Vendor due-diligence triage from public evidence

Pre-screen vendors with confidence in minutes, not weeks.

Built for procurement, security, compliance, and operations teams without a full TPRM stack. VendorLens checks a vendor's public evidence: security certifications, registries, breaches, sanctions, and cost. Then it hands you a plain-language read and a ready-to-send RFP, grounded in NIST and ISO standards. It triages the shortlist; it does not replace your formal risk assessment.

3 free pre-screens every month · no credit card · results in about a minute · how it works
Verifies against authoritative sources FedRAMPSEC EDGARSAM.govCSA STARFINRAopenFDAEPAHave I Been PwnedNIST SP 800-161
Where it fits in your process 1 · Enter a vendor name, website, or just the need 2 · Evidence collected from 30+ public sources 3 · Risk flags + source links in plain language 4 · Export or route to your formal due diligence
How it works

From "who do I even look at?" to a confident shortlist.

Three steps. No spreadsheets, no scraping, no waiting on questionnaires.

1

Tell us what you're sourcing

Describe the product or service, or paste 1 to 5 vendors you're weighing. VendorLens infers the industry and the certifications that actually matter for it.

2

We gather the public evidence

Trust centers, security pages, authoritative registries, breach databases, and pricing, all read from each vendor's own public footprint and verified against the issuing sources.

3

Get a clear read

A likelihood-to-clear score with a confidence level, a side-by-side comparison, a relative cost indicator, a NIST-aligned RFP for the vendor, and a ready-to-forward request to hand your own procurement or sourcing team.

What you get

Built for the person who has to decide.

Plain language for business units, real rigor underneath for security and procurement.

🛡️

Deep trust-center detection

Reads modern JavaScript trust portals and bot-walled security pages most tools miss, and surfaces the certs that are actually published.

⚖️

Two numbers, never one

Likelihood to clear a review and how much public evidence backs it, so "not found" never gets mistaken for "risky."

🏷️

Industry-aware certifications

NAICS-anchored across 20 industries. It checks for FDA, FedRAMP, ISO 13485, PCI DSS and more, depending on what you're buying.

🚩

Adverse screening

Known breaches, lawsuits, and recalls flagged from authoritative records, framed to verify and never auto-judged.

💲

Relative cost indicator

A clear cost rating from $ to $$$$, so you can weigh budget alongside posture instead of chasing "contact sales" pages.

📄

Ready-to-send RFP

A NIST SP 800-161-aligned RFP with the right required certs, the specific questions to ask, and a sources appendix, generated for you.

📋

Hand off to procurement

Picked a vendor? Forward a ready-made request to your sourcing or procurement team to start their process, as an email, Word doc, CSV, or JSON that drops into the common procurement and GRC tools.

Where it fits

Five moments it pays for itself.

📥

New-vendor intake

A business unit wants a new tool. Triage it in a minute: real company, published certs, red flags, and exactly which documents to request before it goes any further.

🏁

Shortlists & runoffs

Weighing several suppliers? Screen them side by side, see who leads and why, and export a runoff summary. Kill the weak candidates before anyone spends due-diligence hours on them.

🗓️

Annual-review prep

Re-screen your existing vendors before renewal: certifications lapsed, new breaches or sanctions hits, anything that changed since you signed.

🔎

M&A and partner screening

A fast, sourced first pass on a target's or partner's public posture: legitimacy, ownership, litigation, and adverse records, before deeper diligence begins.

🚦

Low-risk routing

Not every vendor needs the full questionnaire. The inherent-risk tier helps you route low-risk purchases through a lighter path and save the heavy review for the vendors that warrant it.

The math is simple.

One screen checks 30+ authoritative sources in about a minute. Done by hand, that first pass takes an analyst 30 to 60 minutes per vendor. At 20 vendors a month, that is 10 to 20 analyst-hours back every month, and the weak candidates never reach your formal review at all.

Anyone can ask a chatbot. VendorLens shows its receipts.

Chatbot research can be outdated or invented, and there is no way to tell which. Every VendorLens fact is checked against the issuing registry or the vendor's own public pages, and the sourced ones link to exactly where they came from, so anyone can verify them. No hallucinated SOC 2s.

Trustworthy by design, because we show our work.

VendorLens is an informational pre-screen from public data, nothing more, and every signal carries an evidence grade you can audit.

  • Three-state grading. Every finding is Verified, Claimed, or Not found, and "not found" is never scored as insecure.
  • Grounded in standards. Scoring is gauged against NIST SP 800-161, ISO/IEC, and the OWASP LLM Top 10, not opaque vendor magic.
  • Authoritative verification. Certifications are confirmed against issuing registries (FedRAMP, CSA STAR, openFDA), with the source cited.
  • Low-risk by construction. We read each vendor's own public pages plus public registries, with no third-party-ToS scraping.
Pricing

Start free. Scale when it earns its place.

Far below enterprise risk-rating tools, and priced so an analyst can expense it without a procurement cycle.

Other tools charge $79 to $210 per vendor, every month, just to monitor one. VendorLens is priced per person, not per vendor, so on a paid plan you screen as many vendors as you want for one flat price.

Free

$0
Try it before you commit
  • 3 full pre-screens every month
  • All screening dimensions
  • Inherent-risk tiering
  • Cost & adverse checks
Try it free
MOST POPULAR

Pro

$19 /mo
For one person
  • Unlimited pre-screens
  • Watchlist monitoring + change alerts
  • RFP + procurement-handoff generation & export
  • Saved history & re-screens
Get started
NEW

Small team

$89 /mo
For a small team · up to 5 seats
  • Everything in Pro, for up to 5 people
  • Shared saved history across the team
  • One simple bill, no per-seat math
  • Seat limit enforced, swap people any time
Get the team on →

Team

$299 /mo
Whole company · up to 100 employees
  • Everything in Pro, for everyone at your work domain
  • API access, pull screens into your GRC / procurement system
  • No per-seat math, no invites to manage
  • $2,990/yr on annual (2 months free), invoice & PO friendly
Get your team on →

Enterprise (over 100 employees, SSO, DPA, SLA, connectors): from $4,900/yr. Talk to us and we'll set you up.

FAQ

Good questions, straight answers.

Is this a security assessment or audit?
No. It's an informational pre-screen from public data, built to help you decide which of the vendors you're weighing are worth submitting to a formal risk review. It points you to the right questions; it doesn't make the decision for you.
Where does the evidence come from?
Each vendor's own public website (trust centers, security and privacy pages, pricing) plus authoritative registries: FedRAMP, CSA STAR, openFDA, Have I Been Pwned, and CourtListener. Certifications are confirmed against the issuing source and cited.
How accurate is the cost indicator?
It's a relative cost estimate, from $ to $$$$, based on public pricing signals. Think of it as a buying guide to compare options, not a quote. Most enterprise pricing is "contact sales," so the indicator is intentionally relative rather than exact.
What if a vendor publishes very little?
You'll see "not enough public evidence, request documents," never a false "risky." VendorLens separates how likely a vendor is to clear from how much evidence backs that view, so thin disclosure is flagged as thin, not as risky.
Do I need an account?
A quick email sign-up gets you 3 free pre-screens every month, no credit card. They refresh on the 1st; upgrade any time for unlimited use.

Stop guessing which vendors to vet.

Run 3 pre-screens free every month and see the shortlist, and the questions to ask, in about a minute.

Try VendorLens free →