Know every third party
before they become your liability.
VendorLeak is the third-party risk platform for software vendors and supply chain partners. Scan against your compliance requirements, get plain-language risk verdicts, approve or flag third parties, and keep your entire team aligned. It takes minutes, not weeks.
✓ 14-day free trial·✓ Setup in minutes·✓ Cancel anytime
Third-Party Risk Dashboard
18 vendors & suppliers · 4 require attention
Salesforce CRM
salesforce.com
No violations · Policy compliant
Global Parts Co.
Supply Chain
2 compliance gaps flagged for review
Acme Analytics
acmeanalytics.io
Sells data to 3rd parties · HIPAA violation
- 6
- Risk categories scored
- Approved Vendor Library
- Shareable team directory
- <2 min
- Average assessment time
- HIPAA · SOC 2 · GDPR · ISO
- Compliance frameworks
One platform. Two categories of third-party risk.
Whether the risk is in your software stack
or your supply chain, we have you covered.
Most risk tools are built for one or the other. VendorLeak handles both, so your security, compliance, procurement, and operations teams finally work from one source of truth.
Software & SaaS Vendors
Every tool your team uses, from Slack to Salesforce, dev tools to analytics platforms, assessed automatically against your compliance requirements.
- Privacy policy & terms of service analysis
- Data handling and third-party sharing practices
- Compliance violations mapped to your requirements
- Breach history and security posture
- Instant verdict: OK / Review / High / Violation
Supply Chain Partners
Manufacturers, logistics providers, professional services firms, and every operational supplier your business depends on, assessed with the same rigor as your software stack.
- Breach and security incident history
- Security certification status (ISO 27001, SOC 2, C-TPAT)
- Regulatory and compliance posture
- Operational and concentration risk indicators
- On-demand breach and incident re-checks
Just paste a URL or company name. VendorLeak auto-populates details and begins the assessment instantly.
Who it’s for
Built for every team in the third-party review chain
Security, compliance, procurement, and operations each get what they need, in minutes rather than months of vendor review cycles.
Security Teams
Run a breach check across your entire third-party portfolio in one click. Every result is stored with the date it was checked, so you can show exactly what was known and when.
- One-click portfolio breach checks
- Six-category risk scoring
- Full scan history & audit trail
Privacy & Compliance
Check vendors and suppliers against HIPAA, GDPR, SOC 2, PCI DSS, or your own custom requirements. Spot violations before you sign.
- Policy-to-requirement matching
- GDPR, HIPAA, SOC 2, PCI DSS, SOX
- Plain-language violation summaries
Procurement Teams
Compare vendors with objective risk scores before you commit. Attach PDF reports to purchase decisions. Set official approval status visible to the whole org.
- Side-by-side vendor comparison
- Approval & flagging workflows
- PDF reports for buying decisions
Operations & Supply Chain
Assess the suppliers your operations depend on: manufacturers, logistics providers, professional services firms. Surface risk before disruption.
- Supplier risk assessments
- Certification & compliance tracking
- Operational risk indicators
How it works
From first scan to full org alignment, in four steps.
Define what matters to your company once. Scan anything. Approve or flag. Monitor forever. Your entire third-party risk lifecycle, in one platform.
Define your requirements
Set your compliance framework (HIPAA, SOC 2, GDPR, PCI DSS, ISO 27001) or write custom guidance. Every vendor and supplier gets measured against your standards, not a one-size-fits-all default.
Scan any vendor or supplier
Paste a URL or type a company name, and we auto-populate the details and run a full assessment. Works for SaaS tools, software vendors, supply chain partners, and professional services firms.
Approve, flag, and publish to your team
Mark each vendor Approved or Not Approved. Everything you approve is published to your team's shared Approved Vendor Library, so any colleague checking a tool sees your decision instantly, with no repeat reviews.
Re-check and report
Switch on monitoring for the vendors that matter, then run a breach check across all of them whenever you need one: before a renewal, an audit, or a board review. Download per-vendor or full-portfolio PDF reports.
Approved Vendor Library & Team Governance
Your team’s go-to list of approved tools, always up to date and always shared.
Every vendor you assess and approve is automatically added to your team’s shared Approved Vendor Library. When a colleague wants to adopt a new tool, they check the library first. No starting from scratch, no going around IT, no duplicate reviews. One platform. One source of truth for every tool your org uses.
Official approval status
Mark any vendor or supplier Approved or Not Approved. The decision is visible to your entire workspace, so the next person who considers that tool sees it instantly instead of starting a fresh review.
Colleague request links
Share a link so teammates can submit vendors or suppliers they're considering. They fill in the name or URL, and you get the full risk assessment back in minutes, with no back-and-forth required.
Instant sharing & reporting
Share any assessment with a link. Download per-vendor reports or your full portfolio summary as a PDF, ready for board decks, procurement approvals, or audit submissions.
Vendor decisions, shared with your workspace
Salesforce CRM
SoftwareReviewed by Security · Jun 2025
ShipCo Logistics
SupplierISO 27001 verified · No incidents
Acme Analytics
SoftwareData sold to 3rd parties · HIPAA violation
FastParts Inc.
SupplierColleague request · Awaiting your decision
DataFlow SaaS
SoftwareColleague request · Awaiting your decision
Share request link → colleagues submit vendors for assessment
Platform capabilities
Everything your team needs to manage third-party risk
Risk verdicts & scoring
Every assessment returns a clear OK / Review / High / Violation verdict plus a 0–100 risk score (higher = more risk) across six weighted categories: data handling, breach posture, subprocessors, compliance evidence, security posture, and contractual posture.
Breach & incident checks
Flag the vendors and suppliers you want to watch, then check them all for known breaches in one click. Each carries a clear green or red status and a dated record of when it was last checked.
Compliance framework matching
Set HIPAA, SOC 2, GDPR, PCI DSS, ISO 27001, CMMC, SOX, or custom requirements. Every assessment is evaluated against your specific framework, not a generic industry checklist.
Approval & governance workflows
Set an official Approved or Not Approved decision for any vendor or supplier. It is shared across your workspace, so every team member sees the same answer and no one duplicates a review.
Approved Vendor Library & team sharing
Your assessed and approved vendors live in a shared team directory, so any colleague checking a tool sees the verdict instantly. Share a request link so teammates can submit new vendors for review without starting from scratch or going around IT.
Auto-detect the tools you already use
Sign in with Google and VendorLeak reads the sender domains in your inbox to find the SaaS vendors your team already uses, then hands you the list to assess. Sender domains only, never message content.
Tier-aware risk thresholds
Classify each vendor from Tier 1 (regulated or customer data) to Tier 4 (public, read-only). Scoring weights and the high-risk line tighten automatically for the tiers that actually touch sensitive data.
Re-scan & trend history
Re-assess any vendor at any time. Every scan is appended to that vendor's history with its score and verdict, so you can show how a vendor's posture changed between reviews.
Per-vendor & portfolio PDF reports
Download a structured report for any single vendor, or your entire third-party portfolio, with risk scores, violation findings, approval status, and policy excerpts. Ready for board decks, audits, and procurement sign-offs.
Compliance frameworks & standards we evaluate against
The problem
Most teams find out about third-party problems too late, and from the wrong source.
You find out in a headline. In an all-hands. In a board meeting where someone asks, “Didn’t we use them?” The damage is already done to your data, your operations, your reputation.
Software vendors write privacy policies for lawyers, not buyers. Supply chain partners have compliance certifications no one on your team has time to verify. By the time someone reads the fine print closely enough to spot a problem, you’ve already signed.
VendorLeak closes the gap. Assessments in under two minutes, breach checks you can run across the whole portfolio on demand, and an approval system that keeps your team aligned across software vendors and supply chain partners.
Pricing
One plan. Every feature. Software vendors and supply chain. $79 / month, flat.
Per workspace, billed monthly. Unlimited assessments for vendors and suppliers, breach monitoring, approval workflows, Approved Vendor Library, colleague sharing, branded PDF reports, and team workspace (up to 4 members). No per-seat charges.
- Unlimited assessments
- Software & supply chain
- Approved Vendor Library
- Breach monitoring
- Approval workflows
- Colleague sharing
- PDF reports
- Team workspace
- Cancel anytime
Know before you sign. Know before you depend on anyone.
Set up your third-party risk workspace in minutes. Start assessing vendors and suppliers immediately.
✓ 14-day free trial·✓ Full access·✓ Cancel anytime