PRODUCT

TPRM Workspace

Portfolio, per-relationship residual risk, evidence requests, assessments.

Book a demo Start free

What it is

The TrustVendor Trust Workspace is the command centre for your third-party risk program. It replaces the combination of spreadsheets, email threads, and annual questionnaire campaigns with a continuous, evidence-driven view of every vendor in your register. The portfolio view shows every monitored vendor sorted by residual risk to your data — not by alphabetical order or vendor tier, but by what actually matters given what you share with each vendor.

Residual risk is computed as a function of posture, assurance, data class exposure, and integration criticality. A vendor with a moderate posture score who processes PHI at high integration depth may rank higher in your risk register than a vendor with a low posture score who receives only telemetry. The scoring model is deterministic, versioned, and replayable — you can always explain why a vendor ranks where it does.

The workspace integrates with your existing GRC stack rather than replacing it. TrustVendor is the evidence data layer; Vanta, Drata, OneTrust, or ServiceNow remain your compliance workflow and audit layer. Evidence requests let you collect documents from vendors and process them through the same extraction pipeline as public sources — so privately shared SOC 2 reports become first-class evidence with the same span-level citations as public data.

How it works

Three steps, fully auditable.

01

Onboard

Add a vendor by domain name. The resolver builds the identity graph, links to existing public evidence, and initiates monitoring. Your whole vendor register can be imported in bulk via CSV or synced from your GRC platform.

02

Configure

Set the data classes, integration criticality, and geographic scope for each vendor relationship. These parameters feed the residual risk computation and determine which signals are material for that specific relationship.

03

Monitor

Continuous evidence collection, signal delivery, and score updates run automatically. Reviews are triggered by signals and score thresholds, not by calendar — your team reviews when something changes, not on a quarterly schedule.

What you get

Built for compliance teams that have to prove things.

Portfolio by residual risk

Every vendor ranked by the risk it poses to your specific data, not by alphabetical order or contract value. Drill into any vendor for the full posture, assurance, and signal history.

Evidence requests

Send a structured evidence request to a vendor and process the response through the same extraction pipeline as public sources. Privately shared SOC 2 reports become span-cited evidence.

Assessments without spreadsheets

Pre-populated assessments extract answers from documents the vendor already published. Your team reviews the gaps, not the obvious answers a questionnaire should have already found.

Sample

What it looks like in practice.

Portfolio — sorted by residual risk 48 vendors

Acme Analytics

Analytics · PHI, PII

Posture / Assurance

84 / 71

Residual risk

High

Open signals

1 medium

BrightPath Health

Healthcare SaaS · PHI

Posture / Assurance

79 / 52

Residual risk

High

Open signals

1 medium

ClearStream Data

Data pipeline · PII

Posture / Assurance

91 / 88

Residual risk

Medium

Open signals

None

Common questions.

How does residual risk differ from posture score?
The posture score measures what controls a vendor claims to have — it is global and identical for every customer of that vendor. Residual risk is relationship-scoped: it factors in what data classes you share, your integration depth, and whether the vendor's claimed controls actually cover your exposure. Two customers of the same vendor can have very different residual risk scores.
Can TrustVendor replace our existing GRC platform?
TrustVendor is designed to complement your GRC platform, not replace it. TrustVendor is the evidence data layer — continuous monitoring, span-cited findings, and vendor intelligence. Your GRC platform remains the workflow, policy management, and audit layer. The most common deployment is TrustVendor feeding vendor risk data into Vanta, Drata, or ServiceNow via the integration layer.
What happens when a vendor relationship ends?
You can archive a vendor relationship, which stops monitoring and removes it from your active portfolio. All historical signals, scores, and evidence remain accessible in the archive for the retention period you configure. For audit purposes, the evidence of what you knew during the active relationship period is preserved.
How do we handle vendors that are subsidiaries of other monitored vendors?
TrustVendor models corporate relationships as edges in the vendor graph — subsidiary_of, acquired_by, hosted_on. When you monitor a vendor, subprocessor concentration risk is computed automatically: if eleven of your vendors share the same underlying infrastructure provider, that concentration surfaces in your portfolio view.

See TPRM Workspace on your vendor data.

Book a 30-minute demo. We will run it live on vendors from your register.

We will respond within one business day.