Skip to content
FortaRisks
The whole platform

The real posture of your vendors, not their questionnaire

The questionnaire your vendor fills in, continuously cross-checked against a scan of their real attack surface. The gap between what they declare and what their surface shows becomes an explicit signal, and the scan covers a perimeter they validated themselves, so it can be challenged and re-run after remediation.

7 days

To first alert

0 to 100

Vendor score, A+ to F

110+

Finding types per vendor

The annual questionnaire is already out of date.

A once-a-year form does not tell you when a vendor is actually exposed or breached.

Value you can see

Outcomes your team will feel.

  • The vendor cannot contradict themselves

    Declared and observed side by side, with a flag when the two diverge.

  • A scan they can challenge

    Perimeter validated by the vendor, re-scan on demand after remediation: the opposite of attribution false positives.

  • Questionnaire fatigue, handled

    Answers reused from one client to the next, passwordless portal, versioned evidence.

Key capabilities

  • Declared and observed, reconciled

    On one side the vendor's questionnaire, on the other a native external scan of their surface. Both are cross-checked continuously without being merged, and a divergence between what is declared and what is observed is raised as an explicit flag. That is what ratings lack, having only the observed, and what questionnaires lack, having only the declared.

  • The vendor answers once, for every client

    A vendor receives around 37 assessment requests a month. In their own space they answer once and reuse those answers from one client to the next, question by question or by SCF control. No network or marketplace to build: the SCF link is what makes reuse possible.

  • Passwordless portal and versioned evidence

    The vendor signs in with a code sent by email, with no account to create and no licence to buy. They build a versioned evidence library they can share again. The catalogue is shared: a vendor already known to the platform is not re-scanned for every new client.

  • Three questionnaire levels, including an OT/ICS module

    From a 24-question baseline to a full 139-question assessment across 9 domains and 35 control domains, plus 6 thematic modules you can add. One of them covers OT and ICS, which none of the twenty-plus vendors studied offers. Every answer maps to an SCF control, which gives NIST, ISO 27001, SOC 2 and GDPR coverage with no extra work.

  • Share reports for remediation

    Export a vendor's report and hand it to them, turning your assessment into their improvement, with no extra licence for them.

  • Questionnaires on demand

    When a posture degrades and you need depth, send a targeted questionnaire for the detail external scanning cannot see, not a yearly blanket survey.

A degradation becomes a dated remediation request.

Twelve configurable alert policies trigger on a score drop, a grade crossing or a new critical finding. The remediation request goes out with a deadline and reminders, and surfaces in the Action Center as well as the risk register. Five registers are exportable, and vendors can be imported in bulk.

Three real-world scenarios. Three measurable outcomes.

  • Case 1

    Finance (DORA, OSFI B-13)

    A Canadian bank with 1,200 employees, 60 critical ICT suppliers (cloud, SaaS, managed services). DORA audit imminent. Before FortaRisks: DORA questionnaires sent in March, 60% return rate, variable quality, usable in September. With FortaRisks TPRM: 60 suppliers onboarded in 5 days. Initial score for 100% of third parties in under 7 days. Continuous detection of TLS degradation, newly exposed ports, critical CVEs on Internet-facing services. DORA report generated in 1 day, continuous evaluation evidence exportable.

  • Case 2

    Healthcare (Loi 25, targeted ransomware)

    A Quebec clinic group, 800 employees, 25 suppliers handling personal health information (PHI). Historic ransomware target. Before FortaRisks: no continuous visibility on supplier posture, reliance on their Loi 25 declaration. With FortaRisks TPRM: continuous observation of 25 critical suppliers. Automatic detection of a supplier whose subdomain was hijacked via subdomain takeover (unconfigured Webflow), 48 hours after the event. Action: access suspended in 24 hours, contractual negotiation activated.

  • Case 3

    Manufacturing OT

    A 1,500-employee manufacturer, 12 sites, 80 suppliers including 15 OT suppliers (automation, sensors, supervision). Before FortaRisks: zero visibility on the OT surface exposed by suppliers (accidentally exposed Modbus / S7 on the Internet). With FortaRisks TPRM: native OT/ICS scanner applied to the 15 OT suppliers. Detection of a sensor supplier's Siemens S7 accessible on the Internet via NAT misconfiguration. Notification to the supplier. Correction in 72 hours. No incident.

What's included

Questionnaires

  • 3 levels: 24, 39 and 139 questions
  • 9 domains and 35 control domains
  • 6 thematic modules you can add
  • OT/ICS module, absent from every vendor studied
  • Every answer mapped to an SCF control
  • Inherent risk assessment and tiering

Scoring & depth

  • 0 to 100 score, A+ to F grades
  • Native external scan of the vendor's surface
  • Perimeter validated by the vendor, so it can be challenged
  • Re-scan on demand after remediation
  • Divergence flag between declared and observed
  • 110+ finding types applied to every vendor
  • First alert within 7 days

Vendor portal & operations

  • Passwordless vendor portal, access by email code
  • Versioned, shareable evidence library
  • Answers reused from one client to the next
  • Shared catalogue: a known vendor is not re-scanned
  • 12 configurable alert policies
  • Remediation requests with deadline and reminders
  • 5 registers exportable to XLSX
  • Bulk vendor import

Frameworks

  • NIST CSF 2.0
  • ISO 27001:2022
  • SOC 2
  • GDPR
  • Quebec Law 25
  • IEC 62443

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In third-party risk, AI targets repetitive work: pre-filling a questionnaire from past answers, flagging an answer inconsistent with the evidence provided, summarizing a vendor file. The assessment and the score stay grounded in validated declarations and the observed scan.

Sovereignty: the platform is built and hosted in Canada, beyond the reach of the US CLOUD Act. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

TPRM is not a silo. The other modules feed it.

Continuous TPRM only has value because the other modules exist. That's what distinguishes it from a standalone TPRM product (BitSight, SecurityScorecard) or a TPRM module added to a GRC (OneTrust). Each pillar feeds a different dimension of third-party observation.

  • EASM → TPRM

    The 110+ EASM finding types are applied to each third party's perimeter. The native OT/ICS scanner is applied to industrial suppliers. The subdomain takeover detection engine on 83 services is applied to third-party exposed assets. No additional ingestion cost.

  • CTI → TPRM

    The 50+ aggregated CTI sources and 1,500+ tracked actors are filtered by third-party industry sector. If BlackBasta targets the healthcare sector and one of your healthcare suppliers has an exposed critical CVE, you see it immediately, before the attack.

  • Posture → TPRM

    The 1,534+ SCF controls mapped across 31 frameworks serve as a reference for alignment drift. If a third party declares SOC 2, FortaRisks observes external signs of that alignment (TLS, MTA-STS, security headers) and alerts on drift vs declaration.

  • Risk Engine → TPRM

    The third-party score contributes to your organization's overall risk score. Cross-module prioritization takes your third parties into account: a critical CVE on one of your critical third parties is prioritized over a medium CVE on one of your unexposed direct assets.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.

Frequently asked questions

How is this different from an external score like BitSight or SecurityScorecard?

Those give you a grade from a closed methodology. FortaRisks exposes every finding behind a vendor's score, by dimension, so the vendor can dispute it point by point and you can defend your decision with technical proof.

Does the vendor have to cooperate for the initial assessment?

No. The external scan starts without them and already yields an observed posture. Their cooperation adds the declarative side, the evidence library and perimeter validation, which makes the score challengeable and therefore defensible. Since they can reuse past answers, the cost of entry is low for them.

Does the OT/ICS scanner apply to vendors?

Yes. Categorize a vendor as OT or industrial at onboarding and the native OT/ICS scanner is included in their continuous surface scan, read-only with adapted rate limiting.

What happens when a third party disputes its score?

The scanned perimeter is the one they validated, so the discussion is about recognized assets, not questionable attribution. They fix, request a new scan, and the score updates. That is the direct counter to the number one complaint made about rating platforms.