Features

Everything vendor risk needs. Nothing it doesn't.

Vendors, assessments, questionnaires, contracts, tasks, and shadow IT, all in one calm workspace, with multi-tenant isolation baked in.

Vendor register

Track every vendor across every client portfolio

Stop maintaining a spreadsheet per client. RiskBee gives each client a dedicated, searchable vendor register - and you can jump between Client A and Client B without losing context. Categories, criticality, and residual risk stay clear across the whole portfolio.

  • Unlimited vendors per client, clearly tagged by owner and category
  • Portfolio view shows which clients share the same risky vendor
  • Bulk CSV import and accounting-system sync for faster onboarding

How it works: Vendors move through a lifecycle - discovered, provisionally approved, approved, archived - and a record completeness score tells you exactly which fields, documents or answers are still missing before approval.

Vendors
Search 214 vendors…
Acme Cloud
SaaS
Low
Northwind Payments
Fintech
Med
Contoso Analytics
Data
High
Globex CDN
Infra
Low
Initech HR
People
Med
Umbrella Logistics
Supply chain
High
168
Approved
31
Provisional
12
Discovered
3
Declined
Risk assessments

Run assessments for Client A, then Client B, then the rest

Deploy standardized questionnaires across your entire book of business. AI drafts answers from each client's uploaded certifications and previous assessments, so your analysts review rather than retype - and you deliver consistent quality at scale.

  • AI auto-fill from SOC 2, ISO 27001, DPA, and past responses
  • Weighted scoring across security, privacy, and operational controls
  • One-click client-ready PDF reports for boards and QBRs

How it works: Review cadence is set by inherent risk tier, so critical vendors come back annually and low-impact vendors do not clog the queue. The due register and task board stay in sync, and an assessment logged anywhere clears the matching task automatically.

Risk assessment · Acme Cloud
Q1
Yes - SOC 2 Type II
Q2
AES-256 at rest
Q3
Reviewed quarterly
Q4
MFA enforced for all staff
Q5
Sub-processors published
Score
87
Low risk
Security92
Privacy84
Resilience79
5 of 24 questions shown · evidence attachedNext review 12 Aug 2027
Questionnaire builder

Build one template, deploy across every client engagement

Create a master question library for your MSSP methodology. SOC 2, ISO 27001, GDPR, and custom frameworks become reusable blocks you can drop into any client questionnaire - no copy-pasting between engagements.

  • Curated library mapped to SOC 2, ISO, GDPR, HIPAA, and more
  • Conditional logic and section scoring per client requirement
  • White-labelled sends under each client’s brand, not yours

How it works: Questions can demand evidence, not just a tick: a claimed certification asks for the certificate, and RiskBee inspects the upload to confirm the document is actually what was requested.

Questionnaire builder
Library
SOC 2
GDPR
Encryption
Incident response
Canvas
Do you have SOC 2 Type II?
How is data encrypted at rest?
What is your IR plan?
Contracts

Manage renewals and SLAs across every client contract

Upload each client's vendor contracts once and let RiskBee extract the clauses that matter. Auto-renewal alerts, expiry tracking, and version history give you a single view of contractual obligations across the portfolio.

  • AI clause extraction for termination, liability, and data handling
  • Expiry reminders scoped to client and vendor owner
  • Side-by-side version history and contract renewal timeline

How it works: Terms of service, DPAs and order forms attach to the master agreement as companion documents, so a renewal review shows the whole paper trail - including contracts resold through an MSSP.

MSA · Acme Cloud
Master service agreement
42d to renewal
Termination for convenience - 60 days notice
Data processing: EU + US regions
Auto-renewal unless notified 90 days prior
Liability capped at 12 months of fees
Breach notification within 72 hours
$48k
Annual value
Annual
Billing
90 days
Notice window
ToS + DPA
Companion docs
Renewal runwayNotice due in 12 days

Bring your first client across this afternoon

Import a vendor list, connect the client's identity provider, and have a real risk picture before your next check-in call.

Tasks

One board for every piece of remediation work

Follow-ups, evidence chases, renewal reviews and overdue assessments all land on a single board, grouped by category and assigned to the analyst, client contact or vendor owner who has to move them.

  • Tasks created automatically when something needs doing - and closed automatically when it gets done
  • Categories for assessments, evidence, contracts and renewals
  • Due dates with escalation, plus AI guidance that explains the fix in plain English

How it works: Open a task and RiskBee drops you on the exact screen with a guidance bar summarising what is missing. Do the work anywhere in the app and the task resolves itself - no manual ticking off.

Tasks
10 open · 4 due this week
2 overdueAuto-created
To do
Request SOC 2 · Acme
Chase DPA · Loom
Verify ISO cert · Globex
In review
Legal review MSA
Renewal brief · Contoso
Adverse media triage
Done
Onboard Acme
Sign DPA · Notion
Approve Slack
Close Q3 review
AI guidance: “Upload Acme’s SOC 2 to close 3 linked tasks.”
Evidence

A secure evidence vault for every client

Store all the certifications and policies you collect on your clients' behalf in isolated, versioned vaults. Documents are tagged by framework, expire automatically, and can be requested from vendors without giving them a login.

  • Encrypted storage with strict per-client isolation
  • Auto-expiry alerts when certifications lapse
  • Vendor upload links so evidence collection keeps moving

How it works: The trust centre scanner reads a vendor's public trust page and attaches what genuinely exists. Links are probed before they are recorded, so dead or invented URLs never make it into an audit file.

Documents · Acme Cloud
Compliance
SOC2-Type-II-2025.pdf
Verified
DPA-signed.pdf
Verified
ISO-27001-cert.pdf
Verified
Pen-test-report.pdf
Expires 60d
Cyber-insurance-COI.pdf
Verified
Sub-processor-list.pdf
New
92%
Evidence coverage
1
Expiring < 90d
6 / 6
Auto-classified
Shadow IT

Scan a client’s IdP and catch unapproved vendors instantly

Connect a client’s Google Workspace or Microsoft Entra ID and RiskBee scans OAuth grants and app assignments. Unapproved SaaS - the tools employees signed up for without procurement - surface automatically so you can assess them before they become an incident.

  • Scheduled weekly scans of Google Workspace and Microsoft Entra ID
  • Auto-flag apps that are missing from the client’s approved register
  • One-click promote an unapproved app to a full risk assessment

How it works: Every discovered app arrives as a real vendor record with the sign-in evidence attached, so triage is one decision - approve, assess or decline - rather than a research project.

Shadow IT · IdP scan
Scanning Microsoft Entra ID
contoso-health.onmicrosoft.com · OAuth grants
Complete
5 apps discovered
3 unapproved
F
Figma
42 users
Unapproved
L
Loom
18 users
Unapproved
N
Notion
61 users
Approved
C
ChatGPT
87 users
Unapproved
S
Slack
124 users
Approved
User compliance

See exactly who is still signing in to apps you declined

Discovery tells you which apps exist. User compliance tells you who is using them. Every person found by an identity provider scan gets a profile showing every app they touch, with violations and unreviewed apps pinned to the top.

  • People directory built from real sign-in data, not a survey
  • Violations for declined or archived apps, warnings for apps still awaiting review
  • Branded nudge email to the individual, with a 30-day cooldown so nobody gets spammed
  • Auto-notify after each scan, off by default until the client turns it on

How it works: Decline a vendor on the board and its users become violations immediately. Notices are logged per person per app, so you can prove the client was told - and when.

People directory · Contoso Health
3 people · 9 app grants
1 violation
S
Sarah Chen
Figma, Loom, ChatGPT
1 Violation
M
Mike Torres
Notion, ChatGPT (pending review)
1 Warning
A
Aisha Patel
Slack, Notion, Figma, Loom
Clear
Nudge Sarah about Figma · 30-day cooldown

Shadow IT and user compliance, in one pass

One scan finds the unapproved apps and the people using them - then chases both without your analysts writing a single email.

Modern slavery

Triage modern slavery risk without adding a single spreadsheet

RiskBee classifies every vendor's industry, assigns an inherent modern slavery risk tier, and routes them automatically: Tier 1 gets a deep-dive questionnaire, Tier 2 gets a lite attestation, Tier 3 clears without touching your analysts. Adverse media scanning watches for reported modern slavery issues and the outcome feeds straight into the vendor health score.

  • Automatic tier assignment from a built-in industry risk taxonomy
  • Deep-dive or lite questionnaires triggered by inherent tier, not guesswork
  • AI-triaged adverse media scanning for reported modern slavery and human rights issues
  • Score contribution visible on the vendor record, ready for audit evidence

How it works: Software vendors with no physical supply chain clear automatically, so the workload lands where the risk actually sits - logistics, manufacturing, construction, cleaning and labour hire.

Modern slavery triage
Industry taxonomy
auto-classified
Garment manufacturing
Tier 1 inherent risk
Deep dive
Third-party logistics
Tier 2 inherent risk
Lite attestation
SaaS platform
Tier 3 inherent risk
Cleared
Adverse media signal2 findings triaged
4th-party risk

See who your vendors depend on, before an outage tells you

RiskBee reads DPAs and trust centre pages to extract each vendor's sub-processors, then builds a shared register across the whole portfolio. When many vendors sit on the same underlying provider, concentration risk surfaces on the dashboard, and blast-radius search answers 'who is exposed if this provider goes down' in seconds.

  • AI sub-processor extraction from DPAs and trust centre pages
  • Concentration risk across your entire client portfolio, not one vendor at a time
  • Blast-radius lookup for incident response and client comms
  • External security grades and adverse media carried through to 4th parties

How it works: Sub-processors are stored as their own register, so one provider appearing behind eleven vendors shows up once - with all eleven exposures listed underneath it.

Supply chain map
Vendor
AWS eu-west-1
A
Stripe Payments
A-
Zendesk Support
C
Concentration risk7 vendors on AWS eu-west-1
Blast radius: who uses Zendesk?
Built for MSSPs

Multi-tenant by design, built for your operating model

RiskBee is structured around clients, not contacts. Each client workspace keeps its vendors, assessments, documents, and users isolated - while you retain portfolio-level visibility and can switch between clients in a single keystroke.

  • Fast client switcher with search - jump from Client A to Client B instantly
  • Per-client branding and white-labelled vendor communications
  • Portfolio dashboard for risk posture across your entire client base

How it works: Isolation is enforced in the database, not just the interface. Your team sees the portfolio; each client only ever sees their own workspace.

MSP portfolio
Switch client
Northwind Bank
42 vendors
Low
Contoso Health
118 vendors
Med
Globex Retail
27 vendors
Low
Initech Legal
63 vendors
High

Ready to run TPRM across your client portfolio?

Start with one client, add the rest as you grow. Have your first assessment out the door in under an hour.