PRODUCT
Signals & Lifecycle
Ten signal types with severity SLAs, per-tenant lifecycle, and Slack routing.
What it is
TrustVendor monitors ten distinct signal types across the vendor risk surface: breach notifications, CVE disclosures, financial changes, news sentiment shifts, certificate expirations, compliance status changes, data incidents, acquisitions, regulatory actions, and service outages. Each type carries a default severity rating refined by the Triage agent against your relationship context — the data classes, integration scope, and geography you share with that vendor.
Signals are not notifications. A notification fires and disappears. A signal has a full lifecycle: new, acknowledged, investigating, resolved, or dismissed. Each state transition is timestamped and attributed to the user or system that made it. You can attach notes, link related signals, and export the full lifecycle history for audit purposes. When an auditor asks how you responded to a vendor breach notification, you have a timestamped record.
Routing is flexible by design. Signals can be delivered to Slack channels, Jira issues, Linear tickets, Microsoft Teams, PagerDuty, or your own webhook endpoint. Routing rules are per-vendor-group and per-severity, so critical signals for vendors processing PHI go to your security on-call channel while informational signals for low-criticality tools go to a weekly digest.
How it works
Three steps, fully auditable.
What you get
Built for compliance teams that have to prove things.
Ten typed signal categories
Breach, CVE, financial, sentiment, certificate expiry, compliance change, data incident, acquisition, regulatory action, outage — each with a default severity and evidence citation.
Severity SLAs
Critical signals reach your channel within 15 minutes of detection. All SLA clock times are from the source event timestamp, not from the crawl timestamp — no hiding latency in the pipeline.
Full audit lifecycle
Every state transition is timestamped and attributed. Acknowledged, investigated, resolved, or dismissed — the record is complete and exportable for your auditors.
Sample
What it looks like in practice.
Common questions.
How is severity determined?
Can I silence signals for specific vendors?
What is the difference between a signal and a score change?
Do signals work for vendors not in my monitored portfolio?
See Signals & Lifecycle on your vendor data.
Book a 30-minute demo. We will run it live on vendors from your register.