Trevos · Third-Party Risk Management

Every third party, in view.
Every risk, in money

Trevos finds, rates, assesses and monitors every vendor, supplier and service provider you depend on, then tells you which ones could cost you the most, in the currency your board already reports in.

The everyday problem

Most tools that say TPRM send a questionnaire,
track a contract, and stop there

You don't have a real inventory

Vendors arrive through procurement, through a corporate card, through a team that just needed something by Friday. The list nobody maintains is the list you get audited on.

Everyone gets the same questionnaire

Without tiering, the payroll processor holding every employee record gets the same 300 questions as the office plant supplier, so the answers that matter arrive late and unread.

Nobody can answer “how much”

A board asks what third-party risk is worth and gets a colour, a letter grade, or a score out of a hundred. None of those go in a budget conversation.

Start here

Grade a vendor before you ask them anything

A passive, outside-in scanner rates any vendor's external security posture across 13 signal dimensions: DNS, TLS, headers, subdomains, exposed services, leaked credentials, threat intelligence and more. No consent, no onboarding, no agent: the same legal basis the established security-ratings vendors operate on. It is the fastest way to know who deserves the long questionnaire.

Trevos: an outside-in scan detail showing grade, score, category contributions and findings
The full lifecycle

Eight stages. Most tools stop at four

Vendor risk does not end when the contract is signed. That is roughly where it starts. Trevos covers the whole arc, including the four stages almost nobody else does.

  1. 01

    Inventory

    One source of truth for every third party, owner, service, data access, contract status, geography, tier, last assessed. Shadow-IT and fourth-party discovery included.

  2. 02

    Tiering

    Weighted scoring on data access, financial impact, operational dependency, regulatory sensitivity and geography. This is the load-bearing decision: it sets assessment depth, monitoring cadence and contract rigour.

  3. 03

    Assessment

    Right-sized questionnaires per tier, SIG-Lite style, CAIQ, and a 14-pack enterprise catalogue. Vendor portal, evidence upload, AI evidence review, inherent versus residual risk, and a clear opinion: approve, conditional, escalate or reject.

  4. 04

    Contracting

    An eight-clause must-have checklist with presence tracking, AI clause extraction, an inline PDF reader, and remediation tied back to the findings that caused it.

  5. 05

    Monitoring

    Continuous and multi-signal. A passive outside-in scanner rates external posture, alongside financial-health and adverse-media signals, trigger, escalation, reassessment.

  6. 06

    Issues and incidents

    An issue tracker with ID, severity, owner, due date and evidence-to-close, an escalation matrix, and a 24/48/72-hour vendor incident playbook.

  7. 07

    Exit readiness

    Per-critical-vendor exit plans: alternate providers, data retrieval, transition timeline, dependencies and comms, written before you need them, not during.

  8. 08

    Reporting

    A one-page risk summary, a board dashboard, a board-ready PDF in one click, and the Red-Flag Translator that turns technical findings into business language.

Stages 05–08 are where most vendor-risk programmes go quiet, and where the incidents that reach a board actually happen.

Risk in money

A number your CFO
already knows how to use

Trevos models vendor risk with probabilistic loss modelling, Monte Carlo simulation producing loss-exceedance curves, sized to your organisation. It answers how much and which vendors, not a colour or a score out of a hundred. Anchored to NIST SP 800-30, NIST IR 8286 and ISO 27005, and reported in the currency you run the business in.

Portfolio and concentration risk

The part almost nobody models. Trevos looks at correlated loss, what happens to the whole portfolio when a dozen vendors quietly depend on the same underlying provider, so a single outage stops being a dozen unrelated line items.

Fourth and Nth parties

When a provider two hops away has a breach, Trevos fans the impact out to every vendor that depends on it and moves the money accordingly. Your supply chain rarely stops at the people you have contracts with.

Trevos: the board risk overview, with exposure index, modelled loss, engagement pipeline and assessment coverage
Trevos AI

The reading, done for you

Autonomous where it should be, human-in-the-loop where it matters. Trevos AI does the work that makes vendor risk unbearable at scale, and hands a human the decision.

  • Reads SOC 2, ISO and pentest reports and extracts what they actually evidence
  • Routes each questionnaire to the right tier and the right owner
  • Drafts the risk opinion for a human to accept, edit or reject
  • Flags contradictions across a vendor's own answers
  • Translates findings into language a board can act on

Nothing fires on its own. A risk opinion is drafted, not issued; a contradiction is flagged, not resolved. Trevos is explicit about the difference between what it knows and what you should check, and says so on the record rather than presenting a guess as a finding.

Coverage

One engine. Framework packs on top

Trevos is industry- and jurisdiction-agnostic by design: a principles-based engine with overlay packs you switch on for wherever you operate and whatever you are held to. It maps to what an auditor already tested, so vendors are not re-asked what a SOC 2 already evidences.

501
vendors pre-profiled, with verified legal entities
13
external signal dimensions in the passive scanner
625
questions across 14 assessment packs, tier-matched
Cross-industry core
SOC 2ISO/IEC 27001ISO/IEC 27036NIST CSF 2.0NIST SP 800-161PCI DSS v4.0
Overlay packs, switch on what applies
GDPRHIPAADORAIndia RBI 2025India DPDP ActSEBI CSCRF
Trevos: the vendor catalogue, pre-profiled with outside-in cyber ratings, adoptable in one click
Also from CTRL 18

The rest of the house

Bring us your vendor list.
We'll grade it

In one demo we will scan real vendors from your own portfolio, tier them, and show you what the top of that list is worth in money.