Penthropic TPRM

See how Penthropic verifies your vendors?

Book a Discovery Call

Third-party risk management

The vendor answers.
The AI reads the evidence.
You see the gap.

Most third-party risk tools record the answer and file the document. Penthropic reads the SOC 2 report, the ISO certificate, the policies and the DPA the vendor uploaded, then checks every high-stakes answer against them. When the answer and the evidence disagree, you hear about it before signature, not six months after it.

AI evidence cross-check Drift detection on every resubmit Regulator evidence packs for six frameworks

Built for

Fintech SaaS Media and broadcast PE-backed firms Financial services Professional services

The moment that matters

“Yes” does not mean yes.

A vendor answers the questionnaire the way they want to be read. Their own SOC 2 report says something else. The AI reads both and puts the two sentences side by side, before you sign.

Q15.4 · Multi-factor authentication on administrative accounts Illustration
Claimed · the questionnaire answer

Yes

Enforced on all administrative accounts, today.

“Multi-factor authentication is enforced on all administrative accounts.”

Source: the vendor's own words, kept on the record

Observed · the vendor's own evidence

Q3 2026

When their own auditor expects full enforcement.

“Multi-factor authentication for privileged accounts was deployed mid-period; the auditor noted full enforcement is expected Q3 2026.”

Source: SOC 2 Type II report, uploaded by the vendor

Contradiction

The answer says enforced today. The vendor's own auditor says full enforcement is not expected until Q3 2026. Put in front of your analyst at severity High, carrying that question's own control reference, NIST CSF: PR.AC-7. The platform proposes; a person on your side decides.
The shape of a real cross-check. The vendor, the wording and the dates are illustrative, not a client record.
Evidence cross-check · one vendor submissionIllustration
readSOC 2 Type II report, ISO 27001 certificate, access control policy, signed DPA
keepThe vendor's own wording, stored against each answer so it can be contradicted later
compareEvery high-stakes answer measured against what those documents say
flagContradiction, carrying the sentence from the document when the model can point to one
partialUnfinished: a read the model did not complete is reported as unfinished, never as a pass
Drawn to show the shape of a run, not a measurement. Nothing here is a client record.

How it works

Verify before signing. Watch after signing. Show the path.

Three jobs on the same vendor record. No reading PDF evidence by hand, no “yes” nobody checked, no drift you find out about at renewal.

01 · Verify

Cross-check every high-stakes answer

The AI reads every SOC 2 report, ISO certificate, policy and DPA the vendor uploaded, then compares every high-weight control claim in the questionnaire with what the evidence says.

  • Catches a “yes” that contradicts the SOC 2 testing section
  • Catches an “in progress” control dressed up as live
  • Carries the sentence from the document when the model can point to one
  • Independent of vendor self-attestation
02 · Watch

Catch drift after the deal closes

The questionnaire re-runs on a cadence, and a finding is opened the moment a high-weight control regresses. A Tier 1 vendor that turned multi-factor authentication off last quarter shows up the same day.

  • Diffs the current submission against the prior one, control by control
  • Severity scaled to control weight and vendor tier
  • Reassessment cadence driven by tier and risk
  • External monitoring, breach feeds and certificate transparency feed the same engine
03 · Show

Render the breach path

The attack-chain composer takes the vendor's open findings and renders a five-step, MITRE-aligned breach path. The narrative a board asks for, rather than another list of CVEs.

  • Built from that vendor's real findings, not a generic template
  • Mapped to MITRE ATT&CK techniques
  • A one-paragraph executive summary beside the visual
  • A public link for senior leaders, with no Penthropic login

Four specialists read the same submission

Every submission gets a multi-perspective review, and the four views are synthesised into one. A privacy problem and a procurement problem do not look alike, and neither is found by reading the questionnaire once.

InfoSec Privacy Legal Procurement Synthesiser

Versus the incumbents

Built for the person doing the review.

Most third-party risk platforms take weeks to stand up, need a professional services engagement to configure, and still leave your reviewers reading PDF evidence by hand.

Typical third-party risk platforms compared with Penthropic TPRM
Capability Typical TPRM Penthropic TPRM
Time to first vendor liveWeeks of professional servicesSame day. We send your access credential by hand, then you self-serve
Day-to-day interfaceHeavy, multi-portal, datedOne fast interface, keyboard first
Editing questions, templates and rulesA consultant ticket, days to landEdited in the app, live immediately
Send a questionnaire, receive answersYesYes
Evidence vault with expiry trackingYesYes
Tier-aware questionnairesManual, often a single template181Q, 32Q and 16Q, routed by tier
AI cross-checks answers against the vendor's own evidenceTakes the answer as truthReads the evidence and cites what it read
Drift detection on resubmitPoint-in-time onlyOpens a finding on regression
Attack-chain narrative per vendorRisk register onlyMITRE-aligned, written for a board
Multi-perspective AI reviewSingle lens, or noneFour specialists and a synthesiser
Regulator evidence pack (DORA Art.28, NIS2 Art.21, FCA SYSC 13, UK GDPR Art.28, ISO 27001:2022 A.5.19–5.22, NIST CSF supply chain)A paid add-onSix packs, included, with gaps shown as gaps
Senior-leader approval by public linkLogin requiredSigned link, works on a phone
Concentration map, where your vendors share infrastructureManual analysisProvider, region, country and type

Sector ready

The regulators do not care about features.

They care whether you can answer one question: how do you know what your vendors are doing? Penthropic gives you an answer you can defend, and shows a gap as a gap.

SaaS and tech
Touch EU personal data and GDPR holds you responsible for your processors. If you are treated as an essential or an important entity, NIS2 makes third-party risk management mandatory.
Finance, health, media
DORA, NIS2 and sector rules make overseeing your vendors' security a legal requirement rather than good practice.
Anyone on public cloud
Auditors and customers expect your vendors' controls mapped to ISO 27001, the same evidence your own SOC 2 or ISO audit asks you to produce.
UK and EU financial services

The reference travels with the question

Questions on outsourcing oversight, operational resilience and ICT third-party risk carry the reference they were written against. When an answer regresses and a finding is raised, that finding inherits the question's reference. Findings raised by external monitoring or by the attack-surface scan carry no reference at all, and show none rather than a guess.

DORA Art.28DORA Art.19DORA Art.6FCA SYSC 8FCA PS21/3EBA OG 2019/02
NIS2 and cyber-regulated

A pack of seven measures, gaps included

NIS2 Art.21 covers third-party risk management as a mandatory control. Penthropic ships a NIS2 evidence pack that groups your vendor's answers and uploaded documents under seven named Art.21 measures. A measure nothing evidences is shown as a gap, and one the evidence cannot grade is shown as unassessable, never folded into covered. We do not tag findings to an article paragraph, because the question bank does not carry NIS2 references and we will not print one we did not map.

Evidence pack: NIS2 Art.217 named measures
UK GDPR and data privacy

What the ICO pack actually reaches

Processor obligations, international transfers, breach notification, retention and data subject rights. The bank carries a UK GDPR or GDPR article reference on 34 questions. The ICO Art.28 evidence pack is a separate view and is not built from that reference: it matches a keyword against each question and its references, and gathers answers, vault documents and sub-processor records under six named Article 28 obligations. That draws in 21 questions from the bank, 8 of them from those 34. An obligation nothing matches is shown as a gap.

UK GDPR Art.28UK GDPR Art.33UK GDPR Art.44UK GDPR Art.46GDPR Art.35
ISO 27001, SOC 2 and NIST CSF

Mapped where we mapped it, and nowhere else

NIST CSF is the densest mapping in the bank: 60 questions carry a NIST CSF reference, 15 carry an ISO 27001 reference and 5 name SOC 2 at the report level. In total 133 of the 422 built-in questions carry a control reference. The rest carry none, and the report shows none, because a mapping we did not make is not a mapping.

NIST CSF: PR.AC-1NIST CSF: DE.CM-8ISO 27001: A.5.1ISO 27001: A.9.2.5SOC 2 Type II

Scorecard methodology

How a vendor's score is built, and what it will not tell you.

The scorecard pairs passive asset discovery with continuous threat-intelligence checks. Every signal is observable from outside the vendor, and a check that could not run is recorded as unchecked rather than as clean.

A 90 and above B 80 to 89 C 70 to 79 D 60 to 69 F below 60
Discovery

Where the assets come from

We map each vendor's external attack surface using Certificate Transparency logs (crt.sh), the Wayback CDX API and subdomain enumeration via Cloudflare DNS over HTTPS. We then resolve IPs, detect cloud provider ranges (AWS, GCP, Azure, Cloudflare, Fastly), and fingerprint the tech stack from HTTP response headers. The collector that found each asset is recorded against it, so the provenance travels with the asset.

Checks

What is actually checked

After mapping assets we run lightweight checks: DMARC policy (published, monitor-only or enforced), SPF record presence and a missing all qualifier, MTA-STS policy presence, DNSSEC presence, TLS certificate expiry, subdomain takeover (dangling CNAME), registered typosquat domains, missing HSTS, CSP and clickjacking headers, publicly catalogued breaches of the vendor's own domain in Have I Been Pwned, and domain reputation from AlienVault OTX. Each check maps to a severity score from 1 (low) to 8 (critical). When a lookup fails, the DNS, breach and reputation checks record an explicit unchecked result with the reason, rather than reporting the vendor as clean.

Not on the scorecard. Legacy TLS version detection is not built for vendor scans and does not run. Ransomware leak-site matching is built and sweeps daily, but a hit lands in Dark Web Watch as a match for review, not as a scorecard finding, so it does not move a vendor grade. VirusTotal and Google Safe Browsing left the vendor scan on 17 September 2026, because both licence their free tiers for non-commercial use only. Their rows stay on the vendor record, marked not checked with that reason, rather than disappearing.

Boundaries

What we do not scan

No active port scanning, no exploit probing, no destructive tests. We perform read-only passive reconnaissance, we observe what is already publicly visible on the internet. We do not access dark web marketplaces, purchase stolen credentials, or enumerate internal systems. Requests that reach your vendor name us in the User-Agent, so they can identify our traffic in their logs: Penthropic-Scorecard/1.0 from the asset-discovery collectors, and Penthropic-Signal/1.0 from the security-header and lookalike-domain checks.

Rubric

Severity and scoring

Each finding is assigned a severity from 1 (Low) to 8 (Critical). The scorecard score is 100 − ∑(active finding weights), clamped to 0–100, then converted to a letter grade: A (90+), B (80–89), C (70–79), D (60–69), F (<60). Severity bumps apply when a scan finding directly contradicts a security claim your vendor submitted in their questionnaire.

Disputes

How a vendor pushes back

Every finding can be disputed. Vendors log in to the vendor portal and submit a written explanation or evidence. The dispute is recorded against the finding with the vendor's reason and the date, and the finding is marked as awaiting review. Raising a dispute does not move the score; the decision on it does. If we uphold the dispute we are agreeing the finding was wrong about the vendor, so it is marked resolved and removed from the active score, with the decision, the written reason and the reviewer recorded against it. If we reject it, the finding stands exactly as it was. A finding also leaves the active score when it is closed or when the risk is formally accepted, and each of those is a recorded action with an owner. Vendors can also request a rescan after remediating an issue.

Cadence

How often it refreshes

Asset graphs are rebuilt weekly (Sunday, 03:00 UTC). Threat-intelligence signals refresh nightly. Score snapshots are written after each sweep so trend data is always current. Questions about a specific finding? Contact us at security@penthropic.ai or visit penthropic.ai.

Next step

Stop trusting the questionnaire. Start verifying it.

Thirty minutes on one of your own vendors: what the AI would read, what it would check the answers against, and who on your side would see the result.

TPRM is part of the platform subscription. There is no separate TPRM price list. Pricing is here, and the vendor allowance in each tier is stated on it.

Six regulator evidence packs included. London based, UK hosted. Reply within 1 business day.