PRODUCT

Agents & Q&A

Ask "which vendors process PHI outside the US with an expiring SOC 2?" and get a cited answer.

Book a demo Start free

What it is

TrustVendor's Analyst agent is a tool-using reasoning system built on top of the evidence graph. It can answer portfolio-wide questions — "which of our vendors process PHI outside the US with a SOC 2 expiring in the next 90 days?" — and return a cited list of vendors with the specific evidence that supports each answer. The citations link to the exact spans in the source documents, so you can verify every assertion without trusting the model.

The agent has access to a small, safe tool set: semantic vendor search with filters, vendor profile reads, portfolio queries scoped to your tenant, claim queries with span retrieval, evidence fetching, and the deterministic scorer for exposure computation. It cannot modify data. It cannot access data outside your tenant scope. Its output is an ordered list of vendors with reasoning and evidence references — not a narrative that mixes up facts and inference.

Portfolio Q&A is designed for the question you can't answer with a dashboard filter because you don't know exactly how to slice the data. The agent handles the query decomposition, calls the right combination of search and filter tools, and returns results that are traceable to primary evidence. Every session is logged and replayable — so if the answer to a query changes next week because a vendor's SOC 2 expired, you can re-run the same query and see precisely what changed.

How it works

Three steps, fully auditable.

01

Query

You pose a natural-language question against your monitored portfolio. The agent decomposes it into a plan: which vendors to retrieve, which claims to filter on, which score computations to run. The plan is visible and editable before execution.

02

Retrieve

Tool calls fan out to the vendor graph search, claim query engine, and deterministic scorer. The agent never generates facts — it retrieves them from the evidence database and cites the artifact and span for each.

03

Cite

The answer is a structured result set: vendors, scores, and evidence links. Each finding references the claim that supports it, with a direct link to the span in the source document. The model writes the narrative; the facts come from the database.

What you get

Built for compliance teams that have to prove things.

Natural-language portfolio queries

Ask complex cross-vendor questions in plain English. The agent handles query decomposition, tool selection, and result ranking — you get a cited answer, not a list of filters to configure.

Every answer cited

No fact in the response is generated by the model without a database source. Each vendor in the result set links to the claim and evidence span that put it there.

Replayable sessions

Every query session is logged. Run the same question next week and compare results to see exactly which vendors changed status and why — powered by the same bitemporal evidence store.

Sample

What it looks like in practice.

Portfolio Q&A

Your question

Which vendors process PHI outside the US with a SOC 2 expiring in the next 90 days?

2 vendors found · All answers cited

BrightPath Health

Processes PHI under EU DPA. SOC 2 Type II expires 2026-10-14 (41 days).

Source: trust.brightpath.io snapshot art_4mN9pQ

Meridian Cloud

PHI processing in Singapore region. SOC 2 Type II expires 2026-11-02 (60 days).

Source: trust.meridian.co snapshot art_7xR2kL

Common questions.

How is this different from just filtering in the portfolio view?
Dashboard filters work well for single-dimension queries you can define in advance. Portfolio Q&A handles questions that require combining multiple evidence types, computing derived attributes on the fly, or reasoning about relationships between vendors — questions where you do not know exactly which combination of filters would give you the answer.
Can the agent access data from vendors outside my portfolio?
Yes, with distinction. For public graph data — posture scores, certifications, and public claims — the agent can retrieve information for any vendor in the graph. For your relationship data — residual risk, signals, evidence requests — the agent is scoped to your tenant by row-level security. It cannot access another tenant's portfolio.
How do I know the agent is not making up facts?
Every claim in the agent's output is grounded to a database record with an artifact and span citation. The agent is explicitly prohibited by its system prompt from emitting a claim it cannot cite. You can click through to the evidence drawer for any finding and see the exact source text. Claims without citations are a prompt violation and are filtered out before the response is returned.
Can I use this to generate vendor assessment narratives for auditors?
Yes. The Analyst agent can generate a vendor dossier — a structured narrative of a vendor's current posture, assurance level, open signals, and key evidence — formatted for external review. The dossier includes evidence links for every assertion. This is distinct from a self-assessment questionnaire: it is TrustVendor's view of the vendor based on primary evidence, not the vendor's own attestations.

See Agents & Q&A on your vendor data.

Book a 30-minute demo. We will run it live on vendors from your register.

We will respond within one business day.