Every third party gets a branded, isolated portal to complete assessments, upload evidence and sign off — with a tamper-evident record of everything they submitted, when, and to whom.
The vendor contact receives a fully branded email — sent from your own domain when configured — with a magic link. No account to create, no friction.
On activation they land on a dashboard showing only their assigned assessments, uploaded documents and message threads. They can never see another vendor's data.
Questionnaires render with section navigation, a live progress bar, conditional branching and inline file upload per question — designed to be finished, not abandoned.
SOC 2 reports, ISO certificates, pen-test results and BCPs are uploaded directly in the portal, timestamped and version-tracked as evidence.
At submission the contact provides a legally significant attestation that responses are accurate. Signed responses become immutable evidence.
All communication with your risk team happens inside the portal — every message timestamped, attributed and permanently associated with the record.
The vendor session cookie is cryptographically segregated from the platform session. A vendor contact cannot escalate to any internal view.
Assessment data is filtered by the responder's identity at the service layer — not just hidden in the UI. The database query itself enforces the boundary.
Invitation links expire after five days. Expired tokens are rejected with no information leaked about the associated record.
Once a vendor submits and signs, answers are locked. Reviewers add notes and findings but can never alter a vendor's response.
Vendors on one tenant cannot infer the existence of another — hostname routing resolves the tenant before any data is loaded.
You decide whether vendor contacts must be explicitly invited or may self-register, per your programme's needs.
The Vendor Portal is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.