Pre-screen vendors with confidence in minutes, not weeks.
Built for procurement, security, compliance, and operations teams without a full TPRM stack. VendorLens checks a vendor's public evidence: security certifications, registries, breaches, sanctions, and cost. Then it hands you a plain-language read and a ready-to-send RFP, grounded in NIST and ISO standards. It triages the shortlist; it does not replace your formal risk assessment.
From "who do I even look at?" to a confident shortlist.
Three steps. No spreadsheets, no scraping, no waiting on questionnaires.
Tell us what you're sourcing
Describe the product or service, or paste 1 to 5 vendors you're weighing. VendorLens infers the industry and the certifications that actually matter for it.
We gather the public evidence
Trust centers, security pages, authoritative registries, breach databases, and pricing, all read from each vendor's own public footprint and verified against the issuing sources.
Get a clear read
A likelihood-to-clear score with a confidence level, a side-by-side comparison, a relative cost indicator, a NIST-aligned RFP for the vendor, and a ready-to-forward request to hand your own procurement or sourcing team.
Built for the person who has to decide.
Plain language for business units, real rigor underneath for security and procurement.
Deep trust-center detection
Reads modern JavaScript trust portals and bot-walled security pages most tools miss, and surfaces the certs that are actually published.
Two numbers, never one
Likelihood to clear a review and how much public evidence backs it, so "not found" never gets mistaken for "risky."
Industry-aware certifications
NAICS-anchored across 20 industries. It checks for FDA, FedRAMP, ISO 13485, PCI DSS and more, depending on what you're buying.
Adverse screening
Known breaches, lawsuits, and recalls flagged from authoritative records, framed to verify and never auto-judged.
Relative cost indicator
A clear cost rating from $ to $$$$, so you can weigh budget alongside posture instead of chasing "contact sales" pages.
Ready-to-send RFP
A NIST SP 800-161-aligned RFP with the right required certs, the specific questions to ask, and a sources appendix, generated for you.
Hand off to procurement
Picked a vendor? Forward a ready-made request to your sourcing or procurement team to start their process, as an email, Word doc, CSV, or JSON that drops into the common procurement and GRC tools.
Five moments it pays for itself.
New-vendor intake
A business unit wants a new tool. Triage it in a minute: real company, published certs, red flags, and exactly which documents to request before it goes any further.
Shortlists & runoffs
Weighing several suppliers? Screen them side by side, see who leads and why, and export a runoff summary. Kill the weak candidates before anyone spends due-diligence hours on them.
Annual-review prep
Re-screen your existing vendors before renewal: certifications lapsed, new breaches or sanctions hits, anything that changed since you signed.
M&A and partner screening
A fast, sourced first pass on a target's or partner's public posture: legitimacy, ownership, litigation, and adverse records, before deeper diligence begins.
Low-risk routing
Not every vendor needs the full questionnaire. The inherent-risk tier helps you route low-risk purchases through a lighter path and save the heavy review for the vendors that warrant it.
The math is simple.
One screen checks 30+ authoritative sources in about a minute. Done by hand, that first pass takes an analyst 30 to 60 minutes per vendor. At 20 vendors a month, that is 10 to 20 analyst-hours back every month, and the weak candidates never reach your formal review at all.
Anyone can ask a chatbot. VendorLens shows its receipts.
Chatbot research can be outdated or invented, and there is no way to tell which. Every VendorLens fact is checked against the issuing registry or the vendor's own public pages, and the sourced ones link to exactly where they came from, so anyone can verify them. No hallucinated SOC 2s.
Trustworthy by design, because we show our work.
VendorLens is an informational pre-screen from public data, nothing more, and every signal carries an evidence grade you can audit.
- ✓Three-state grading. Every finding is Verified, Claimed, or Not found, and "not found" is never scored as insecure.
- ✓Grounded in standards. Scoring is gauged against NIST SP 800-161, ISO/IEC, and the OWASP LLM Top 10, not opaque vendor magic.
- ✓Authoritative verification. Certifications are confirmed against issuing registries (FedRAMP, CSA STAR, openFDA), with the source cited.
- ✓Low-risk by construction. We read each vendor's own public pages plus public registries, with no third-party-ToS scraping.
Start free. Scale when it earns its place.
Far below enterprise risk-rating tools, and priced so an analyst can expense it without a procurement cycle.
Free
- ✓3 full pre-screens every month
- ✓All screening dimensions
- ✓Inherent-risk tiering
- ✓Cost & adverse checks
Pro
- ✓Unlimited pre-screens
- ✓Watchlist monitoring + change alerts
- ✓RFP + procurement-handoff generation & export
- ✓Saved history & re-screens
Small team
- ✓Everything in Pro, for up to 5 people
- ✓Shared saved history across the team
- ✓One simple bill, no per-seat math
- ✓Seat limit enforced, swap people any time
Team
- ✓Everything in Pro, for everyone at your work domain
- ✓API access, pull screens into your GRC / procurement system
- ✓No per-seat math, no invites to manage
- ✓$2,990/yr on annual (2 months free), invoice & PO friendly
Enterprise (over 100 employees, SSO, DPA, SLA, connectors): from $4,900/yr. Talk to us and we'll set you up.
Good questions, straight answers.
Is this a security assessment or audit?
Where does the evidence come from?
How accurate is the cost indicator?
What if a vendor publishes very little?
Do I need an account?
Stop guessing which vendors to vet.
Run 3 pre-screens free every month and see the shortlist, and the questions to ask, in about a minute.
Try VendorLens free →