Penthropic TPRM

The TPRM that
verifies.

Janus

Most third-party risk tools take the vendor's word for it. Penthropic reads what they actually uploaded, checks every answer against their evidence, watches for drift after the deal closes, and shows you the breach path before it happens.

AI evidence cross-check
Drift detection on every resubmit
DORA / NIS2 / GDPR mapped
The magic moment

"Yes" doesn't mean yes.

A vendor will tell you exactly what you want to hear on a questionnaire. Their own SOC 2 report tells a different story. Penthropic reads both, and surfaces the gap before you sign.

The verify loop · Janus
VENDOR DOCS CROSS-CHECK QUESTIONNAIRE SOC 2 Type II report ISO cert 27001:2022 Policy access control DPA signed v3.1 AI evidence cross-check READ COMPARE CITE Q3.5 · Cyber Insurance £5m policy verified Q8.2 · Data residency EEA-only, confirmed ! Q15.4 · MFA on admin accounts Vendor claims YES, auditor says Q3 2026 CONTRADICTION Q11.7 · Backups + restore RPO ≤ 1h, RTO ≤ 4h Q19.1 · Sub-processor list Current + tier-tagged Verify before signing. Watch after signing. Show the breach path before it happens.

From the SOC 2 Type II

Globex Cloud · Type II report, page 42
"Multi-factor authentication for privileged accounts was deployed mid-period; the auditor noted full enforcement is expected Q3 2026."

Penthropic verdict

High confidence · auto-raised
CONTRADICTION
The vendor's questionnaire claims full MFA enforcement today. Their own auditor says full enforcement is not expected until Q3 2026. Risk auto-raised at severity High, mapped to NIS2 Art.21(2)(j), ISO 27001 A.5.16.
Verify before signing. Watch after signing. Show the breach path before it happens.
How it works

Third-party risk management.
Without the headaches.

No more PDF-eyeballing, no more "yes" answers no one checks, no more vendor-drift surprises six months later. Penthropic adds the layer that actually verifies, before, during, and after the relationship.

VERIFY WATCH SHOW
01
Verify

Cross-check every answer

AI reads every SOC 2, ISO certificate, policy and DPA the vendor uploaded. Compares each control claim in the questionnaire to what the evidence actually says.

  • Catches "yes" answers that contradict the SOC 2 testing section
  • Catches "in progress" controls dressed up as live
  • Page-and-line citations for every flag
  • Independent of vendor self-attestation
02
Watch

Catch drift after the deal closes

Re-runs the questionnaire on cadence and auto-raises a finding the moment a high-weight control regresses. The Tier 1 vendor that turned off MFA last quarter? You hear about it the same day.

  • Diffs current vs prior submission, control by control
  • Severity scaled to control weight + tier
  • Reassessment cadence driven by tier + risk
  • External monitoring (breach feeds, cert transparency) feeds the same engine
03
Show

Render the breach path

Attack-chain composer takes the vendor's open findings and renders a five-step, MITRE-aligned breach path. The narrative your board actually wants, not another list of CVEs.

  • Generated from real findings, not a generic template
  • Maps to MITRE ATT&CK techniques
  • One paragraph executive summary alongside the visual
  • Public link to share with senior leaders, no Penthropic login required
Versus the incumbents

The incumbents are slow, clunky,
and built for consultants, not you.

Most TPRM platforms take weeks to stand up, need a pro-services engagement to configure, and still leave your reviewers eyeballing PDF evidence by hand. Penthropic ships opinionated, live same day, and reads the evidence for you.

Typical TPRM Penthropic TPRM
Time to first vendor liveWeeks of pro-services✓ Same day, no consultant
Day-to-day UXHeavy, multi-portal, dated✓ One fast UI, keyboard-first
Editing questions, templates & rulesConsultant ticket, days to land✓ Edit in-app, live immediately
Send questionnaire, receive answers
Evidence vault + expiry tracking
Tier-aware questionnaires (Tier 1 / 2 / 3)Manual, often single template✓ 181Q / 32Q / 16Q auto-routed
AI cross-checks answers against the vendor's own evidence takes the answer as truth✓ Penthropic-unique
Drift detection on resubmit point-in-time only✓ Auto-raises on regression
Attack-chain narrative per vendor risk register only✓ MITRE-aligned, board-ready
Multi-perspective AI review (InfoSec / Privacy / Legal / Procurement)Single-lens or none✓ Four specialists + synthesiser
Regulatory rollup on every finding (DORA, NIS2, GDPR, FCA)Pay-extra add-on✓ Out of the box
Business Owner portal (separate UX, soft training gate)Same UI for everyone✓ Purpose-built
Senior-leader approval via public link (no login)Login required✓ Signed link, mobile-friendly
Concentration map, where your vendors share infrastructureManual analysis✓ Provider, region, country, type
Sector-ready

The regulators don't care about features.

They care whether you can answer the question: "how do you know what your vendors are doing?". Penthropic gives you a defensible answer for every regulator you face.

UK + EU Financial Services

FCA SYSC 8.1 outsourcing oversight, PRA SS2/21 operational resilience, and EU DORA (Regulation 2022/2554) on ICT third-party risk. Every finding tagged to the article that applies, Penthropic produces the audit trail the regulator asks for.

FCA SYSC 8.1.7RPRA SS2/21DORA Art.28DORA Art.11

NIS2 + cyber-regulated

NIS2 Art.21 covers third-party risk management as a mandatory control. Penthropic auto-tags every finding to the NIS2 paragraph that bites and produces the evidence pack your supervisory authority will ask for.

NIS2 Art.21(2)(d)NIS2 Art.21(2)(j)NIS2 Art.23

UK GDPR + data privacy

Article 28 processor obligations, Article 32 security of processing, Article 33 breach notification. Penthropic flags every gap and routes the right risk to your DPO.

GDPR Art.28GDPR Art.32GDPR Art.33UK DPA 2018

ISO 27001 + SOC 2 alignment

Every finding controls-mapped to ISO 27001:2022 Annex A and the relevant SOC 2 Trust Service Criteria, ready to drop into your control evidence library.

ISO 27001 A.5.7ISO 27001 A.5.16SOC 2 CC6.1SOC 2 CC7.2

How we score your vendors

Our automated scorecard combines passive asset discovery with continuous threat-intelligence checks. Every signal is observable, every finding is actionable.

🔍

Asset discovery sources

We map each vendor's external attack surface using Certificate Transparency logs (crt.sh), the Wayback CDX API, subdomain enumeration via Cloudflare DoH, and SecurityTrails passive DNS. We then resolve IPs, detect cloud provider ranges (AWS, GCP, Azure, Cloudflare, Fastly), and fingerprint the tech stack from HTTP response headers.

Scan checks performed

After mapping assets we run lightweight checks: MTA-STS and DMARC policy enforcement, SPF alignment, legacy TLS version detection, DNSSEC presence, subdomain takeover (dangling CNAME), leaked credentials from breach databases, and ransomware leak-site mention matching. Each check maps to a severity score from 1 (low) to 8 (critical).

🚫

What we do NOT scan

No active port scanning, no exploit probing, no destructive tests. We perform read-only passive reconnaissance — we observe what is already publicly visible on the internet. We do not access dark web marketplaces, purchase stolen credentials, or enumerate internal systems. All checks carry a Penthropic-Scorecard User-Agent so you can identify our traffic.

📊

Severity and scoring rubric

Each finding is assigned a severity from 1 (Low) to 8 (Critical). The scorecard score is 100 − ∑(active finding weights), clamped to 0–100, then converted to a letter grade: A (90+), B (75–89), C (60–74), D (40–59), F (<40). Severity bumps apply when a scan finding directly contradicts a security claim your vendor submitted in their questionnaire.

Disputes via the vendor portal

Every finding can be disputed. Vendors log in to the vendor portal and submit a written explanation or evidence for review. Accepted disputes are marked resolved and removed from the active score; rejected disputes are logged with reasoning. Vendors can also request a rescan after remediating an issue.

🔄

Refresh cadence and contact

Asset graphs are rebuilt weekly (Sunday, 03:00 UTC). Threat-intelligence signals refresh nightly. Score snapshots are written after each sweep so trend data is always current. Questions about a specific finding? Contact us at security@penthropic.ai or visit penthropic.ai.

Stop trusting the questionnaire.
Start verifying it.

Penthropic TPRM reads the SOC 2, cross-checks every "yes" against the evidence, watches for drift after the deal closes, and renders the breach path your board can actually understand. Built by cyber practitioners who got tired of TPRM tools that just shuffle PDFs around.

Book a discovery call Talk to the founder

DORA · NIS2 · GDPR · FCA mapped out of the box. London-based founding team. One business-day response.