Third-Party Risk Management

Vendor Risk Scores From Real Scans & A Portal To Fix Them

GoTrust continuously maps every vendor's external infrastructure from passive reconnaissance and grades it O through F. A shared provider going down automatically flags every vendor exposed to it.

When a grade needs work, a scoped login lets the vendor's own team see what's driving it and fix it directly.

Vendor PortfolioLive
A-Portfolio
13-tier grading, O through F

Recomputed after every scan, on a diminishing-returns risk curve.

NONorthwind Cloud
A
MEMeridian Payments
B+
HAHalcyon Logistics
C
VEVertex Data Systems
D-
Core capabilities

What a TPRM Program Actually Needs

RS
Continuous risk scoring

13-tier O to F grading recomputed after every scan. A diminishing-returns risk curve means one bad finding doesn't collapse the score.

PT
Portfolio & peer benchmarking

See a vendor's grade against its own industry tier and peer set. Track portfolio-wide trends — improving vs. worsening, at-risk counts.

4P
Fourth-party breach cascade

Log an incident at a shared provider once. Every vendor with a detected dependency on it is flagged automatically.

HI
Hierarchical vendor structures

Score a vendor's subsidiaries or business units as sub-organizations. Rolls up into one parent score automatically.

SH
Shareable scorecards

Every vendor gets a public, no-login scorecard link — for onboarding review, or to prove posture to its own customers.

VP
Scoped remediation access

A vendor's login gets a 404, not a 403, on anything outside its grant. It can't even confirm another organization exists.

RC
Rescans confirm the fix

No re-attestation, no “please confirm you fixed this” email. The platform verifies remediation the same way it found the issue: by scanning again.

MU
One account, multiple orgs

A vendor running several subsidiaries can be granted exactly the set they're responsible for — no more, no less.

FP
Works for internal teams too

The same scoping mechanism works for an internal business unit or, for government deployments, an individual ministry.

Government & CERTs
Turn a risk score into a fixed vulnerability

From “You're at Risk” to “It's Fixed”

Most vendor risk tools stop at handing over a scorecard the vendor can't act on. GoTrust goes one step further.

1
Scope a login

Grant a vendor's team account access to exactly their own organization — no visibility into anyone else's data.

2
They see their findings

Every open finding, ranked by severity and real exploit likelihood — not just a number.

3
They remediate

The vendor's own team fixes the issue directly — no ticket bouncing through your risk team.

4
Score updates automatically

The next scheduled rescan picks up the fix — visible to both sides, no manual re-attestation.

gotrust-interface — Scorecard
D-
Before remediation

Open critical & high findings driving the score down

A-
After the vendor fixes their own findings

Same infrastructure, same scan pipeline, rescanned automatically

Our approach

A Questionnaire Tells You What A Vendor Claims. Reconnaissance Tells You What's True.

Point-in-time attestations and self-reported questionnaires go stale the day they're signed.

GoTrust re-observes on a schedule, entirely from passive sources, so a vendor's grade reflects their infrastructure today, not six months ago. Active verification is available once a vendor authorizes it.

GoTrust
Continuous
Questionnaire-based tools
Point-in-time
Data source
Passive reconnaissance, active verification with authorization
Self-reported answers
Freshness
Continuous, scheduled rescans
Point-in-time, goes stale
Vendor can dispute the score
Fix the finding, rescan proves it
Re-answer the form
Fourth-party visibility
Automatic breach cascade detection
Not typically covered
Shadow IT discovery
Full subdomain & asset enumeration
Limited to declared assets

Stop Chasing Vendors For Remediation Status

Score the portfolio, hand vendors the access to fix what's found, and let the next scan confirm it.

No vendor notice required
Scoped, revocable access
Rescan verifies every fix
FAQ

Questions Risk Teams Ask First

How the score is built, what vendors can see, and where questionnaires still fit.

Talk to our team

From real findings across discovery, port/service enumeration, web and vulnerability scanning. Weighted by severity — critical findings weighted far more heavily than low-severity ones — then mapped onto a 13-tier grade.

Yes — passive reconnaissance doesn't require vendor participation or notice. Granting them remediation access, or requesting authorization for active verification, is a separate, optional step.

On a schedule you control per vendor or tier — higher-risk vendors can be rescanned more frequently than low-risk ones.

Most programs use GoTrust as continuous, objective ground truth alongside — not instead of — internal control questionnaires for things a scan can't see (policies, training, contracts).

Yes, at any time — access is a grant your admin manages, not a permanent credential handed to the vendor.

Yes — the public scorecard link is read-only and shows the grade. A scoped login lets the vendor actually see finding-level detail and take action.

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands