Vendor, SaaS and AI risk,
    finally under control.

    Score every vendor from the outside in, monitor them continuously, and prove compliance — automatically.

    No agents. No log access. No credentials.

    VendorBreach scores your vendors the way an attacker sees them. Nothing to install. Running in under 10 minutes.

    How we get our data

    Everything in the base platform is measured from the public internet. The only thing that ever looks inward is Discovery, and you switch that on yourself.

    Outside-in — every plan

    You give us vendor domains. That's it.

    • DNS, TLS and certificate transparency
    • Email authentication (SPF, DKIM, DMARC)
    • Exposed services and CISA KEV exposure
    • Breach and credential-dump feeds
    • Lookalike and impersonation domains
    • Declared and auto-detected subprocessors

    No agents, no log access, no credentials.

    Inside-out — Discovery module, optional

    Finds the SaaS and AI tools nobody told security about.

    Discovery uses a read-only connection to your identity provider, or an export from finance, to surface apps your people already use. It is separately enabled, separately explained, and can be disconnected at any time.

    • Read-only scopes only
    • Raw sign-in events are not stored
    • User counts, never named individuals
    See exactly what we touch

    How does your company score?

    Free instant security check — no signup required. Enter your work email and we'll scan your domain in seconds.

    • SSL, DNS, and network exposure
    • Breach database lookup
    • Threat intelligence score

    Free Security Check

    No signup required · Instant results

    VendorBreach needs a work email. Consultant using a personal address? Verify your domain instead.

    We don't add you to a marketing list. Your scan results are emailed once.

    New: AI Security

    Your employees already use AI. Do you know which tools?

    VendorBreach now discovers shadow AI across your organization, profiles every AI vendor's data practices, and governs usage against NIST AI RMF and the EU AI Act — in the same platform you already use for third-party risk.

    Discover

    Connect Google Workspace, Microsoft 365, or Okta and we detect the AI vendors already in use — including personal-account signups nobody approved.

    Assess

    Every AI vendor gets a profile: training-data policy, retention window, data residency, attestations, and breach history — matched against a curated AI vendor catalog.

    Govern

    Set your own AI risk thresholds, publish AI usage policies, nudge risky users, and track posture against NIST AI RMF and the EU AI Act.

    30%
    of breaches involved a third party, double the year before
    194
    days avg. to identify a breach
    $4.44M
    avg. cost of a data breach

    Why now? The regulatory landscape demands it.

    New regulations are making third-party risk management a board-level priority. Organizations that fail to comply face severe penalties, reputational damage, and operational disruption.

    NIS2 Directive

    The EU's NIS2 mandates supply chain security assessments for critical infrastructure operators, with fines up to €10M.

    DORA Regulation

    Financial entities must continuously monitor ICT third-party risks and report incidents within strict timelines under DORA.

    SEC Cyber Rules

    The SEC now requires public companies to disclose material cybersecurity incidents, including those originating from vendors.

    How it works

    Get from zero to full vendor visibility in three simple steps.

    1

    Add Your Vendors

    Import your vendor list by CSV or add domains by hand. Nothing to install — scoring starts from the domain alone.

    2

    Continuous Monitoring

    Real-time SSL, DNS, and port scanning combined with breach intelligence and dark web feeds — 24/7, fully automated.

    3

    Report & Remediate

    Generate board-ready risk reports, assign remediation tasks, and track resolution across your entire vendor ecosystem.

    Everything you need for vendor risk

    A single platform to discover, assess, monitor, and report on every vendor in your supply chain.

    Shadow AI Discovery

    Optional Discovery module: a read-only connection to your identity provider surfaces the AI tools your people already use — before one becomes a data leak.

    Shadow SaaS Discovery

    Optional Discovery module: map third-party apps connected to Google Workspace, Microsoft 365, Okta and Slack, with read, write or admin access flagged.

    Continuous Monitoring

    Real-time SSL, DNS, and port scanning across your entire vendor ecosystem.

    Breach Intelligence

    Instant alerts when a vendor appears in breach databases or threat feeds.

    Risk Assessments

    Automated questionnaires with scoring, tracking, and remediation workflows.

    Compliance Vault

    Centralized evidence repository for SOC 2, ISO 27001, GDPR, EU AI Act, and more.

    Access Reviews

    Periodic access certification with approval chains and audit trails.

    Executive Reports

    Board-ready risk reports with trend analysis and exportable dashboards.

    Works with your existing stack.

    SlackJiraServiceNowMicrosoft TeamsPagerDutyZapier

    Why VendorBreach

    Purpose-built for teams that want results without the enterprise sales process.

    Fast time-to-value

    Go live in under 10 minutes — not weeks. Import vendors, configure monitoring, and start seeing risk scores immediately.

    Automation-first

    No more manual questionnaires. AI auto-fills assessments, continuous scans replace periodic reviews, and alerts fire instantly.

    Transparent pricing

    Published pricing on our website. No mandatory sales calls, no surprise invoices, no 12-month lock-in required.

    Simple, transparent pricing

    Start with a 14-day free trial. No credit card required. Cancel anytime.

    Starter

    $299/month

    $299/mo billed monthly · $249/mo billed annually ($2,988/year)

    14-day free trial included

    • Up to 25 vendors monitored
    • Email breach alerts
    • Basic risk scoring
    • Monthly summary reports
    • Community support
    • 3 user seats
    Start Free Trial
    Most Popular

    Professional

    $799/month

    $799/mo billed monthly · $649/mo billed annually ($7,788/year)

    14-day free trial included

    • Up to 100 vendors monitored
    • Email, Slack & SMS alerts
    • Advanced risk scoring
    • Weekly + on-demand reports
    • Compliance templates
    • 5 user seats
    Start Free Trial

    Enterprise

    Custom

    Tailored to your organization

    Custom pilot available

    • Unlimited vendor monitoring
    • All alert channels + API
    • Custom risk models
    • Real-time dashboards
    • Dedicated CSM & SLA
    • Unlimited user seats
    Contact Sales

    Frequently asked questions

    Everything you need to know about VendorBreach.

    Customer data is stored in the United States (AWS US-East-2, Ohio), encrypted with AES-256 at rest and TLS 1.3 in transit. A Canadian data region is coming. The web front end is served from a global edge network. See the Trust Center for the full sub-processor list.

    Built for Security Teams

    Enterprise-grade infrastructure with the security controls your team demands.

    Encryption
    AES-256 at rest, TLS 1.3 in transit
    AWS Hosted
    Multi-AZ infrastructure
    MFA & SSO
    TOTP + SAML 2.0
    SOC 2 Type I
    Audit underway, report expected Q4 2026. Independent auditor engaged.
    Third-party penetration tested
    Independent testing firm, July 2026 — no critical findings

    Ready to secure your vendor ecosystem?

    Start your 14-day free trial and see your vendor risk posture in minutes.

    Get Started Free

    Still evaluating? Read our vendor risk management software buyer's guide or start with the basics of third-party risk management.