Service
Third-party & vendor security review
Assess suppliers, subcontractors and managed providers before signature — and throughout the contract.
The problem we solve
A growing share of incidents comes through a supplier: managed services, SaaS software, a subcontractor with remote access. Questionnaires come back incomplete, nobody has time to analyze them, and the security clauses in contracts stay generic.
Who it is for
- Organizations entrusting sensitive data to service providers
- Procurement and legal teams qualifying a vendor before signature
- Companies subject to Law 25 for transfers of personal information
What is included
- Vendor tiering by criticality
- Questionnaire scaled to each third party’s risk level
- Analysis of SOC 2 reports, ISO certificates and responses received
- Recommended contractual security clauses
- Documented annual follow-up process
Our approach
We start by inventorying your third parties and ranking them by the data and access they hold. Critical vendors get an in-depth review, the rest a lighter questionnaire. Every review ends with a clear decision: accept, accept with conditions, or decline.
Typical deliverables
Third-party register
Ranked by criticality and access type
Assessment sheets
One per critical vendor, with a reasoned opinion
Clause templates
Security, incident notification, right to audit
Follow-up procedure
Frequency and reassessment triggers
Expected outcomes
- Purchasing decisions backed by evidence
- Contracts that actually protect you during an incident
- A repeatable process your teams can run without us