How Vetrail works

The mechanics, in the order they happen. If you would rather see it than read it, start free or open the demo.

Vendor risk: Runs itself

Assessments go out when they're due, and a silent vendor gets chased until they answer. You hear from Vetrail when something needs a decision. A quiet month is it working.

Day −7 First reminder Day −3 Reminder Due date Reminder Day +7 Reminder Day +14 Final reminder Escalate One digest to a human

Default rungs; each workspace sets its own. Escalation also fires on a Critical rating, a rating that drops, or 30 days overdue. Full mechanics →

Internal risk: say it out loud, get a draft

Talk to Blaze like you would to a risk manager, or type it. Either way a full draft comes back - title, rating, suggested controls - for you to review. Nothing saves until you approve it.

Identify From the library or written from scratch Inherent rating Before any controls - only you can judge it Controls What actually mitigates it today, if anything Residual rating What's left after the controls above Treat Solve, accept, or transfer - owner + date

Same Low/Medium/High/Critical language as the vendor side, so the two registers read as one system. Start from the library, a blank form, or a conversation with Blaze. Full mechanics →

A register that tiers itself

Say what a vendor touches and what you spend. Vetrail sets the tier, and the tier decides how deep the assessment goes and how often it repeats.

Talk to Blaze

Describe a risk out loud. Blaze asks what it needs, then writes the entry - title, category, rating, suggested controls - for you to approve.

Questionnaires vendors actually finish

A link, no account to create. 24 controls or 54, your call. 60+ common vendors arrive pre-researched from their own public disclosures.

A risk library to start from

Researched risks across strategic, operational, financial, compliance and reputational. Your industry pre-checks the likely ones; nothing is ever hidden.

Audit-ready by default

Every rating computed the same way, with a critical failure capping it however strong the rest looks. Export either register as CSV or PDF.

Your data stays yours

A full JSON export is always one click away. Encrypted off-site copies run on a 1-hour recovery objective, integrity-checked both ways.

Built for the moment it matters

A customer security review

Procurement asks how you manage third-party risk. You send a current register instead of asking for two weeks.

SOC 2 or ISO 27001 prep

Vendor management and risk assessment are both control domains. Vetrail produces evidence for each, continuously - not the week before fieldwork.

Investor diligence

Asked what happens if a critical supplier fails, or what your own operational risks are, you have two rated registers to point at.

How the posture score is worked out

Two dials, each out of 100 - one for your own operational risk, one for your vendors. A number you are asked to trust should be a number you can reason about, so here is how it behaves.

1

It is not an average

Averaging lets good news hide bad news. Twenty healthy vendors would bury the one that holds your customer data and has not answered in a year - which is precisely the failure a register exists to prevent. The worst thing you have is what moves the number most, and it keeps moving it until you deal with it.

2

Severity and tier both count

A Critical finding weighs more than a High one, and the same finding weighs more on a tier-1 vendor handling customer data than on a tier-3 one that does not. Tier is derived from what a vendor touches, how much you depend on it and what you spend - so the score follows your real exposure rather than the length of your list.

3

Unknown counts against you

A vendor nobody has assessed is not treated as healthy. Not knowing is a position, and it is not a good one. The dials say how much of the score is unknown rather than quietly scoring it as fine - the single most common way a risk dashboard flatters the person reading it.

4

Only the register feeds it

Ratings, tiers, control-domain results, assessment and treatment status, review dates, and overdue action items. That is the whole input list. Nothing about how you use the product, what you pay, or how you behave touches the number, and nothing is inferred about you from anywhere else.

Both dials name what is pulling them, so the score is never the whole answer - the list underneath it is. The exact weighting is not published: it is the part we keep, and publishing it would let a score be gamed rather than earned. Everything that decides the direction of the number is above.

Start where it's easiest

Free for up to 15 vendors and 5 people, with the whole risk register included. No credit card, no sales call.