UprootSecurity
Book a demo

64 vendors under continuous assessment

PRODUCT

Every vendor is a control surface.

SOC 2 freshness, DPA expiry, breach signals, and account hygiene tracked live for every third party that touches your data. Risk scores recompute the moment a signal changes, not once a year on a forgotten spreadsheet.

Start free trialSee the risk model
64Vendors tracked
DailyBreach sweep
3Flagged now
app.uproot.security · /vendorsLive
Vendor risk register
64 vendors · continuous · last sweep 2m ago
B+
Portfolio
Low risk
52
Medium
9
High
3
Expiring docs
5
VendorTierRisk
SN
Snowflake
data warehouse · PII
Critical
A · 12
DD
Datadog
observability · logs
High
A− · 18
PX
PixelProxy
image CDN · sub-processor
Medium
B · 41
RP
Rippling
HRIS · employee PII
High
A− · 16
ZK
Zoko
messaging · no PII
Low
A · 9
Breach signal · PixelProxy
public disclosure · 4m ago

Sub-processor PixelProxy disclosed an incident affecting CDN logs. Score recomputed; owner notified.

B · 41C · 63
How vendor risk stays current

Onboard once. Re-assessed forever.

The annual questionnaire is a snapshot that's stale the day it's filed. Uproot treats a vendor like any other monitored surface assessed at intake, then continuously, with the score moving when reality does.

01Intake

Discover, don't chase.

Vendors are pulled from SSO, expense data, and OAuth grants including the shadow ones nobody filed a ticket for. Each gets a data-sensitivity tier on intake.

Discovery automatic
02Assess

Documents become a live score.

SOC 2 reports, DPAs, and pentest letters are parsed and expiry-tracked. Combined with tier and access scope, they produce a risk score you didn’t fill in by hand.

Inputs docs + access
03Watch

Signals move the score in real time.

A daily breach sweep, expiry clocks, and access changes feed back continuously. A new disclosure or a lapsed DPA recomputes the score the same day it happens.

Sweep daily
04Act

Route the risk to an owner.

When a score crosses your threshold, the vendor owner is paged with the why and the next step renew the DPA, request a bridge letter, or revoke access entirely.

Owner notified
Inside a vendor profile

The score is the headline. The why is one click down.

Every vendor carries a living profile: the documents on file, the access it holds, the signals against it, and the full history of how its score has moved. No quarterly re-survey required.

SN
Snowflake
data warehouse · critical · PII
A · 12
SOC 2 Type II on file
period ends 2026-09 · no exceptions
Fresh
DPA executed
expires 2027-01 · auto-reminder set
Valid
Admin access · SSO + MFA
4 admins · just-in-time elevation
Enforced
Sub-processor list changed
+1 new region · review queued
Review
A profile that grades itself

Risk you can defend, not a number you made up.

The score is a function of inputs you can inspect attestation freshness, DPA status, data tier, access scope, and live signals. Every component is shown, so when a board member asks "why is this one a C," the answer’s on screen.

SOC 2 / ISO attestation parsed, with the report period and exceptions surfaced

DPA and sub-processor list tracked with expiry clocks

Access scope from SSO and OAuth what they can actually reach

See a full vendor profile
PixelProxy · risk history
B → C · last 90d
today · 02:14Z
Breach disclosed → score B (41) to C (63)
CDN log exposure reported; owner @platform-eng paged.
14 days ago
Sub-processor added → +6
New EU region introduced; pending data-flow review.
41 days ago
DPA renewed → −4
Updated DPA executed; expiry pushed to 2027.
intake · 90 days ago
Onboarded at B (39)
Medium tier; SOC 2 on file, scoped CDN access.
The score has a history

Watch risk move, with the reason attached.

Every change to a score is logged with the signal that caused it. A lapsed attestation, a public breach, a widened access grant the timeline is an audit trail of your third-party risk decisions, not just current state.

Daily breach & disclosure sweep across public sources

Expiry clocks for every document, surfaced before they lapse

Each score change is dated, sourced, and exportable as evidence

How scoring works
Outbound · PixelProxy SIG-Lite
sent 4d ago · 2 reminders · 84% complete
Awaiting
Inbound · Mercury security review
312 questions · 298 auto-answered from library
Drafted
Inbound · Plaid vendor assessment
answered from live posture · shared read-only
Sent
Answer library
142 reusable answers · synced to controls
Live
Both sides of the questionnaire

Send them once. Answer yours from live proof.

When a vendor needs chasing, Uproot sends and tracks the questionnaire for you. And when a prospect sends you one, you answer from the same evidence library pointing at live artifacts instead of re-typing 300 rows.

Outbound questionnaires with reminders and a response portal

Inbound questionnaires answered from your live posture

A reusable answer library that stays current as your controls change

See questionnaire automation

What continuous beats annual on, in numbers.

64
Vendors under continuous assessment for a typical customer
4m
From public breach disclosure to a recomputed score and a page
298
Of 312 inbound questionnaire answers drafted from the library
What feeds the score

Four signal families. One number you can defend.

A vendor's risk score is a transparent weighting of these inputs each tracked continuously and tied to the data tier of what they can touch.

AT
Attestationsparsed

Third-party assurance reports, read and expiry-tracked not just filed and forgotten.

SOC 2 Type II · period + exceptions1d
ISO 27001 certificate validity1d
Pentest / bridge letters1d
LG
Legal & datatracked

The contracts that govern what a vendor may do with your data, with expiry clocks that surface before they lapse.

DPA executed + expiry1d
Sub-processor list changes1d
Data residency commitments1d
AC
Access hygienelive

What the vendor can actually reach in your environment pulled from SSO and OAuth, not self-reported.

SSO + MFA on vendor admins1h
OAuth scope & token age1h
Data-tier of granted access1h
SG
External signalsswept daily

Public evidence of trouble breaches, disclosures, and security posture changes the vendor didn't tell you about.

Breach & disclosure feeds1d
Public security posture changes1d
Status-page incident history1h
TR
Tieringon intake

Not every vendor matters equally. The score is weighted by the sensitivity of what they touch.

Data classification reachedintake
Business criticalityintake
Blast radius if breachedintake
HS
Historyretained

Every score movement, with its cause, kept as evidence the audit trail of your third-party risk program.

Score-change log per vendorevent
Owner decisions + rationaleevent
Exportable as audit evidenceon demand

When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort.

HH
Hiren HasmukhCo-Founder & CEO
2d
Ahead of the vendor's own breach notification
Common questions

What teams ask about the risk model.

A vendor score is only useful if you can explain it. Here's what sits behind the number.

How is the risk score actually calculated?+

It's a transparent weighting of attestation freshness, legal status (DPA, sub-processors), access hygiene, external signals, and data tier. Every component is visible on the profile, and you can tune the weighting no opaque black-box number.

Where do the breach signals come from?+

A daily sweep across public disclosure feeds, status pages, and security-posture sources. When a signal matches a vendor in your register, it's attached to that vendor's timeline and the score recomputes the same day often ahead of the vendor's own notice.

How do you find shadow vendors we didn't register?+

Discovery pulls from SSO sign-in logs, OAuth grants, and expense data to surface tools that never went through procurement. Each gets a tier and enters the same continuous assessment as the ones you onboarded deliberately.

Can Uproot answer inbound security questionnaires for us?+

Yes inbound questionnaires auto-draft from your live evidence library (in our example, 298 of 312 answered with no human input). You review the draft, or share a scoped read-only trust view instead of a spreadsheet.

Does a score change create evidence?+

Every score movement is logged with its cause, the owner's decision, and the date and exports as audit evidence. Your third-party risk program produces its own paper trail just by running.

Find out which vendor is your weakest link.

Connect SSO and Uproot will discover your real vendor footprint shadow tools included and score every one within the hour.

Start free trialBook a demo

Auto-discovery

Shadow vendors surfaced from SSO and OAuth.

Continuous, not annual

Scores move when reality does.

Defensible scoring

Every input visible; weighting is yours to set.

Questionnaires, both ways

Send them; answer yours from live proof.