Skip to main content
Operations · Module VRM-01 · PDF

Vendor Risk Management datasheet

Third-party exposure scoring and continuous monitoring — see your suppliers' attack surface and dark-web exposure as if it were your own.

One page, no preamble

Your suppliers' security posture is your security posture.

A breach at your top supplier is a breach at you. ShadowMap monitors your third-party ecosystem continuously, applying the same outside-in methodology to your vendors that it applies to your own estate — attack surface, brand, data exposure, dark web, threat intel — and surfaces material risk before it shows up in your SOC.

Everything in the datasheet is on this page and on the Vendor Risk Management capability page. The PDF exists because procurement asks for one, not because it says anything the site does not.

Vendor Risk Management datasheet (PDF)

We'll email you a confirmation link. Click it and the PDF downloads — no waiting on a sales call.

By downloading, you agree to receive relevant communications. We respect your privacy.

Prefer to skip the form? Everything here is on the capability page, ungated.

The capability list

What Vendor Risk Management monitors

Every capability in the Vendor Risk Management module, as printed in the datasheet
CapabilityWhat it does
Continuous third-party monitoring Every vendor monitored with the same outside-in methodology you run on your own estate — no extra tools, no extra contracts.
Vendor exposure scoring Composite score per vendor across attack surface, dark web, brand abuse, data leakage, and active threat-actor targeting.
Trend + drift detection Vendor scores tracked over time. Material posture changes (new exposures, breach indicators, leaked credentials) surfaced as alerts.
Concentration risk view Map of where your vendors share infrastructure, suppliers, or staff — so a single upstream incident can't hit you in five places.
Questionnaire enrichment Existing SIG / CAIQ / VAS questionnaire workflows enriched with ShadowMap evidence — fewer "we follow best practices" answers, more verifiable claims.
Evidence vault Per-vendor evidence pack — last 90 days of exposures, breach indicators, dark-web hits — exportable for procurement, legal, and audit.
Onboarding scoring New-vendor evaluation: 24-hour exposure assessment before the contract is signed, with comparable peer benchmarking.
Material-incident escalation When a vendor shows up in a ransomware leak post or a major breach, your team is paged with full context before the news cycle catches up.

Every capability in the Vendor Risk Management module, as printed in the datasheet

Continuous third-party monitoring

What it does
Every vendor monitored with the same outside-in methodology you run on your own estate — no extra tools, no extra contracts.

Vendor exposure scoring

What it does
Composite score per vendor across attack surface, dark web, brand abuse, data leakage, and active threat-actor targeting.

Trend + drift detection

What it does
Vendor scores tracked over time. Material posture changes (new exposures, breach indicators, leaked credentials) surfaced as alerts.

Concentration risk view

What it does
Map of where your vendors share infrastructure, suppliers, or staff — so a single upstream incident can't hit you in five places.

Questionnaire enrichment

What it does
Existing SIG / CAIQ / VAS questionnaire workflows enriched with ShadowMap evidence — fewer "we follow best practices" answers, more verifiable claims.

Evidence vault

What it does
Per-vendor evidence pack — last 90 days of exposures, breach indicators, dark-web hits — exportable for procurement, legal, and audit.

Onboarding scoring

What it does
New-vendor evaluation: 24-hour exposure assessment before the contract is signed, with comparable peer benchmarking.

Material-incident escalation

What it does
When a vendor shows up in a ransomware leak post or a major breach, your team is paged with full context before the news cycle catches up.

How it works

Onboard → Monitor → Score → Alert

1

Onboard

Add vendors via domain, business name, or DUNS. A typed inventory + dark-web identifiers built within 24 hours.

2

Monitor

The same continuous monitoring you run on your own estate — every capability, applied to each vendor in the portfolio.

3

Score

Per-vendor score updated daily; portfolio view ranks vendors by composite risk and trend direction.

4

Alert

Material drift, new ransomware-leak appearances, or major credential exposures route to procurement / vendor-management workflows.

60-80%

What changes

Faster vendor-incident response

Replaces the "annual SIG questionnaire" with continuous evidence-backed monitoring. Customers typically reduce vendor-incident response time by 60–80%.