flags gaps; your reviewers confirm or reject them.

  4. 4

    Close the findings

    Assign remediation, discuss it with the vendor, then verify the fix or record an accepted risk.

Security posture

A vendor’s public footprint, graded

Each scan scores five areas out of 100 and rolls them into the vendor’s trust score.

  • HTTP headers

    0B

  • TLS

    0A

  • Open ports

    0C

  • CORS policy

    0F

  • WAF coverage

    0A

Sample scores.

Two experiences

A workspace for you, a portal for your vendors

Run the whole review from one console

  • Onboard vendors and keep contacts, certifications and risk tier together
  • Build, review and send assessments
  • Triage findings, assign owners and sign off accepted risks
  • Generate reports and review the audit trail
Create your workspace

Compliance coverage

Assess against the standards you answer to

Clauses and questions for each framework are reviewed by your platform admins before they reach an assessment. You can add your own questions on top.

  • ISO/IEC 27001
  • SOC 2
  • HIPAA Security Rule
  • GDPR
  • CCPA
  • DPDP
  • AIS-189/190

FAQ

Questions teams ask first

How does AI evaluate a vendor’s responses?

It compares each answer with the evidence the vendor attached and with the framework clause behind the question. If an answer claims compliance but the evidence is missing, unreadable or says something different, it drafts a finding. Your team reviews every finding before it goes to the vendor.

What does the external scan check?

It looks at a vendor’s public domain only: HTTP security headers, TLS configuration, open ports, CORS policy and WAF coverage. Nothing is installed on the vendor’s side.

How do vendors sign in?

Vendor contacts use a separate portal and sign in with a one-time code sent to their email. They can complete assigned questionnaires, upload evidence and respond to findings.

Can we assess our own organization too?

Yes. Self-assessment runs the same framework questions against your own controls and produces findings and a score, so you can hold yourself to the standard you set for vendors.

Which frameworks are supported?

ISO/IEC 27001, SOC 2, HIPAA, GDPR, CCPA, DPDP and AIS-189/190 today, plus custom questions you write yourself.

Start your first vendor assessment today

Create a workspace with your work email, pick your frameworks, and invite your first vendor.