If you don't see your question here, just get in touch.
Technical security posture (email authentication, TLS/SSL configuration, security headers, IP reputation), corporate registry health (UK Companies House and Ireland CRO), and visibility into a supplier's ICT supply chain — hosting, subprocessors, and how many third-party scripts their site depends on. You can also upload a signed agreement or a completed security questionnaire for an AI-assisted review.
Small businesses and non-profits who need to understand supplier risk but don't have the budget or dedicated team that commercial platforms like SecurityScorecard or BitSight assume you have. It's built to be genuinely usable by someone without a security background.
Everything we check is based on publicly available information and evidence you provide directly — DNS records, public registry data, a supplier's own website, documents you upload. We never actively scan, probe, or attempt to access a supplier's systems, and we never use credentials or exploit anything. It's the same reason we can assess a supplier without ever needing their permission or involvement.
No — and that's deliberate. Supplier Manager gives you clear, evidence-based information to support your own decision. It doesn't make the decision for you, and it's upfront about what it does and doesn't know — including being clear when something is self-reported by a supplier rather than independently verified.
Same underlying idea — evidence-based supplier risk visibility — built at a scale and price point that actually fits a small business or non-profit, rather than an enterprise security budget.
Get in touch and we'll talk through what fits your organisation.
Adding a supplier and running the technical and corporate checks takes moments. Reviewing an uploaded agreement or questionnaire typically completes within a minute or so.
Yes — get in touch if you'd like more detail on how data is handled and stored.