Third-party security assurance

Assess suppliers in hours, not weeks.

AI-powered third-party security assurance that turns supplier questionnaires and security evidence into explainable, audit-ready risk assessments.

AI drafts the analysis. Your analysts make every decision.

The problem

Supplier assurance hasn't kept up with the number of suppliers.

Security teams send long questionnaires, collect stacks of documents and read them by hand. By the time a supplier is approved, the evidence is already ageing.

Weeks per supplier

Manual review of questionnaires, certificates and reports creates long queues and delayed onboarding.

One-size-fits-all questionnaires

Low-risk vendors get the same 300 questions as critical ones, wasting everybody's time.

Claims taken at face value

Answers are rarely compared with evidence, so gaps and contradictions slip through to approval.

How it works

From intake to decision in five steps.

  1. 1

    Tier the supplier

    Score data sensitivity, criticality and access to set inherent risk.

  2. 2

    Send a sized questionnaire

    Light, standard, enhanced or full — based on the tier.

  3. 3

    Collect evidence

    Suppliers answer and upload documents in their own portal.

  4. 4

    AI checks claims

    Each answer is compared with the documents, with citations.

  5. 5

    Analyst decides

    Reviewers confirm findings and approve, conditionally approve or reject.

Evidence-first AI

AI that shows its working — and knows when it can't tell.

The AI never approves a supplier and never sets the final risk score. It reads what was supplied, cites it, and flags what is missing.

Cited sources

Every verdict points to the document and page or section it relies on.

Says “insufficient evidence”

If the documents don't support a claim, it says so instead of guessing.

Contradictions and stale evidence

Flags answers that conflict with documents, and evidence past its freshness window.

Human sign-off

Findings are drafts until an analyst confirms them, with a full provenance trail.

Risk scoring

Deterministic, explainable scores.

Inherent and residual risk are calculated from fixed, visible rules — not by a language model. Every score lists the drivers behind it.

What moves the residual score

  • Control effectiveness, as confirmed by reviewers
  • Open critical and high findings
  • Evidence gaps and stale or expired documents
  • Contradictory evidence
  • Overdue and validated remediation actions

Risk levels — shown with icon, label and score

  • Critical75–100
  • High50–74
  • Medium25–49
  • Low0–24

Supplier portal

A simple, separate space for your suppliers.

Answer and upload

Suppliers see only their assigned questionnaires and upload evidence securely.

Clarifications

Your analysts ask follow-up questions; suppliers reply in one place.

Internal stays internal

Suppliers never see your risk scores, methodology, internal notes or other suppliers.

Remediation

Turn findings into tracked actions.

Create an action from any material finding, assign an owner and due date, and require reviewer validation before it is closed.

OpenIn progressPending validationResolvedAccepted risk

Closing an action needs a reviewer note — recorded in the audit log.

Framework support

Map controls across the frameworks you use.

Available today

ISO/IEC 27001NIST CSF 2.0GDPRCustom frameworks

On the roadmap

NIS2DORACyber EssentialsPCI DSS

AssureFlow helps you assess suppliers against these frameworks. It does not certify compliance.

Security

Built for sensitive supplier evidence.

Tenant isolation

Every record is scoped to your organisation and enforced in the database.

Private evidence storage

Documents are never public; access uses short-lived signed links.

Role-based access

Admins, analysts, reviewers, executives and suppliers each see only what they need.

Immutable audit log

Views, downloads, decisions and changes are recorded — without document contents.

Server-side AI

AI runs only on the server. No keys in the browser.

Upload scanning

Files are checked for type, size, macros and embedded scripts before storage.

Session controls

Inactive sessions sign out automatically.

Rate limiting

Uploads, analysis and portal activity are throttled to limit abuse.

Pricing

Plans that scale with your supplier base.

Starter

For teams starting a structured programme.

Free

  • Up to 5 suppliers
  • Risk tiering & questionnaires
  • Supplier portal
  • Evidence vault
Start free
Most popular

Professional

For growing GRC teams.

Contact us

  • Unlimited assessments
  • AI evidence analysis
  • Remediation & approvals
  • Executive reports
Book a demo

Enterprise

For complex, regulated organisations.

Custom

  • Custom frameworks
  • Multiple business units
  • Advanced roles
  • Dedicated support
Talk to us

FAQ

Common questions.

Run your first supplier assessment today.

Start free, or book a walkthrough with our team.