Platform / Vendor Risk

Third-party risk, without the chasing.

Send a security questionnaire your suppliers actually finish - one link, completed in the browser, no account to create. Assura assesses the answers into a clear risk rating with the specific concerns spelled out, and keeps the register current.

A short call about your organisation, then a full demo if it fits - no obligation.

How it runs

From "who are they?" to a rating you can defend.

01

Add the supplier

Name them, note what they handle for you - staff data, production infrastructure, customer records - and they join the register.

02

Send the link

The supplier gets a security questionnaire that opens in the browser. No portal, no account creation, nothing to install - so it actually gets finished.

03

They answer, Assura assesses

The moment answers arrive, Assura assesses them into a clear risk rating - with the specific concerns cited from their own responses, not a bare traffic light.

04

Track and revisit

The register keeps statuses current - awaiting, complete, assessed - and you can re-send when contracts renew or something material changes.

The questionnaire

Questionnaires suppliers actually finish.

Third-party risk usually dies at the supplier's side: a portal login they won't create, a spreadsheet they won't open. Assura's questionnaire is one tokenised link that opens in the browser and reads in plain English - the friction is gone, so the answers come back.

  • One public link per supplier - no account, no portal, no install
  • Plain-English questions a non-security contact can answer
  • Status tracked in your register from sent to complete
Questionnaire sent Opened in browser
No login wall Completed
The assessment

A rating you can defend.

A traffic light on its own is a guess with a colour. Assura reads the supplier's answers and produces a risk rating with the reasoning attached - which answers drove it, and exactly what concerned us - so when someone asks "why is this vendor high risk?", the answer is written down.

  • Risk rating derived from their actual answers, not a checkbox count
  • Specific concerns cited - shared credentials, missing MFA, no offboarding
  • You review the assessment; your judgement has the final word
Answers received High risk
Concern No MFA on admin accounts
Concern Shared credentials in use
The register

A register, not a folder of PDFs.

Supplier assessments are worth little scattered across inboxes. Assura keeps one register - who they are, what they handle, when they were last assessed, and what it found - sitting beside the rest of your risk picture, where it belongs.

  • Every supplier's status and rating in one view
  • High-risk suppliers stand beside your other risks, not in a silo
  • Re-send and re-assess when contracts renew or scope changes
8 suppliers tracked 6 assessed
1 high risk On the board's radar
Questions

Asked and answered.

Do our suppliers need an Assura account?

No. They get one tokenised link that opens the questionnaire in the browser - nothing to sign up for, nothing to install. That's most of why the answers actually come back.

What do we get back when they finish?

A clear risk rating, the specific concerns that drove it - cited from their own answers - and the full response set to read if you want the detail.

Can we override the rating?

Yes. The assessment is a considered first opinion, not a verdict - review it, adjust it, and your judgement has the final word in the register.

How do we keep supplier assessments current?

The register tracks every supplier's status, and you can re-send the questionnaire whenever a contract renews or something material changes - the new answers are assessed the same way.

Get started

Know who you're trusting.

Book a demo and we'll send a sample questionnaire so you can see exactly what your suppliers would.

Prefer to pick a time? Book a 15-minute intro · or leave your email and we'll come to you.