Create workspace
Register, choose sample data, or start with your own vendor. No sales call required.
Third-party cyber risk intelligence
NetRisk helps you discover vendors, verify security evidence, map attack surface, trace attack paths, and quantify third-party cyber risk with guided workflows that make every next step clear.
See sample vendor journeyNo sales call required. Start with sample data or add your first vendor.
Evidence first
Verify before you ask
Exposure aware
Attack surface + paths
Quantified
Risk in euros
Guided action
Every risk has a next step
Continuous
Trust stays alive
Connected to the systems your teams already use
The state of TPRM
Most tools start with a questionnaire and hope the answers are true. NetRisk starts with reality: public evidence, real exposure, and what an attacker can already see.
Traditional tools collect answers
slow loopThe old model waits for answers, stores evidence as files, and turns uncertainty into a static color.
NetRisk connects proof to risk
living graphQuestionnaire first
Evidence before questions
Static score
Exposure before scoring
Severity color
Financial impact before priority
Annual review
Continuous monitoring after approval
Start in 3 minutes
Register, choose sample data, or start with your own vendor. No sales call required.
Enter a vendor name or domain. NetRisk begins research, evidence discovery, and exposure mapping.
Review evidence, ask only missing questions, create tasks, and track risk continuously.
One vendor. One continuous story.
Watch Northwind AI, a new GenAI SaaS, travel through NetRisk as you scroll. The vendor is asked only after evidence, exposure, and attack paths are understood.
Northwind AI shows up in SSO logs, an expense line, procurement intake, and email-domain signals. NetRisk dedupes the noise into one vendor profile.
NetRisk does
Detects the vendor across 8 intake sources and assigns one profile.
You decide
Confirm ownership and business criticality.
Deduped to
Northwind AI
1 profileA research agent finds the domain, product category, trust center, compliance claims, subprocessors, public breach signals, and source confidence.
NetRisk does
Pulls public sources into an evidence inbox with citations.
You decide
Review only when confidence is high enough.
SOC 2, ISO 27001, DPA, subprocessor lists, and pen-test summaries are gathered first, so the eventual assessment starts with what is already provable.
NetRisk does
Extracts claims from each document automatically.
You decide
Flag sources that need first-party proof.

SOC 2 Type II
trust centerISO 27001 cert
publicDPA + subprocessors
legal pagePenetration test
on requestEvery claim carries authority, freshness, expiry, and confidence. Contradictions and missing proof are escalated for human review.
NetRisk does
Scores confidence and flags an expired pen test.
You decide
Approve verified claims and request the rest.
Encryption at rest - AES-256
verifiedSSO + MFA enforced
verifiedPen test recency
expired 14moIncident response evidence
missingNetRisk maps external domains, IPs, cloud assets, certificates, technologies, open ports, and known vulnerabilities before the vendor answers anything.
NetRisk does
Finds an exposed admin panel and a critical CVE.
You decide
Decide whether exposure blocks onboarding.
Exposure, weak controls, and data access connect into a reasoned attack path from an internet-facing asset to quantified business impact.
NetRisk does
Chains exposure to weak control to business impact.
You decide
Accept, mitigate, or escalate the path.
Exposure
admin.northwind.ai reachable from internet
Weak control
No MFA evidence on admin plane
Data access
Processes customer PII + prompts
Impact
Account takeover to EU PII exfiltration
A FAIR-style model turns the path into probable annualized loss exposure with confidence, evidence links, an owner, and a treatment plan.
NetRisk does
Computes EUR 420k-EUR 1.8M ALE with linked evidence.
You decide
Approve, request remediation, or reject.
Exposed admin panel
no MFA evidence
Weak IR evidence
expired pen test
Critical data access
EU customer PII
Probable annualized loss exposure
EUR 420k-EUR 1.8M
Loss event frequency 0.18/yr. Single-loss EUR 2.4M-EUR 9.6M. FAIR-style model with linked evidence.
Confidence
Medium
Evidence
3 claims
Owner
A. Reyes
Verified evidence removes repeat questions, while expired, missing, or contradictory controls become targeted follow-ups.
NetRisk does
Compresses 312 questions into 47 targeted questions.
You decide
Send only the missing questions.
Assessment compression
312
47
targeted questions remain after verified evidence fills the rest.
Security governance
80% verified
Data protection
60% verified
Subprocessors
verified
Pen test
expired
Incident response
missing
AI governance
missing
The draft risk becomes an owned remediation or evidence request with due date, expected residual-risk reduction, and escalation state.
NetRisk does
Creates task, due date, owner, and expected impact.
You decide
Assign the task or request vendor follow-up.
Risk
Admin-panel takeover
EUR 420k-EUR 1.8M
Evidence
Expired pen test + missing IR proof
confidence medium
Action
Request remediation evidence
due in 14 days
Next best action
Evidence expiry, new exposed assets, fresh CVEs, trust-center changes, and control drift trigger reassessment long after approval.
NetRisk does
Watches change and reopens risk when it moves.
You decide
Act on triggers and track remediation to closure.
Mar 02
SOC 2 + ISO evidence verified - approved with conditions
Apr 18
Pen-test evidence expiring in 30 days - reassessment queued
May 09
New subdomain + critical CVE detected - risk reopened
May 21
Remediation task assigned - evidence requested
May 28
Fix verified - residual risk reduced 71%
Northwind AI transformation
01 / 10
Deduped to
Northwind AI
1 profileAsk only what is missing
When most answers are already public and verified, sending a giant form is theatre. NetRisk fills assessment sections from evidence and generates only the questions that remain.
Security governance
80% verified
Data protection
60% verified
Subprocessors
verified
Pen test
expired
Incident response
missing
AI governance
missing
The risk-in-euros moment
NetRisk composes technical findings into a probable financial loss range a board can act on.
Exposed admin panel
admin.northwind.ai - no MFA evidence
Weak incident-response evidence
no IR runbook - expired pen test
Critical data access
processes EU customer PII + prompts
Probable annualized loss exposure
EUR 420k-EUR 1.8M
Loss event frequency 0.18/yr. Single-loss EUR 2.4M-EUR 9.6M. FAIR-style model with confidence, owner, evidence links, and next action.
Confidence
Medium
Evidence
3 linked claims
Owner
A. Reyes
The signature concept
Vendors, products, domains, evidence, claims, assets, controls, exposures, attack paths, risks, tasks, and owners connect in one model.
Vendor
Northwind AI
Product
GenAI SaaS
Domain
northwind.ai
Evidence
SOC 2 / DPA / ISO
Claims
MFA, IR, encryption
Assets
apps, APIs, mail
Controls
verified + missing
Exposures
admin + CVE
Attack Path
asset to impact
Risk
EUR 420k-1.8M
Task
request MFA proof
Owner
Security
One connected model
Evidence, exposure, attack path, risk, task, and owner stay linked as trust changes.
From story to operating system
Vendor review
Evidence
8 found
Exposure
2 open
Risk
EUR 1.8M
Evidence review
Found
SOC 2 Type II, DPA, ISO certificate
Missing
Incident-response proof and recent pen test
Decision
Approve evidence or request missing proof
What changed?
Northwind AI profile was enriched with verified public evidence.
Why it matters
Evidence can answer repeat questionnaire sections before the vendor is asked.
Evidence
SOC 2, DPA, ISO 27001, trust center, subprocessor list
Risk impact
312 questions reduced before outreach
What you can do immediately
01
Enter a vendor name or domain and start a guided review.
Add vendor
02
Find public sources, trust centers, security docs, and vendor claims.
Run AI research
03
See what is found, missing, expired, or contradictory.
Review evidence
04
Open public-facing domains, technologies, exposures, and risk signals.
Map attack surface
05
Convert evidence and exposure into a draft risk scenario.
Generate first risk
06
Send a targeted questionnaire only for gaps.
Ask missing questions
07
Assign remediation or evidence follow-up.
Create tasks
08
Track expiry, new vulnerabilities, trust-center changes, and control drift.
Monitor continuously
One platform. The whole journey.
Discovers vendors from shadow IT, SaaS usage, procurement, and email signals, then dedupes to one profile.
Decides Who actually has access to our data?
Builds a sourced vendor profile with domain, category, trust center, claims, subprocessors, and breach signals.
Decides What do we already know before we ask?
Extracts claims from SOC 2, ISO, DPAs, and pen tests with authority, freshness, expiry, and confidence.
Decides Which claims are provable?
Maps domains, cloud assets, certificates, technologies, open ports, and known vulnerabilities.
Decides What can an attacker see right now?
Connects exposure, weak controls, and data access into paths from asset to business impact.
Decides How does exposure become a breach?
Explains why risk changed, which evidence supports it, what action reduces it, and who owns it.
Decides Which vendors create real business risk?
Built for the whole decision
CISO
Financial exposure, portfolio trend, and defensible prioritization.
Continuous verification
Approval is the start of monitoring. Evidence expiry, trust-center edits, new assets, fresh CVEs, and control drift reopen risk when the facts change.
Current signal
Monitoring
Monitoring inputs
Always on
trust model watching
Risk state
5 signals
Task routing
Queued if material
Residual risk
Awaiting proof
Your first NetRisk workspace
Start with sample data, then add real vendors when you are ready. NetRisk guides the first review from evidence to risk to action.
Use cases
TriggerNew procurement request
NetRisk actionVerify evidence and quantify onboarding risk
OutputApprove with conditions
TriggerSSO or expense signal
NetRisk actionResearch, dedupe, and map exposure
OutputCreate owner review
TriggerEvidence expiry or new CVE
NetRisk actionReopen trust and update residual risk
OutputAssign remediation
TriggerLarge vendor review queue
NetRisk actionReuse verified evidence and ask gaps only
Output47 targeted questions
TriggerCompliance review
NetRisk actionExport evidence, claims, owners, and decisions
OutputTraceable proof
TriggerTechnical finding
NetRisk actionConnect attack path to business impact
OutputEUR risk range
Trust, security, and AI governance
NetRisk AI proposes. Humans approve. Evidence proves.
Suggested claims, missing evidence, and risk scenarios are clearly labelled.
Material claims and risk changes require review where confidence matters.
Every claim shows source, date, freshness, confidence, and impact if accepted.
Start verifying vendor trust today
Start with sample data. Add real vendors when you are ready.