Vendor Risk Scores From Real Scans & A Portal To Fix Them
GoTrust continuously maps every vendor's external infrastructure from passive reconnaissance and grades it O through F. A shared provider going down automatically flags every vendor exposed to it.
When a grade needs work, a scoped login lets the vendor's own team see what's driving it and fix it directly.
Most vendor risk tools stop at handing over a scorecard the vendor can't act on. GoTrust goes one step further.
1
Scope a login
Grant a vendor's team account access to exactly their own organization — no visibility into anyone else's data.
2
They see their findings
Every open finding, ranked by severity and real exploit likelihood — not just a number.
3
They remediate
The vendor's own team fixes the issue directly — no ticket bouncing through your risk team.
4
Score updates automatically
The next scheduled rescan picks up the fix — visible to both sides, no manual re-attestation.
gotrust-interface — Scorecard
D-
Before remediation
Open critical & high findings driving the score down
A-
After the vendor fixes their own findings
Same infrastructure, same scan pipeline, rescanned automatically
Our approach
A Questionnaire Tells You What A Vendor Claims. Reconnaissance Tells You What's True.
Point-in-time attestations and self-reported questionnaires go stale the day they're signed.
GoTrust re-observes on a schedule, entirely from passive sources, so a vendor's grade reflects their infrastructure today, not six months ago. Active verification is available once a vendor authorizes it.
GoTrust
Continuous
Questionnaire-based tools
Point-in-time
Data source
Passive reconnaissance, active verification with authorization
Self-reported answers
Freshness
Continuous, scheduled rescans
Point-in-time, goes stale
Vendor can dispute the score
Fix the finding, rescan proves it
Re-answer the form
Fourth-party visibility
Automatic breach cascade detection
Not typically covered
Shadow IT discovery
Full subdomain & asset enumeration
Limited to declared assets
Stop Chasing Vendors For Remediation Status
Score the portfolio, hand vendors the access to fix what's found, and let the next scan confirm it.
From real findings across discovery, port/service enumeration, web and vulnerability scanning. Weighted by severity — critical findings weighted far more heavily than low-severity ones — then mapped onto a 13-tier grade.
Yes — passive reconnaissance doesn't require vendor participation or notice. Granting them remediation access, or requesting authorization for active verification, is a separate, optional step.
On a schedule you control per vendor or tier — higher-risk vendors can be rescanned more frequently than low-risk ones.
Most programs use GoTrust as continuous, objective ground truth alongside — not instead of — internal control questionnaires for things a scan can't see (policies, training, contracts).
Yes, at any time — access is a grant your admin manages, not a permanent credential handed to the vendor.
Yes — the public scorecard link is read-only and shows the grade. A scoped login lets the vendor actually see finding-level detail and take action.