Compliance platform

TrustVendor + Scrut

Scrut Automation targets compliance teams in growth-stage companies pursuing multiple frameworks simultaneously. TrustVendor adds continuous vendor evidence monitoring to Scrut's risk and vendor management modules.

How data flows

TrustVendor pushes scored vendor risk data to Scrut on a daily cadence, with real-time webhooks for high-severity signals.

How to set up

  1. 1 Connect TrustVendor via the Scrut integration settings.
  2. 2 Authenticate and sync your vendor list.
  3. 3 Configure risk thresholds and alert routing.
  4. 4 Enable automated vendor risk evidence in Scrut.

Common questions

Does TrustVendor support multi-framework compliance in Scrut?
Yes. The vendor risk evidence TrustVendor provides — certifications, subprocessors, incidents — is relevant across SOC 2, ISO 27001, and GDPR controls in Scrut.
How does TrustVendor handle vendors that are not yet in its public graph when Scrut imports my vendor list?
TrustVendor returns a 202 status and begins a resolution and enrichment job for unknown vendors. The enrichment pipeline runs entity resolution against RDAP, CT logs, GLEIF, and SEC EDGAR, then crawls available public sources. The first scored profile typically arrives within two to eight minutes; complex vendors requiring human review in the confidence queue are flagged visibly in your Scrut integration dashboard.
Do real-time webhooks from TrustVendor affect my Scrut risk register automatically?
High and critical severity signals from TrustVendor — such as a breach disclosure or a compliance change — trigger webhook events that Scrut's workflow engine picks up to update the affected vendor's risk register entry. The update includes the signal title, severity, and a link to the TrustVendor evidence drawer so your team can review the underlying claim before deciding on a response.
Can I scope TrustVendor monitoring in Scrut to only the vendors flagged as critical in my register?
Yes. In TrustVendor you assign a criticality score from 1 to 5 on each vendor relationship, reflecting the sensitivity of data shared and the depth of integration. You can configure alert rules to apply higher severity thresholds for critical vendors while suppressing informational signals for lower-criticality vendors, keeping your Scrut notification volume manageable.
Book a demo See API pricing