Vendor risk assessment software

Assess vendor risk.
Prove it with evidence.

Monitor public cyber exposure, publish a free trust center, and answer unlimited security questionnaires from one evidence-backed workspace.

Free  ·  No credit card  ·  Your first assessment takes about a minute

EXAMPLE COMPANY PROFILE

Northstar Systems

Public signals
86/ 100
LOW RISKRiskAssure IndexIllustrative · 5 of 8 shown
Security posture91
Vulnerability88
Dark web82
Third-party79
Reputation88
Is this your company?Claim your profile and add verified evidence.

One profile. Every security review.

01 Free breach-risk visibility
02 Unlimited questionnaires
03 Evidence-controlled trust center

Built for the people who ask, answer, and stand behind security questions.

Security teamsRisk & complianceProcurementTrusted advisers

01 / LIVE PRODUCT TOUR

Watch trust move
from proof to answer.

Scroll through the workflows your team and your buyers actually use. Every scene mirrors the current RiskAssure app.

PRODUCT WORKFLOWTRUST PROFILE

01

TRUST PROFILE

Establish trust before the first question.

Publish a domain-verified profile that keeps outside-in risk signals separate from company-approved evidence.
Index 86 · 12 approved sources · 78% coverage

EXAMPLE COMPANY PROFILENorthstar Systems

PUBLIC SIGNALS
86/ 100

LOW RISKRiskAssure IndexIllustrative · 5 of 8 shown

Security posture91
Vulnerability88
Dark web82
Third-party79
Reputation88

Is this your company?Claim your profile and add verified evidence.

DOMAIN VERIFIEDnorthstar.systems

APPROVED EVIDENCE12 sources78% coverage

01 / 04
01

TRUST PROFILE

Establish trust before the first question.

Publish a domain-verified profile that keeps outside-in risk signals separate from company-approved evidence.
Index 86 · 12 approved sources · 78% coverage
02

EVIDENCE LIBRARY

Put every claim on approved evidence.

Organize reports and policies once, then control exactly what is public, gated, or internal-only.
12 approved · 3 internal · 2 access-gated
03

CITED Q&A

Give buyers answers they can verify.

The security assistant answers from approved sources, shows citations, and flags anything that needs a person.
94% source support · 3 claims · 3 citations
04

QUESTIONNAIRE REVIEW

Move from upload to reviewed response.

Import unlimited questionnaires, inspect confidence and supporting evidence, then approve before anything leaves your team.
62 questions · 59 answered · 2 to review
Create your free trust center

FREE Unlimited questionnaires Human approval before sharing

02 / FREE TRUST CENTER

FREE FOR EVERY VENDOR

Know your exposure.
Prove your security.

RiskAssure combines outside-in breach-risk visibility with a controlled security trust center—so your team can fix what buyers see, share approved evidence, and move every questionnaire forward.

$0No monthly feeUnlimited questionnaires included
Create your free trust center

Northstar SystemsSecurity Trust Center

Access grantedVerified buyer session

DOMAIN-VERIFIED PROFILESecurity & Compliance

Review current security posture, company-approved evidence, and cited answers in one buyer-ready workspace.

✓ Domain ownership verified   ·   12 approved sources
OverviewAsk a questionUpload questionnaire
APPROVED EVIDENCESecurity documents & reports

Public files open immediately. Sensitive reports remain controlled.

SOC 2 Type II reportIndependent report · Aug 2026CONTROLLED ACCESSRequest access →
Penetration test summaryIndependent test · Jul 2026CONTROLLED ACCESSRequest access →
Information security policyCompany approved · Aug 2026AVAILABLEPreview →
01 / SEE THE RISK

Outside-in breach visibility

  • External asset and domain visibility
  • Vulnerability and patch signals
  • Dark web and leak monitoring
  • Risk ratings and remediation context
02 / SHARE THE PROOF

Buyer-ready security assurance

  • Controlled security trust center
  • Approved evidence content library
  • Access and NDA protection
  • Unlimited questionnaire imports and responses

03 / HOW IT WORKS

See the whole workflow.
Get the hours back.

Watch RiskAssure turn approved security evidence into cited answers, reviewed questionnaires, an explainable score, and a buyer-ready trust center.

74-second product filmFounder narrationCaptions included

RiskAssure launch filmOne governed evidence trail, from first question to shared proof.

Start a free scan
01Approve evidence02Answer with citations03Review questionnaires04Share a trust center

FOR VENDORS

Answer once.
Prove it everywhere.

Turn approved security work into a free, buyer-ready source of truth built for unlimited questionnaires.

  • 01 Correct and control your company profile
  • 02 Keep public signals separate from verified evidence
  • 03 Share documents with scoped access
  • 04 Complete unlimited questionnaires at no cost
Create your free trust center

FOR BUYERS

See the evidence.
Own the decision.

Move from a generic outside-in score to a review shaped by your relationship and risk appetite.

  • 01 Compare observable posture and approved proof
  • 02 Ask questions with source-backed context
  • 03 Track findings, conditions, and review dates
  • 04 Build a defensible review record
Explore the methodology

04 / THE RISKASSURE INDEX

A rating should
show its work.

The RiskAssure Index brings eight component scores into one view. Each covers a different dimension of observable cyber risk—from exposed technology and control hygiene to breach signals, third-party dependence, and company context.

Read common questions
Eight component scores brought together in one point-in-time RiskAssure Index.

Eight component scores

Observed signals · Context · Coverage

  1. Vulnerability

    Observable technical exposure

    Finds known vulnerabilities and exposed services on public-facing assets that can be confidently tied to the company.

    Looks at CVEs · exposed services · software versions · asset attribution

    Context: No observed finding does not prove an asset is vulnerability-free.

  2. Security Posture

    External control hygiene

    Assesses how securely the public-facing stack is configured across transport, domain, email, and browser protections.

    Looks at TLS · DNS · SPF / DKIM / DMARC · HTTP security headers

    Context: Observable configuration does not verify how internal controls operate.

  3. Dark Web

    Breach and credential exposure

    Checks monitored breach and leak sources for company-linked credentials, records, and incident evidence.

    Looks at breach datasets · credential leaks · domain matches · recency

    Context: No match reflects available sources and coverage—not proof of no exposure.

  4. Third-Party

    Connected ecosystem risk

    Identifies observable vendors and service providers, then considers the risk they introduce to the company’s external footprint.

    Looks at identified vendors · assessment coverage · provider posture · relationship confidence

    Context: Inferred relationships should be verified before they drive action.

  5. Breach Prediction

    Forward-looking risk signal

    Estimates future breach likelihood from current observable posture, exposure patterns, and available incident history.

    Looks at current factors · incident history · exposure trends · risk indicators

    Context: This is a forecast, not a guarantee; confidence falls when data is limited.

  6. Reputation

    Public security context

    Analyzes credible security-related reporting and incident coverage associated with the company.

    Looks at article volume · source credibility · recency · coverage tone

    Context: Public reporting adds context; it is not technical proof of a control or breach.

  7. Firmographic

    Business risk context

    Uses company characteristics to place observed risk in context, including size, age, industry, and security resources.

    Looks at employee count · company age · industry · security staffing

    Context: Firmographics provide context and do not measure security performance directly.

  8. IP Reputation

    Attributable network behavior

    Checks company-controlled public IP addresses against public threat blocklists and abuse intelligence.

    Looks at domain resolution · IP attribution · blocklist matches · abuse history

    Context: Shared CDN or cloud addresses are excluded; this component may be not measured.

Coverage is part of the result. Limited data, no finding, and not measured are three different states—and RiskAssure labels them that way.

05 / WHITE-LABEL PARTNERS

Your brand. Every client's trust center.

Launch a buyer-ready trust center with your logo, colors, custom domain, and a clear “Secured by Your Company” endorsement. Your brand secures the experience while every client keeps its name, evidence, access, and account.

See the partner experience
WHITE-LABEL STUDIOPARTNER ADMIN
Northstar SystemsSECURITY TRUST CENTER
trust.yourcompany.comSECURED BYYour Company
NORTHSTAR SYSTEMS VERIFIED CLIENT

Security evidence, ready when buyers ask.

Northstar Systems keeps its verified evidence, access controls, and ownership inside an experience secured by Your Company.

86TRUST SCORE
12Verified documents
94%Answer confidence
Evidence library Ask a questionAccess granted
SECURED BY YOUR COMPANYCLIENT: NORTHSTAR SYSTEMSCLIENT-OWNED EVIDENCE
Your logo & colorsYour custom domainOne client portfolioClient-owned data

06 / TRUST BY DESIGN

Clear signals.
Clear boundaries.

Cyber risk intelligence is useful only when people can understand its scope, challenge its findings, and see where the evidence came from.

01

Passive by default

No active vulnerability testing without explicit authorization.

02

Claim status shown

Unclaimed profiles are clearly separated from domain-verified company information.

03

Every score explained

Material findings include context, freshness, and a path to correction or dispute.

04

Evidence stays distinct

Company-approved proof builds assurance without silently rewriting the public Index.

07 / COMMON QUESTIONS

Understand the signal before you use it.

Plain-language answers about company risk ratings, profile claiming, and third-party risk reviews.

01What is a cyber risk rating?

A cyber risk rating is a point-in-time view of a company’s observable security posture. The RiskAssure Index organizes public signals into eight component dimensions and pairs the score with source context, freshness, and a plain-language risk tier.

02Does a high RiskAssure Index mean a vendor is approved?

No. The public Index is an outside-in signal, not a certification or purchasing decision. Buyers should evaluate it alongside approved first-party evidence, inherent risk, contracts, compensating controls, and their own risk appetite.

03What changes when a company claims its profile?

A domain-verified company can review its profile, request corrections, add approved security evidence, publish its free trust center, and complete unlimited security questionnaires. Claimed status identifies an owner; it does not erase the distinction between public signals and first-party evidence.

04Is the RiskAssure Trust Center really free?

Yes. The RiskAssure Trust Center is free and includes unlimited security questionnaires, an approved content library, controlled evidence sharing, and access and NDA protection. Buyer-side assessments and other managed risk services are separate from the vendor’s free trust center.

05Does RiskAssure actively test a company’s systems?

The public rating is designed around passive, outside-in signals. Active security testing should only occur with explicit authorization. Every material finding should be presented with its source date, scope, and limitations.

06How can advisers use RiskAssure with clients?

Auditors, vCISOs, MSPs, MSSPs, security firms, and privacy advisers can help clients organize approved evidence and launch buyer-ready trust centers while the client retains ownership of its account, data, and access decisions.

START WITH A SIGNAL

Check the company.
Then improve the answer.

Get a free risk rating Talk to RiskAssure