Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Vendor Risk Calculator

Rate a third-party vendor's risk from the data they access, the certifications they hold, and how critical they are to your business. The risk tier and recommended due diligence update live as you choose.

Vendor risk tier
Medium
0 / 100 risk points
Recommended due diligence
    How the score works. Points across four factors (data sensitivity, system access, business criticality, certification status) give an inherent-risk score; a reviewed certification lowers it. Use it to right-size due diligence, and factor in geography, breach history and fourth parties separately.

    Questions

    What makes a vendor high risk?

    The biggest drivers are how sensitive the data they access is, how deeply they integrate with your systems, and how critical they are to operations. A vendor with broad access to customer data and no recognized certification is the classic high-risk case.

    Do certifications like SOC 2 lower vendor risk?

    Yes. A current SOC 2 Type II or ISO 27001 report is independent evidence that the vendor operates real controls, so it lowers the residual risk. It does not eliminate it, and you should still review the report and any exceptions.

    How should I use the risk tier?

    Use it to right-size due diligence. Low-risk vendors may need only a basic review, while high-risk vendors warrant a security questionnaire, evidence review, contractual security terms, and periodic reassessment.

    How often should vendors be reassessed?

    Reassess high-risk vendors at least annually and whenever their access or your relationship changes materially. Lower-risk vendors can be reviewed on a longer cycle.

    Is this calculator free?

    Yes, it is free with no signup. If you need a full third-party risk program or vendor assessment, our team can help.

    Not ready for a call yet?

    Get the compliance playbook

    A few short notes from Jacob on getting audit-ready without months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Third-Party Risk Management

    A managed program for vetting and monitoring your vendors.

    Explore Third-Party Risk Management →

    Build a vendor risk program that holds up.

    Auditors and enterprise customers will ask how you vet your vendors. We help you stand up third-party risk management as part of your compliance program, backed by auditor management and advocacy when it's time for the audit.

    See our security services Book a call

    Want the full picture on your vendors?

    This gives you the shape of the problem. traztech Workspace gives you a proper vendor register: tier every supplier by the data they touch, send them a questionnaire, keep the answers next to the controls that depend on them, and set the review date so it does not lapse. Start free and run your whole vendor list through it.

    Start your free vendor assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.