Skip to content
Second Key Security

Third-Party Risk Management

Vendor security reports read, judged against your requirements, and followed up.

Cadence
Ongoing, by vendor tier
Pricing
Scoped to your environment after the assessment.
Family
Governance and risk

The problem

Vendor SOC 2 reports and questionnaires arrive as long PDFs nobody reads. Exceptions and the controls you are expected to run go unnoticed until an auditor asks.

What you get

How it works

  1. Step 1: Share your vendor list

    From your contracts, or from the apps in your identity provider.

  2. Step 2: Agents read the reports

    SOC 2 reports and questionnaires summarized against your requirements.

  3. Step 3: An expert judges the risk

    Exceptions weighed, follow-ups recommended.

  4. Step 4: You approve any change

    Requests to vendors go out only with your approval. Every approval is logged.

Access we need

  • Vendor reports and questionnaires you already hold
  • Read-only access to the app list in your identity provider, if you want it included

What we never do

  • We never contact a vendor without your approval.
  • We never keep copies of vendor reports.

The full access model is on the security and trust page.

Questions about Third-Party Risk Management?

Tell us what you run and what you need, and we will reply with next steps.