✦ TPRM · The layer between reviews

Third-party risk management software for the pages between reviews.

GRC runs the questionnaire. Cyber ratings scan the infrastructure. Visualping reads the pages your vendors publish.

stripe.com/legal/privacy · check #842
60s ago
ImportantBinary flag. Your rules per URL.
Sub-processor added: Amazon Web Services EU (eu-west-1).
AI summary
A new sub-processor, AWS EU (eu-west-1), was added to the vendor’s Data Sub-processors section. No existing sub-processors were removed. Section heading unchanged.
Routed to: #tprm-alerts, OneTrust webhookdiff +1 / -0
The three layers of TPRM

TPRM runs on three layers.

Most programs cover Layers 1 and 2. Layer 3 falls to whoever remembers to open the tab. We run it for you.

Three layers, one question: is this vendor still the vendor we assessed?

Layer 1

Questionnaires + GRC

Policies, questionnaires, contracts, attestations. The system of record for vendor relationships.

SOC 2 · SIG · CAIQ · DPA · risk register · board reporting
OneTrust · ProcessUnity · Venminder · Archer · MetricStream
Layer 2

Cyber ratings

Outside-in scans of vendor infrastructure. Patches, cert expiry, leaked credentials, port exposure.

External posture scoring · continuous · network-edge view
BitSight · SecurityScorecard · Black Kite · UpGuard
Layer 3

Documentation-surface monitoring

Continuous checks on the vendor pages your program lives on between annual reviews.

Sub-processors · trust centers · privacy · ToS · certifications · status
Visualping
Six surfaces we watch on every vendor

Six surfaces per critical vendor. Checked as often as you need.

We track the pages vendors publish. Every check returns two things: a binary IMPORTANT flag and a plain-English AI summary of what moved.

Sub-processor lists

Who handles customer data on the vendor’s behalf, and when that list changes. New region, new vendor, removed processor.

Trust centers

New certifications. Fresh audit reports. Removed attestations. What a vendor is willing to say in public.

Privacy and DPA pages

Policy edits. New data-handling terms. Jurisdiction swaps. Retention periods that quietly shrink or grow.

Terms of service and AUP

New clauses, liability shifts, usage restrictions, indemnity and warranty edits.

Certifications, SOC 2, ISO

Badge activity, report cycles, lapses between annual reviews, new scopes in an existing certification.

Status and incident pages

Publicly posted incidents, postmortems, degraded-service notices. Operational health, in the vendor’s own words.

Vendor pages don’t sit still

Vendor pages change more than a quarterly review picks up. We checked.

We watched a sample of vendor pages for 90 days. This is what moved.

67%

of sampled sub-processor pages saw a listed-party change within 90 days.

41%

of sampled privacy policies updated during the 90-day window.

62%

of sampled trust centers shipped a documentation change.

1:16

ratio of meaningful changes to automated checks across the vendor sample.

Sample, not total. Figures are from the sampled vendor pages we monitored during the window and should not be read as industry-wide prevalence.

Runs with the stack you already bought

Runs beside OneTrust, ProcessUnity, Venminder. Beside BitSight, SecurityScorecard, UpGuard. One layer they don’t cover.

Alerts land where the work already happens.

Layer 1 · GRC
Reopens the questionnaire when a page moves

Pipe a privacy-policy change into reassessment. Attach a trust-center diff to the vendor record. The calendar stops being the trigger.

OneTrustProcessUnityVenminderPrevalentArcherServiceNow VRM
Layer 2 · Cyber ratings
Reads what vendors write

Cyber rating tools grade vendor infrastructure from the outside. Visualping reads what your vendors write. Two different reads. Same program.

BitSightSecurityScorecardUpGuardPanoraysSecurityStudio
Alert routing
SlackMicrosoft TeamsEmailWebhookZapiern8nREST API
Plans

Start free. Scale when the vendor list grows.

Check frequency and vendor count set the tier. API on every plan. Free too. Alerts work from the first monitor you create.

Free
$0
Daily checks

Try the workflow, monitor a starter set of pages.

Personal
From $10/mo
Daily checks

Teams tracking ~50 vendor pages.

Business
From $100/mo
Hourly checks

Programs running 200+ vendor pages across teams.

API access

Up to five active keys per org, managed in the Developer tab. Push monitors. Pull change events. Write diffs back to OneTrust, ProcessUnity, or Venminder. Every plan.

FAQ

What TPRM teams ask us first.

What does Visualping monitor on a vendor?

The pages a vendor publishes. Sub-processor lists. Trust center. Privacy policy. DPA. ToS. AUP. Certification badges. SOC 2 status. ISO scope pages. Status and incident pages. Any public documentation URL you can paste into a browser.

How is this different from a cyber rating tool like BitSight or SecurityScorecard?

Cyber rating tools grade vendor infrastructure from the outside: patches, cert expiry, leaked credentials, port exposure. Visualping reads what vendors write. Both belong in a TPRM program. They answer different questions.

Does it replace OneTrust, ProcessUnity, or Venminder?

No. Those platforms run the questionnaire and the system of record. Visualping watches the vendor pages between reviews and routes alerts into the tool you already use. Slack, Teams, email, webhook, Zapier, n8n, or the API.

What’s the smallest plan that covers 50 vendor pages? 200?

50 pages fits Personal, daily checks. 200 fits Business, hourly. Pricing scales with check frequency and page count. See the pricing page for tiers and seat rules.

Is the API available on the Free plan?

Yes. API access is included on Free, Personal, and Business. Up to five active keys per organization, managed from the Developer tab. You can push monitors and pull change events from the first monitor you create.

Can I set custom importance rules per vendor URL?

Yes. The IMPORTANT flag is binary per change, and you set the rule that decides it for each URL. A sub-processor page might flag on any list edit; a status page might flag only on a new incident. The AI summary explains what moved in plain English either way.

How fast does a change turn into an alert?

Within seconds of the next scheduled check. Check frequency is configurable per URL, from hourly on Business down to daily on Personal. Alerts route to Slack, Teams, email, webhook, Zapier, n8n, and the REST API.

The TPRM playbook

Go deeper on every layer of the program.

Seven practitioner guides that sit under this landing page. Start with the primer or jump straight to the part of TPRM you run.

Put Layer 3 on autopilot.

One binary IMPORTANT flag. One plain-English AI summary. Every time a vendor page moves.

5 surfaces
per vendor
60 sec
from change to alert
All plans
include API access