Help & Docs
Everything you need to run third-party risk in VendorBreach. No sign-in required.
Getting started
- Start a 14-day free trial — no credit card. Confirm your email from the link we send you.
- Add your first vendors (below). Scans start automatically and usually finish within a few minutes.
- Review the dashboard: each vendor gets a security score, grade, findings and breach history.
- Invite teammates from Settings and turn on email alerts for score drops and new breaches.
Adding vendors
Add a vendor by entering its company name and primary website domain, or import many at once from a CSV (name, domain, category, tier). Duplicate domains are detected and merged.
Plan limits: Starter monitors up to 25 vendors, Professional up to 100, and Enterprise is unlimited. See pricing.
How scoring works
Scores run 0–100 and are built from outside-in evidence: website encryption (TLS), DNS and email authentication (SPF, DKIM, DMARC), exposed services, known breaches and leaked credentials, and published certifications.
Breach probability estimates the chance of a breach in the next 12 months from security-rating weakness, threat exposure, past breaches, missing certifications and weak encryption. Vendors without enough public evidence show no guessed number.
Vendors can raise their score within a capped range by sharing verified evidence through a Trust Profile. See the sample report.
Integrations
- Google Workspace, Microsoft 365, Okta — discover the SaaS and AI tools already in use.
- Slack and Jira — route alerts and remediation tasks (Professional and above).
- REST API and webhooks — sync vendors, findings and scans (Enterprise).
TPRM FAQs
What is third-party risk management?
The practice of identifying and reducing the security, privacy and operational risk your suppliers introduce.
Do vendors need to install anything?
No. Scoring uses public, outside-in signals. Questionnaires and evidence are optional and shared through a secure portal.
Where is my data hosted?
Customer data is stored in the United States (AWS US-East-2, Ohio). Details are in the Trust Center.
I didn't get my confirmation email.
Check spam, then use "Resend confirmation email" on the sign-in page. Messages come from noreply@notify.vendorbreach.com.
Still stuck? Contact us.