Skip to main content
Third-Party Risk Management · Approved Vendor Library · Supply Chain

Know every third party
before they become your liability.

VendorLeak is the third-party risk platform for software vendors and supply chain partners. Scan against your compliance requirements, get plain-language risk verdicts, approve or flag third parties, and keep your entire team aligned. It takes minutes, not weeks.

✓ 14-day free trial·✓ Setup in minutes·✓ Cancel anytime

app.vendorleak.com/dashboard

Third-Party Risk Dashboard

18 vendors & suppliers · 4 require attention

2 VIOLATION2 REVIEW
S
Software
OK

Salesforce CRM

salesforce.com

risk 18

No violations · Policy compliant

G
Supplier
REVIEW

Global Parts Co.

Supply Chain

risk 58

2 compliance gaps flagged for review

A
Software
VIOLATION

Acme Analytics

acmeanalytics.io

risk 88

Sells data to 3rd parties · HIPAA violation

6
Risk categories scored
Approved Vendor Library
Shareable team directory
<2 min
Average assessment time
HIPAA · SOC 2 · GDPR · ISO
Compliance frameworks

One platform. Two categories of third-party risk.

Whether the risk is in your software stack or your supply chain, we have you covered.

Most risk tools are built for one or the other. VendorLeak handles both, so your security, compliance, procurement, and operations teams finally work from one source of truth.

Software & SaaS Vendors

Every tool your team uses, from Slack to Salesforce, dev tools to analytics platforms, assessed automatically against your compliance requirements.

  • Privacy policy & terms of service analysis
  • Data handling and third-party sharing practices
  • Compliance violations mapped to your requirements
  • Breach history and security posture
  • Instant verdict: OK / Review / High / Violation

Supply Chain Partners

Manufacturers, logistics providers, professional services firms, and every operational supplier your business depends on, assessed with the same rigor as your software stack.

  • Breach and security incident history
  • Security certification status (ISO 27001, SOC 2, C-TPAT)
  • Regulatory and compliance posture
  • Operational and concentration risk indicators
  • On-demand breach and incident re-checks

Just paste a URL or company name. VendorLeak auto-populates details and begins the assessment instantly.

Who it’s for

Built for every team in the third-party review chain

Security, compliance, procurement, and operations each get what they need, in minutes rather than months of vendor review cycles.

Security Teams

Run a breach check across your entire third-party portfolio in one click. Every result is stored with the date it was checked, so you can show exactly what was known and when.

  • One-click portfolio breach checks
  • Six-category risk scoring
  • Full scan history & audit trail

Privacy & Compliance

Check vendors and suppliers against HIPAA, GDPR, SOC 2, PCI DSS, or your own custom requirements. Spot violations before you sign.

  • Policy-to-requirement matching
  • GDPR, HIPAA, SOC 2, PCI DSS, SOX
  • Plain-language violation summaries

Procurement Teams

Compare vendors with objective risk scores before you commit. Attach PDF reports to purchase decisions. Set official approval status visible to the whole org.

  • Side-by-side vendor comparison
  • Approval & flagging workflows
  • PDF reports for buying decisions

Operations & Supply Chain

Assess the suppliers your operations depend on: manufacturers, logistics providers, professional services firms. Surface risk before disruption.

  • Supplier risk assessments
  • Certification & compliance tracking
  • Operational risk indicators

How it works

From first scan to full org alignment, in four steps.

Define what matters to your company once. Scan anything. Approve or flag. Monitor forever. Your entire third-party risk lifecycle, in one platform.

01

Define your requirements

Set your compliance framework (HIPAA, SOC 2, GDPR, PCI DSS, ISO 27001) or write custom guidance. Every vendor and supplier gets measured against your standards, not a one-size-fits-all default.

02

Scan any vendor or supplier

Paste a URL or type a company name, and we auto-populate the details and run a full assessment. Works for SaaS tools, software vendors, supply chain partners, and professional services firms.

03

Approve, flag, and publish to your team

Mark each vendor Approved or Not Approved. Everything you approve is published to your team's shared Approved Vendor Library, so any colleague checking a tool sees your decision instantly, with no repeat reviews.

04

Re-check and report

Switch on monitoring for the vendors that matter, then run a breach check across all of them whenever you need one: before a renewal, an audit, or a board review. Download per-vendor or full-portfolio PDF reports.

Approved Vendor Library & Team Governance

Your team’s go-to list of approved tools, always up to date and always shared.

Every vendor you assess and approve is automatically added to your team’s shared Approved Vendor Library. When a colleague wants to adopt a new tool, they check the library first. No starting from scratch, no going around IT, no duplicate reviews. One platform. One source of truth for every tool your org uses.

Official approval status

Mark any vendor or supplier Approved or Not Approved. The decision is visible to your entire workspace, so the next person who considers that tool sees it instantly instead of starting a fresh review.

Colleague request links

Share a link so teammates can submit vendors or suppliers they're considering. They fill in the name or URL, and you get the full risk assessment back in minutes, with no back-and-forth required.

Instant sharing & reporting

Share any assessment with a link. Download per-vendor reports or your full portfolio summary as a PDF, ready for board decks, procurement approvals, or audit submissions.

Vendor decisions, shared with your workspace

S

Salesforce CRM

Software

Reviewed by Security · Jun 2025

APPROVED
S

ShipCo Logistics

Supplier

ISO 27001 verified · No incidents

APPROVED
A

Acme Analytics

Software

Data sold to 3rd parties · HIPAA violation

NOT APPROVED
F

FastParts Inc.

Supplier

Colleague request · Awaiting your decision

REQUESTED
D

DataFlow SaaS

Software

Colleague request · Awaiting your decision

REQUESTED

Share request link → colleagues submit vendors for assessment

Platform capabilities

Everything your team needs to manage third-party risk

Risk verdicts & scoring

Every assessment returns a clear OK / Review / High / Violation verdict plus a 0–100 risk score (higher = more risk) across six weighted categories: data handling, breach posture, subprocessors, compliance evidence, security posture, and contractual posture.

Breach & incident checks

Flag the vendors and suppliers you want to watch, then check them all for known breaches in one click. Each carries a clear green or red status and a dated record of when it was last checked.

Compliance framework matching

Set HIPAA, SOC 2, GDPR, PCI DSS, ISO 27001, CMMC, SOX, or custom requirements. Every assessment is evaluated against your specific framework, not a generic industry checklist.

Approval & governance workflows

Set an official Approved or Not Approved decision for any vendor or supplier. It is shared across your workspace, so every team member sees the same answer and no one duplicates a review.

Approved Vendor Library & team sharing

Your assessed and approved vendors live in a shared team directory, so any colleague checking a tool sees the verdict instantly. Share a request link so teammates can submit new vendors for review without starting from scratch or going around IT.

Auto-detect the tools you already use

Sign in with Google and VendorLeak reads the sender domains in your inbox to find the SaaS vendors your team already uses, then hands you the list to assess. Sender domains only, never message content.

Tier-aware risk thresholds

Classify each vendor from Tier 1 (regulated or customer data) to Tier 4 (public, read-only). Scoring weights and the high-risk line tighten automatically for the tiers that actually touch sensitive data.

Re-scan & trend history

Re-assess any vendor at any time. Every scan is appended to that vendor's history with its score and verdict, so you can show how a vendor's posture changed between reviews.

Per-vendor & portfolio PDF reports

Download a structured report for any single vendor, or your entire third-party portfolio, with risk scores, violation findings, approval status, and policy excerpts. Ready for board decks, audits, and procurement sign-offs.

Compliance frameworks & standards we evaluate against

HIPAASOC 2GDPRPCI DSSISO 27001NIST CSFC-TPATCMMCFedRAMPFERPASOXCustom policy

The problem

Most teams find out about third-party problems too late, and from the wrong source.

You find out in a headline. In an all-hands. In a board meeting where someone asks, “Didn’t we use them?” The damage is already done to your data, your operations, your reputation.

Software vendors write privacy policies for lawyers, not buyers. Supply chain partners have compliance certifications no one on your team has time to verify. By the time someone reads the fine print closely enough to spot a problem, you’ve already signed.

VendorLeak closes the gap. Assessments in under two minutes, breach checks you can run across the whole portfolio on demand, and an approval system that keeps your team aligned across software vendors and supply chain partners.

241 days
Avg. time to identify and contain a breach
IBM Cost of a Data Breach 2025
$4.44M
Global average cost of a data breach
IBM Cost of a Data Breach 2025
<2 min
VendorLeak assessment time per vendor
Policy analyzed automatically
1 platform
Both software AND supply chain covered
No dual tools needed

Pricing

One plan. Every feature. Software vendors and supply chain. $79 / month, flat.

Per workspace, billed monthly. Unlimited assessments for vendors and suppliers, breach monitoring, approval workflows, Approved Vendor Library, colleague sharing, branded PDF reports, and team workspace (up to 4 members). No per-seat charges.

  • Unlimited assessments
  • Software & supply chain
  • Approved Vendor Library
  • Breach monitoring
  • Approval workflows
  • Colleague sharing
  • PDF reports
  • Team workspace
  • Cancel anytime

Know before you sign. Know before you depend on anyone.

Set up your third-party risk workspace in minutes. Start assessing vendors and suppliers immediately.

✓ 14-day free trial·✓ Full access·✓ Cancel anytime