Alerting
TrustVendor + PagerDuty
For organizations where vendor risk events need to trigger on-call response, TrustVendor integrates with PagerDuty to escalate critical and high-severity signals through your existing incident management process.
How data flows
Critical and high-severity TrustVendor signals are sent to PagerDuty as Events API v2 payloads, triggering alerts in your configured PagerDuty service.
How to set up
- 1 Create a TrustVendor integration in PagerDuty and copy the integration key.
- 2 In TrustVendor, add the integration key under Settings > Alerting > PagerDuty.
- 3 Configure which signal severities create PagerDuty incidents.
Common questions
Should all TrustVendor signals create PagerDuty incidents?
Typically only critical-severity signals — like a vendor processing PHI who loses their HIPAA BAA — warrant PagerDuty escalation. Medium and low signals are better handled in Slack or Jira.
How does TrustVendor send events to PagerDuty?
TrustVendor uses the PagerDuty Events API v2, sending a trigger event with the signal title as the summary, the vendor's canonical name and primary domain in the payload, and the TrustVendor evidence URL as the source link. The dedup_key field is set to TrustVendor's signal ID so that subsequent updates to the same signal update the existing PagerDuty incident rather than opening a duplicate.
Does TrustVendor automatically resolve PagerDuty incidents when a signal is resolved?
Yes. When a TrustVendor signal transitions to resolved status — because the underlying condition is no longer detected or your team manually resolves it — TrustVendor sends a resolve event to PagerDuty using the same dedup_key. The PagerDuty incident is resolved automatically, and the resolution appears in the PagerDuty incident timeline with a timestamp from TrustVendor.
Can I map TrustVendor signal types to different PagerDuty services or escalation policies?
Each TrustVendor alerting rule maps to a single PagerDuty integration key, and each key corresponds to a PagerDuty service with its own escalation policy. By creating multiple alerting rules — one for breach_notification and data_incident, another for certificate_expiry — you can route different signal types to different on-call rotations or escalation paths within PagerDuty.
What happens to PagerDuty alert volume if a major vendor has multiple signals fire simultaneously?
TrustVendor's deduplication at the signal level prevents duplicate events for the same finding. If multiple distinct signals fire for the same vendor — for example, a breach disclosure and a simultaneous compliance_change — they create separate PagerDuty incidents, each with its own dedup_key. You can use PagerDuty's alert grouping feature to merge incidents from the same vendor into a single incident for a cleaner on-call experience.