Run the whole review from one console
- Onboard vendors and keep contacts, certifications and risk tier together
- Build, review and send assessments
- Triage findings, assign owners and sign off accepted risks
- Generate reports and review the audit trail
Rivedix TPRM sends framework-based questionnaires, checks the answers against the documents vendors upload, scans their public footprint, and follows every finding until it is closed.
Sign in with a one-time code sent to your work email. No password to manage.
Question
Is multi-factor authentication enforced for all administrative access?
Vendor answer
Compliant
Attached evidence
access-control-policy.pdf, page 7: “MFA is required for staff email accounts.” The admin console is not mentioned.
Finding drafted by AI
HighAnswer is not supported by the evidence for the admin console.
Waiting for your reviewer to confirm before it goes to the vendor.
Capabilities
From the first questionnaire to the audit report, each step keeps its history so you can show how a decision was made.
Pick the frameworks that apply to a vendor and get one merged questionnaire. Overlapping questions across frameworks are combined, and every clause reference is kept.
Vendor answers are checked against the documents they upload. Missing, irrelevant or contradicting evidence becomes a finding with a severity and a suggested remediation.
Scan a vendor’s public domain for HTTP header, TLS, open port, CORS and WAF issues. Scores roll up into the vendor’s trust score.
Track each finding to closure with due dates, vendor Q&A threads, and a recorded risk acceptance when your team decides to live with a gap.
Export executive summaries, vendor scorecards, risk register exports, assessment reports and audit-readiness reports as PDF.
Permissions are granted per role, with per-user overrides. Sensitive actions are written to an audit log you can filter and inspect.
Product tour
| ID | Finding | Vendor | Severity | Source | Status | Due |
|---|---|---|---|---|---|---|
| RR-1042 | Admin console has no MFA enforcement | Northwind Cloud | Critical | Assessment · AI | Overdue | 3 days late |
| RR-1038 | Subprocessor listed without a signed DPA | Contoso Pay | High | Assessment · AI | In progress | Due in 2 days |
| RR-1031 | Legacy API endpoint accepts TLS 1.0 | Fabrikam Analytics | Medium | Security scan | Under review | Due in 12 days |
| RR-1027 | SOC 2 Type II report expires within 30 days | Tailspin Data | High | Manual | Open | Due in 9 days |
| RR-1019 | Missing HSTS header on marketing subdomain | Litware Systems | Low | Security scan | Open | Due in 30 days |
Roadmap
Record what the vendor does and which data they touch. An inherent risk tier is calculated for you.
Choose frameworks, review the generated questions, add your own, and send them to the vendor’s contacts.
Vendors answer and upload proof in their portal. AI flags gaps; your reviewers confirm or reject them.
Assign remediation, discuss it with the vendor, then verify the fix or record an accepted risk.
Security posture
Each scan scores five areas out of 100 and rolls them into the vendor’s trust score.
HTTP headers
0B
TLS
0A
Open ports
0C
CORS policy
0F
WAF coverage
0A
Sample scores.
Two experiences
Compliance coverage
Clauses and questions for each framework are reviewed by your platform admins before they reach an assessment. You can add your own questions on top.
FAQ
It compares each answer with the evidence the vendor attached and with the framework clause behind the question. If an answer claims compliance but the evidence is missing, unreadable or says something different, it drafts a finding. Your team reviews every finding before it goes to the vendor.
It looks at a vendor’s public domain only: HTTP security headers, TLS configuration, open ports, CORS policy and WAF coverage. Nothing is installed on the vendor’s side.
Vendor contacts use a separate portal and sign in with a one-time code sent to their email. They can complete assigned questionnaires, upload evidence and respond to findings.
Yes. Self-assessment runs the same framework questions against your own controls and produces findings and a score, so you can hold yourself to the standard you set for vendors.
ISO/IEC 27001, SOC 2, HIPAA, GDPR, CCPA, DPDP and AIS-189/190 today, plus custom questions you write yourself.
Create a workspace with your work email, pick your frameworks, and invite your first vendor.