Search the vendors you already use. If they’re in our library, you click add — monitoring activates immediately. If they’re not, upload your list and we’ll add them within 24 hours.
Each vendor in the library is already scored against GDPR, ISO 27001, SOC 2, NIS2, DORA and CRA.
Certificates, breaches, sub-processor changes and policy updates monitored on a daily cycle.
CSV, Excel, Okta or Google Workspace import. We dedupe, enrich, and onboard within a day.
ZeroRisk Certificates available the moment a library vendor is added to your scope.
Each of the 10,000+ vendors in the library carries a maintained profile: current certifications (SOC 2, ISO 27001 and friends) with their validity windows, breach and incident history, sub-processor lists, policy and terms changes, and the mapping of all of it onto GDPR, ISO 27001, SOC 2, NIS2, DORA and CRA requirements. When you add a vendor to your scope, you inherit that work — the assessment starts answered instead of blank.
The 24-hour re-check is what makes the library different from a static catalog. A certification lapses, a breach is disclosed, a sub-processor appears: the change lands in your findings the next day, triaged, with the vendors it affects. You hear about the changes that move your risk — not a daily feed of noise.
Upload them — CSV or Excel, or import from your identity provider. We dedupe and enrich the list, and monitoring starts within 24 hours. From then on they’re treated exactly like library vendors: vetted against your frameworks, re-checked daily, findings triaged. There’s no two-tier system where your niche vendors get worse coverage.
The library is also why the platform monitors vendors of every size — from the hyperscalers under Airbus and Pfizer-scale enterprises down to the five-person SaaS tool your marketing team adopted last month.