Always-on vendor-risk monitoring built for fintech compliance.
Vendraft watches your third-party stack — SaaS, payments, KYC, cloud — 24 hours a day. A team of AI agents ingests SOC deltas, status-page incidents, breach disclosures, OFAC hits, and live API health signals, and folds every finding into a fintech-shaped risk register that maps cleanly to DORA, FCA/PRA Operational Resilience, and US Treasury concentration guidance.
vendraft · live-vendor-feed
Watched
347
Open
12
Critical
2
Plaid
KYC · bank linking
Healthy12s agoStripe Connect
Payments · acquiring
SLA dipped 2.1%4m agoOnfido
KYC · identity
Healthy38s agoChainalysis
Sanctions · blockchain
OFAC exposure digest11m agoAWS us-east-1
Cloud · infra
Healthy1m agoSumsub
KYC · AML
Re-ingestingqueuedAdyen
Payments · acquiring
Status-page incidentjust nowPersona
KYC · identity
Healthy22s ago
Illustrative view. Every row is a real third party in your stack.
Capabilities
Three modules. One register your supervisor can open.
Most vendor-risk tools are quarterly questionnaires. Vendraft is a live system. Each module feeds the same register, so a CRO, CISO, or DORA accountable manager sees the same picture at every escalation level.
Watch. Ingest. Score.
AI agents scan the open web for SOC and ISO deltas, drain status-page feeds every minute, scrape breach disclosures as they surface, pull OFAC and EU sanctions hits, and probe the public API health of every third party in your stack. A new SOC report appears at 03:14 UTC — the register updates before your morning stand-up.
<60s
Status-page to alert
24/7
Agent coverage
8
Signal channels
99.9%
Ingest Uptime
Coverage
Every signal your register should hear.
Vendraft does not wait for questionnaires. Agents across eight channels watch your vendors continuously, and the data feeds a fintech-specific scoring layer you will not find in a generic GRC platform.
Ingest channels
SOC 2 & ISO 27001 deltas
streaming
Status-page outage feeds
streaming
Breach & disclosure press
streaming
OFAC, SDN & EU sanctions
streaming
Live API health probes
streaming
Regulator bulletins & TPN
streaming
Scoring layer
Three scores generic TPRM tools do not compute.
Payments uptime
Composite of status-page incidents, latency budget, and concentration across acquirers.
KYC provider stability
Coverage gaps, document-fraud rate trends, and substitution readiness across your stack.
Sanctions-feed integrity
Lag between sanctioning and feed arrival across all your screening and blockchain providers.
Pricing
Per-vendor pricing. Scales with the third parties you actually manage.
Aligned with the per-vendor fee model common across TPRM. Every tier ships with the weekly audit-grade report, regulator mapping, and agent governance layer.
Enterprise
Regulated
Unlimited · on-prem connectors, SSO, SLA
Request enterprise briefPer-vendor pricing after the included quota · annual contracts available
Weekly deliverable
What lands in the CRO's inbox every Friday.
Not a status update. An artefact you can hand to a supervisor without last-minute firefighting — signed PDF + machine-readable JSON.
- Register snapshot with criticality and concentration
- Every finding since last report, severity-tagged
- Fourth-party exposure graph refreshed
- Framework coverage statement per regulator
- Pre-answered questionnaire for top supervisor asks
Vendor-risk report · Week 43, 2026
Critical findings (open)
Adyen
Status-page incident · elevated
Stripe Connect
SLA dipped to 99.62%
DORA
100%
FCA/PRA
98%
US Treasury
96%
Questions buyers ask
FAQ
Anything left open? Email vendraft-8@polsia.app and a risk engineer will reply the same business day.
Ready when you are
Stop firefighting the next supervisor question.
A 30-minute walkthrough on your vendor list. We'll show the register populated with real findings, demonstrate the Friday report, and map every output to your live framework coverage statement.
Direct line · vendraft-8@polsia.app