Growth+ Feature

Know the Risk of Every Vendor You Share Data With

Automated 0–100 security scoring for every data processor. Breach history, SSL validation, certifications, domain age, and DPO sign-off — no spreadsheets, no paid APIs.

Risk score breakdown
30 pts
Security Certification
ISO 27001, SOC 2, PCI-DSS, CERT-In
25 pts
Known Breach History
HIBP + databreach.com lookup
20 pts
SSL/TLS Validity
Real-time certificate check
15 pts
Domain Age (2+ years)
RDAP free lookup
10 pts
DPO Formal Sign-off
12-month review cadence

From vendor list to risk-scored portfolio

1
Sync from inventory
All Third-Party assets from your Data Inventory automatically appear as vendors. No manual re-entry.
2
Enrich vendor
One click triggers automated checks: SSL/TLS validation, breach history lookup, domain age via RDAP, and certificate verification.
3
Upload certification
Log security certifications (ISO 27001, SOC 2, PCI-DSS, CERT-In) with document upload and expiry tracking.
4
DPO sign-off
Your DPO formally signs off on each vendor. 12-month expiry creates a structured annual review cadence.
5
Monitor risk portfolio
Portfolio command bar shows average score, tier distribution, and action queue for vendors needing attention.

Complete vendor security intelligence

Auto

Automated Risk Scoring 0–100

5 factors: Security cert (30pts), breach history (25pts), SSL validity (20pts), domain age (15pts), DPO sign-off (10pts). No paid APIs.

Breach Detection

HIBP v2 + databreach.com breach lookups. Cached in Redis for performance. Flags vendors with known historical or recent breaches.

Certification Tracker

ISO 27001, SOC 2 Type I/II, PCI-DSS, CERT-In, CSA STAR. Upload certificate documents to R2. Expired certs auto-reduce score.

DPA Compliance Banner

Each vendor card shows DPA status (DPDPA S.8(2)): signed, missing, or expired. Not a score factor — a compliance requirement.

Risk Matrix (Scatter Chart)

Visualise your entire vendor portfolio: data sensitivity on X-axis, risk score on Y-axis. Click any dot to jump to that vendor.

Export

Vendor PDF Report

Generate a board-ready vendor risk report: cover page, portfolio summary, per-vendor score breakdown. Stored immutably in R2.

0–100
Risk score
5
Score factors
0
Paid APIs used
Weekly
Auto re-enrichment
Available from Growth plan onwards

Vendor Risk Intelligence is available on Growth, Business, and Enterprise plans.

DPDPA processor obligations — answered

What does DPDPA S.8(2) require for data processors?+

DPDPA S.8(2) requires every Data Fiduciary to ensure that any Data Processor they engage handles personal data only as directed and implements security safeguards that are contractually specified. This means: (1) a written Data Processing Agreement must exist before any processing begins, and (2) the DPA must specify security standards. DPDPA Shield's vendor risk module tracks both the DPA status and the vendor's actual security posture independently.

How is the vendor risk score calculated?+

The score uses 5 factors with no paid APIs: Security Certification (30 points — ISO 27001/SOC 2/PCI-DSS/CERT-In full cert = 30, Type I/CSA STAR = 18, expired = 5, none = 0), Known Public Breaches (25 points — no breach = 25, historical = 8, recent = 0), Valid SSL/TLS (20 points — checked via Node TLS), Domain Age over 2 years (15 points — RDAP lookup), and DPO Formal Sign-off (10 points — 12-month review cycle). Total risk tiers: LOW (≥80), MEDIUM (60–79), HIGH (40–59), CRITICAL (<40).

Why is DPA status shown separately and not in the score?+

DPA status (DPDPA S.8(2)) is a binary compliance requirement, not a risk factor. A vendor can have excellent security and still be non-compliant if you have no DPA with them. Conversely, a DPA doesn't mean the vendor is secure. We surface the DPA status as a prominent compliance banner on every vendor card so you can act on it independently from the security score.

Which plans include Vendor Risk Intelligence?+

Vendor Risk Intelligence is available on Growth, Business, and Enterprise plans. It includes automated enrichment, certification tracking, DPO sign-off workflow, and PDF report generation. Starter plan users do not have access to this module.

Score every vendor before the regulator asks.

Growth plan includes full vendor risk intelligence. Weekly automated re-enrichment keeps scores current.