How does TrustVendor differ from Bitsight or SecurityScorecard?
Bitsight and SecurityScorecard measure external security hygiene using internet telemetry — sinkhole data, botnet sensors, open ports. That tells you how a vendor's perimeter looks from the outside. TrustVendor tells you what a vendor claims in writing, whether those claims are backed by current evidence, and what changed since the last time you looked. The two are complementary: you can ingest your Bitsight score as a signal inside TrustVendor rather than choosing between them.
How do you get access to a vendor's SOC 2?
Most SaaS vendors publish their SOC 2 summary on their trust centre or share it on request via a link. TrustVendor monitors publicly accessible trust centres continuously and also accepts uploads from customers who receive a full report under NDA. We never scrape authenticated portals or bypass access controls. Our bot policy is published at trustvendor.co/bot.
What sources does TrustVendor monitor?
We monitor trust centres, security pages, subprocessor lists, status pages, Certificate Transparency logs, CISA KEV, NVD, SEC EDGAR 8-K filings, HIBP, and published post-mortems. Each source type carries an explicit evidence half-life — a SOC 2 Type II decays more slowly than a status-page incident claim.
How is the score computed?
Scores are deterministic arithmetic over stored claims — no model involvement in scoring. The posture score measures control coverage from your vendor's certifications and disclosures. The assurance score measures evidence freshness, weighted by the half-life of each evidence type. Residual risk is a function of those two scores filtered to the data classes and integration scope you actually share with that vendor. Every computation is versioned and replayable.
Does TrustVendor work alongside our existing GRC platform?
Yes. TrustVendor integrates with Vanta, Drata, Sprinto, Scrut, Secureframe, OneTrust, LogicGate, and ServiceNow GRC. The most common pattern is TrustVendor as the evidence data layer and your GRC tool as the workflow and audit layer. The Vendor Pulse API lets you embed vendor intelligence directly in your GRC's vendor onboarding flow.
What does pricing look like?
The public vendor graph is free — no account required. The Trust Workspace starts at $299/month for up to 25 monitored vendors (Starter), $1,200/month for up to 150 (Growth), and $3,500/month for up to 600 (Scale). Enterprise pricing covers 600+ vendors and private deployment options. The Vendor Pulse API is priced per resolved vendor per month at volume — contact us for platform partnership pricing.