Skip to content
03Module · Vendor & supply-chain risk

Third parties become first-party visibility.

Vendors are linked directly to the critical services they support. When a vendor is in the blast radius, your resilience plan, impact assessment and incident playbooks already know.

01Capabilities

From vendor list to vendor system.

01
Vendor register

Every vendor linked to the critical services it supports, with criticality, data-access level and contractual SLAs.

02
Concentration analysis

See where one vendor, one cloud region or one country is the single point of failure across your services.

03
Geopolitical and country risk

Vendor and hosting locations scored against a maintained country-risk index, with thresholds you can tune.

04
Attestations and reviews

Structured control attestations per vendor, with reminders when evidence expires or a review falls due.

05
Regulatory alignment

Vendor attestation items drawn from DORA, NIS2 and PRA SS1/21 third-party expectations.

06
Incident linkage

When a vendor is in the blast radius of an incident, its services, owners and SLAs are one click away in the command room.

— next step

See AirTee in your environment.

We'll model one of your real scenarios live.