64 vendors under continuous assessment
PRODUCTSOC 2 freshness, DPA expiry, breach signals, and account hygiene tracked live for every third party that touches your data. Risk scores recompute the moment a signal changes, not once a year on a forgotten spreadsheet.
Sub-processor PixelProxy disclosed an incident affecting CDN logs. Score recomputed; owner notified.
The annual questionnaire is a snapshot that's stale the day it's filed. Uproot treats a vendor like any other monitored surface assessed at intake, then continuously, with the score moving when reality does.
Vendors are pulled from SSO, expense data, and OAuth grants including the shadow ones nobody filed a ticket for. Each gets a data-sensitivity tier on intake.
SOC 2 reports, DPAs, and pentest letters are parsed and expiry-tracked. Combined with tier and access scope, they produce a risk score you didn’t fill in by hand.
A daily breach sweep, expiry clocks, and access changes feed back continuously. A new disclosure or a lapsed DPA recomputes the score the same day it happens.
When a score crosses your threshold, the vendor owner is paged with the why and the next step renew the DPA, request a bridge letter, or revoke access entirely.
Every vendor carries a living profile: the documents on file, the access it holds, the signals against it, and the full history of how its score has moved. No quarterly re-survey required.
The score is a function of inputs you can inspect attestation freshness, DPA status, data tier, access scope, and live signals. Every component is shown, so when a board member asks "why is this one a C," the answer’s on screen.
SOC 2 / ISO attestation parsed, with the report period and exceptions surfaced
DPA and sub-processor list tracked with expiry clocks
Access scope from SSO and OAuth what they can actually reach
Every change to a score is logged with the signal that caused it. A lapsed attestation, a public breach, a widened access grant the timeline is an audit trail of your third-party risk decisions, not just current state.
Daily breach & disclosure sweep across public sources
Expiry clocks for every document, surfaced before they lapse
Each score change is dated, sourced, and exportable as evidence
When a vendor needs chasing, Uproot sends and tracks the questionnaire for you. And when a prospect sends you one, you answer from the same evidence library pointing at live artifacts instead of re-typing 300 rows.
Outbound questionnaires with reminders and a response portal
Inbound questionnaires answered from your live posture
A reusable answer library that stays current as your controls change
A vendor's risk score is a transparent weighting of these inputs each tracked continuously and tied to the data tier of what they can touch.
Third-party assurance reports, read and expiry-tracked not just filed and forgotten.
The contracts that govern what a vendor may do with your data, with expiry clocks that surface before they lapse.
What the vendor can actually reach in your environment pulled from SSO and OAuth, not self-reported.
Public evidence of trouble breaches, disclosures, and security posture changes the vendor didn't tell you about.
Not every vendor matters equally. The score is weighted by the sensitivity of what they touch.
Every score movement, with its cause, kept as evidence the audit trail of your third-party risk program.
When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort.

A vendor score is only useful if you can explain it. Here's what sits behind the number.
It's a transparent weighting of attestation freshness, legal status (DPA, sub-processors), access hygiene, external signals, and data tier. Every component is visible on the profile, and you can tune the weighting no opaque black-box number.
A daily sweep across public disclosure feeds, status pages, and security-posture sources. When a signal matches a vendor in your register, it's attached to that vendor's timeline and the score recomputes the same day often ahead of the vendor's own notice.
Discovery pulls from SSO sign-in logs, OAuth grants, and expense data to surface tools that never went through procurement. Each gets a tier and enters the same continuous assessment as the ones you onboarded deliberately.
Yes inbound questionnaires auto-draft from your live evidence library (in our example, 298 of 312 answered with no human input). You review the draft, or share a scoped read-only trust view instead of a spreadsheet.
Every score movement is logged with its cause, the owner's decision, and the date and exports as audit evidence. Your third-party risk program produces its own paper trail just by running.
Connect SSO and Uproot will discover your real vendor footprint shadow tools included and score every one within the hour.
Auto-discovery
Shadow vendors surfaced from SSO and OAuth.
Continuous, not annual
Scores move when reality does.
Defensible scoring
Every input visible; weighting is yours to set.
Questionnaires, both ways
Send them; answer yours from live proof.