The real posture of your vendors, not their questionnaire
The questionnaire your vendor fills in, continuously cross-checked against a scan of their real attack surface. The gap between what they declare and what their surface shows becomes an explicit signal, and the scan covers a perimeter they validated themselves, so it can be challenged and re-run after remediation.
7 days
To first alert
0 to 100
Vendor score, A+ to F
110+
Finding types per vendor
The annual questionnaire is already out of date.
A once-a-year form does not tell you when a vendor is actually exposed or breached.
Outcomes your team will feel.
The vendor cannot contradict themselves
Declared and observed side by side, with a flag when the two diverge.
A scan they can challenge
Perimeter validated by the vendor, re-scan on demand after remediation: the opposite of attribution false positives.
Questionnaire fatigue, handled
Answers reused from one client to the next, passwordless portal, versioned evidence.
Key capabilities
Declared and observed, reconciled
On one side the vendor's questionnaire, on the other a native external scan of their surface. Both are cross-checked continuously without being merged, and a divergence between what is declared and what is observed is raised as an explicit flag. That is what ratings lack, having only the observed, and what questionnaires lack, having only the declared.
The vendor answers once, for every client
A vendor receives around 37 assessment requests a month. In their own space they answer once and reuse those answers from one client to the next, question by question or by SCF control. No network or marketplace to build: the SCF link is what makes reuse possible.
Passwordless portal and versioned evidence
The vendor signs in with a code sent by email, with no account to create and no licence to buy. They build a versioned evidence library they can share again. The catalogue is shared: a vendor already known to the platform is not re-scanned for every new client.
Three questionnaire levels, including an OT/ICS module
From a 24-question baseline to a full 139-question assessment across 9 domains and 35 control domains, plus 6 thematic modules you can add. One of them covers OT and ICS, which none of the twenty-plus vendors studied offers. Every answer maps to an SCF control, which gives NIST, ISO 27001, SOC 2 and GDPR coverage with no extra work.
Share reports for remediation
Export a vendor's report and hand it to them, turning your assessment into their improvement, with no extra licence for them.
Questionnaires on demand
When a posture degrades and you need depth, send a targeted questionnaire for the detail external scanning cannot see, not a yearly blanket survey.
A degradation becomes a dated remediation request.
Twelve configurable alert policies trigger on a score drop, a grade crossing or a new critical finding. The remediation request goes out with a deadline and reminders, and surfaces in the Action Center as well as the risk register. Five registers are exportable, and vendors can be imported in bulk.
Three real-world scenarios. Three measurable outcomes.
- Case 1
Finance (DORA, OSFI B-13)
A Canadian bank with 1,200 employees, 60 critical ICT suppliers (cloud, SaaS, managed services). DORA audit imminent. Before FortaRisks: DORA questionnaires sent in March, 60% return rate, variable quality, usable in September. With FortaRisks TPRM: 60 suppliers onboarded in 5 days. Initial score for 100% of third parties in under 7 days. Continuous detection of TLS degradation, newly exposed ports, critical CVEs on Internet-facing services. DORA report generated in 1 day, continuous evaluation evidence exportable.
- Case 2
Healthcare (Loi 25, targeted ransomware)
A Quebec clinic group, 800 employees, 25 suppliers handling personal health information (PHI). Historic ransomware target. Before FortaRisks: no continuous visibility on supplier posture, reliance on their Loi 25 declaration. With FortaRisks TPRM: continuous observation of 25 critical suppliers. Automatic detection of a supplier whose subdomain was hijacked via subdomain takeover (unconfigured Webflow), 48 hours after the event. Action: access suspended in 24 hours, contractual negotiation activated.
- Case 3
Manufacturing OT
A 1,500-employee manufacturer, 12 sites, 80 suppliers including 15 OT suppliers (automation, sensors, supervision). Before FortaRisks: zero visibility on the OT surface exposed by suppliers (accidentally exposed Modbus / S7 on the Internet). With FortaRisks TPRM: native OT/ICS scanner applied to the 15 OT suppliers. Detection of a sensor supplier's Siemens S7 accessible on the Internet via NAT misconfiguration. Notification to the supplier. Correction in 72 hours. No incident.
What's included
Questionnaires
- 3 levels: 24, 39 and 139 questions
- 9 domains and 35 control domains
- 6 thematic modules you can add
- OT/ICS module, absent from every vendor studied
- Every answer mapped to an SCF control
- Inherent risk assessment and tiering
Scoring & depth
- 0 to 100 score, A+ to F grades
- Native external scan of the vendor's surface
- Perimeter validated by the vendor, so it can be challenged
- Re-scan on demand after remediation
- Divergence flag between declared and observed
- 110+ finding types applied to every vendor
- First alert within 7 days
Vendor portal & operations
- Passwordless vendor portal, access by email code
- Versioned, shareable evidence library
- Answers reused from one client to the next
- Shared catalogue: a known vendor is not re-scanned
- 12 configurable alert policies
- Remediation requests with deadline and reminders
- 5 registers exportable to XLSX
- Bulk vendor import
Frameworks
- NIST CSF 2.0
- ISO 27001:2022
- SOC 2
- GDPR
- Quebec Law 25
- IEC 62443
Optional AI enrichment
AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.
In third-party risk, AI targets repetitive work: pre-filling a questionnaire from past answers, flagging an answer inconsistent with the evidence provided, summarizing a vendor file. The assessment and the score stay grounded in validated declarations and the observed scan.
Sovereignty: the platform is built and hosted in Canada, beyond the reach of the US CLOUD Act. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.
TPRM is not a silo. The other modules feed it.
Continuous TPRM only has value because the other modules exist. That's what distinguishes it from a standalone TPRM product (BitSight, SecurityScorecard) or a TPRM module added to a GRC (OneTrust). Each pillar feeds a different dimension of third-party observation.
EASM → TPRM
The 110+ EASM finding types are applied to each third party's perimeter. The native OT/ICS scanner is applied to industrial suppliers. The subdomain takeover detection engine on 83 services is applied to third-party exposed assets. No additional ingestion cost.
CTI → TPRM
The 50+ aggregated CTI sources and 1,500+ tracked actors are filtered by third-party industry sector. If BlackBasta targets the healthcare sector and one of your healthcare suppliers has an exposed critical CVE, you see it immediately, before the attack.
Posture → TPRM
The 1,534+ SCF controls mapped across 31 frameworks serve as a reference for alignment drift. If a third party declares SOC 2, FortaRisks observes external signs of that alignment (TLS, MTA-STS, security headers) and alerts on drift vs declaration.
Risk Engine → TPRM
The third-party score contributes to your organization's overall risk score. Cross-module prioritization takes your third parties into account: a critical CVE on one of your critical third parties is prioritized over a medium CVE on one of your unexposed direct assets.
Explore the other modules.
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.
Frequently asked questions
How is this different from an external score like BitSight or SecurityScorecard?
Those give you a grade from a closed methodology. FortaRisks exposes every finding behind a vendor's score, by dimension, so the vendor can dispute it point by point and you can defend your decision with technical proof.
Does the vendor have to cooperate for the initial assessment?
No. The external scan starts without them and already yields an observed posture. Their cooperation adds the declarative side, the evidence library and perimeter validation, which makes the score challengeable and therefore defensible. Since they can reuse past answers, the cost of entry is low for them.
Does the OT/ICS scanner apply to vendors?
Yes. Categorize a vendor as OT or industrial at onboarding and the native OT/ICS scanner is included in their continuous surface scan, read-only with adapted rate limiting.
What happens when a third party disputes its score?
The scanned perimeter is the one they validated, so the discussion is about recognized assets, not questionable attribution. They fix, request a new scan, and the score updates. That is the direct counter to the number one complaint made about rating platforms.