Vendor Risk Assessment

Rate any vendor's security posture in seconds.

Enter a vendor domain for a free external A-F rating. Then inventory, question and continuously monitor every third party from one workspace — with alerts when a vendor's posture changes.

Passive, external checks only. No signup required. Shareable link included.

From one rating to a managed portfolio

Third-party risk is a process, not a one-off score. Vulnios covers the full loop.

01

Inventory your vendors

Add vendors by domain, tag them by criticality and data access, and assign an owner. Import from CSV or add one at a time.

02

Rate and question

Every vendor gets an external A-F security rating plus SIG Lite / CAIQ questionnaires sent from a vendor portal — no spreadsheets over email.

03

Monitor continuously

Ratings are re-assessed on a schedule. Rating drops, expired certificates and breach disclosures trigger alerts to the vendor owner.

Vendor Risk plans

Priced per organisation by vendor count — never per user or per asset. Standard and Pro start with a 14-day free trial.

VRA Standard

Vendor risk — inventory, external security ratings & questionnaires

  • Up to 10 vendors
  • External security ratings (A–F)
  • SIG Lite / CAIQ questionnaires
  • On-demand re-assessment
Start 14-day trial
Most popular

VRA Pro

Vendor risk with daily continuous monitoring & change alerts

  • Everything in VRA Standard
  • Up to 50 vendors
  • Daily continuous monitoring
  • Rating-change & breach alerts
Start 14-day trial

VRA Enterprise

Vendor risk — unlimited vendors, active pentest & SSO

  • Everything in VRA Pro
  • Unlimited vendors
  • Hourly continuous monitoring
  • Active vendor pentest (authorized)
Talk to sales

For MSSPs and vCISOs

Run vendor risk for every client from one login.

Each client is an isolated tenant with its own vendor inventory, ratings, questionnaires and reports. Your analysts switch tenants without switching accounts, and every deliverable exports as a white-label PDF you can put in front of the client's board.

  • Org-isolated tenants with role-based access and MFA
  • Per-vendor and portfolio PDF reports, branded per client
  • Rating-change and breach alerts routed to the client owner
  • SOC 2 controls mapped (audit in progress)

Pilot in three steps

  1. 1We set up two tenants for two of your clients.
  2. 2You import their vendor lists and we rate everything within the hour.
  3. 3You deliver the first portfolio report — then decide.

Frequently asked questions

How is the vendor security rating calculated?

The rating engine runs passive, external checks against the vendor domain — TLS/certificate configuration, HTTP security headers (CSP, HSTS, X-Frame-Options and more), DNS hygiene, and email authentication (SPF, DKIM, DMARC). Each dimension is scored and the weighted result becomes a single A-F grade. Nothing is exploited and no login to the vendor is required, so you can rate a vendor before they have signed anything.

Is the free rating the same engine as the paid product?

Yes. The free rating on this page is generated by the same engine that powers Vulnios Vendor Risk Assessment. The free version shows the grade, the per-dimension scores and a shareable link. A paid plan adds the full findings with evidence, questionnaires, continuous re-assessment, alerts and portfolio reporting across all your vendors.

Which questionnaires are supported?

SIG Lite and CAIQ templates ship out of the box, and you can add custom question sets. Vendors answer in a dedicated portal, attach evidence such as their own audit reports, and your reviewers approve or flag answers per control.

Can an MSSP run vendor risk for multiple clients?

Yes. Vulnios is multi-tenant by design: each client is an isolated organisation with its own vendor inventory, ratings and reports, and your analysts can belong to several tenants from one login. Pilot pricing for MSSPs is per-tenant — book a call and we will set up a two-tenant pilot.

Is there a free trial?

VRA Standard and VRA Pro include a 14-day free trial with no credit card required. Enterprise is set up with our team so we can configure SSO and any custom questionnaire packs before you start.