Third-party security assurance
Assess suppliers in hours, not weeks.
AI-powered third-party security assurance that turns supplier questionnaires and security evidence into explainable, audit-ready risk assessments.
AI drafts the analysis. Your analysts make every decision.
The problem
Supplier assurance hasn't kept up with the number of suppliers.
Security teams send long questionnaires, collect stacks of documents and read them by hand. By the time a supplier is approved, the evidence is already ageing.
Weeks per supplier
Manual review of questionnaires, certificates and reports creates long queues and delayed onboarding.
One-size-fits-all questionnaires
Low-risk vendors get the same 300 questions as critical ones, wasting everybody's time.
Claims taken at face value
Answers are rarely compared with evidence, so gaps and contradictions slip through to approval.
How it works
From intake to decision in five steps.
- 1
Tier the supplier
Score data sensitivity, criticality and access to set inherent risk.
- 2
Send a sized questionnaire
Light, standard, enhanced or full — based on the tier.
- 3
Collect evidence
Suppliers answer and upload documents in their own portal.
- 4
AI checks claims
Each answer is compared with the documents, with citations.
- 5
Analyst decides
Reviewers confirm findings and approve, conditionally approve or reject.
Evidence-first AI
AI that shows its working — and knows when it can't tell.
The AI never approves a supplier and never sets the final risk score. It reads what was supplied, cites it, and flags what is missing.
Cited sources
Every verdict points to the document and page or section it relies on.
Says “insufficient evidence”
If the documents don't support a claim, it says so instead of guessing.
Contradictions and stale evidence
Flags answers that conflict with documents, and evidence past its freshness window.
Human sign-off
Findings are drafts until an analyst confirms them, with a full provenance trail.
Risk scoring
Deterministic, explainable scores.
Inherent and residual risk are calculated from fixed, visible rules — not by a language model. Every score lists the drivers behind it.
What moves the residual score
- Control effectiveness, as confirmed by reviewers
- Open critical and high findings
- Evidence gaps and stale or expired documents
- Contradictory evidence
- Overdue and validated remediation actions
Risk levels — shown with icon, label and score
- Critical75–100
- High50–74
- Medium25–49
- Low0–24
Supplier portal
A simple, separate space for your suppliers.
Answer and upload
Suppliers see only their assigned questionnaires and upload evidence securely.
Clarifications
Your analysts ask follow-up questions; suppliers reply in one place.
Internal stays internal
Suppliers never see your risk scores, methodology, internal notes or other suppliers.
Remediation
Turn findings into tracked actions.
Create an action from any material finding, assign an owner and due date, and require reviewer validation before it is closed.
Closing an action needs a reviewer note — recorded in the audit log.
Framework support
Map controls across the frameworks you use.
Available today
ISO/IEC 27001NIST CSF 2.0GDPRCustom frameworks
On the roadmap
NIS2DORACyber EssentialsPCI DSS
AssureFlow helps you assess suppliers against these frameworks. It does not certify compliance.
Security
Built for sensitive supplier evidence.
Tenant isolation
Every record is scoped to your organisation and enforced in the database.
Private evidence storage
Documents are never public; access uses short-lived signed links.
Role-based access
Admins, analysts, reviewers, executives and suppliers each see only what they need.
Immutable audit log
Views, downloads, decisions and changes are recorded — without document contents.
Server-side AI
AI runs only on the server. No keys in the browser.
Upload scanning
Files are checked for type, size, macros and embedded scripts before storage.
Session controls
Inactive sessions sign out automatically.
Rate limiting
Uploads, analysis and portal activity are throttled to limit abuse.
Pricing
Plans that scale with your supplier base.
Starter
For teams starting a structured programme.
Free
- Up to 5 suppliers
- Risk tiering & questionnaires
- Supplier portal
- Evidence vault
Professional
For growing GRC teams.
Contact us
- Unlimited assessments
- AI evidence analysis
- Remediation & approvals
- Executive reports
Enterprise
For complex, regulated organisations.
Custom
- Custom frameworks
- Multiple business units
- Advanced roles
- Dedicated support
FAQ
Common questions.
Run your first supplier assessment today.
Start free, or book a walkthrough with our team.