Trust & controls

The questions risk teams ask us, answered honestly.

VendorLens sells to the people whose job is skepticism. So here are the real answers on where the data comes from, what keeps it accurate, what you can export, and what is still on the roadmap, with nothing dressed up.

"The data is public. What am I paying for?"

Time, completeness, and consistency. Every fact VendorLens shows is publicly checkable, and that is the point: it is evidence you can defend. What you pay for is that one screen checks 30+ authoritative sources in about a minute, the same first pass that takes an analyst 30 to 60 minutes per vendor by hand, and it checks the same sources every time, so vendor number forty gets the same rigor as vendor number one. The sources include FedRAMP, SEC EDGAR, SAM.gov, the US, UN, UK and EU sanctions lists, FINRA, FDIC, FMCSA, EPA, openFDA, and more, each linked from the finding it produced.

"Can the AI make things up?"

Not about the facts. Every number, certification, and registry result is computed in code directly from the source data. The AI's only job is to reword those computed findings into plain language, under hard rules that forbid it from inventing certifications, numbers, or sources. If the AI is unavailable, the deterministic version renders instead. The displayed hard numbers are always rendered from the computed data, so even a misbehaving model cannot alter them.

"How do I know a match is really my vendor?"

Name screens (sanctions, debarment, exclusions) use collision-safe matching: whole-word gates, distinctive-token filters, and exact-name-versus-fragment logic. An exact match is flagged as material; a partial name overlap is surfaced as a likely collision to verify, never asserted as guilt. And "not found" is never scored as a failing grade; it becomes the exact document to request instead.

"What quality controls exist?"

Three layers. A regression corpus of known ground-truth vendors (real breaches that must surface, clean vendors that must never false-flag, sanctions entries that must and must not match) runs against the live engine, and every accuracy issue that is found becomes a permanent test so it cannot silently return. A semi-annual source audit re-verifies the advice against the underlying standards (NIST, CFPB-class benchmarks, registry formats). And source data is refreshed on schedule: sanctions and exclusion mirrors update weekly or daily from the official government feeds.

"Is there an audit trail I can export?"

Every result carries its evidence: per-vendor receipts (how many facts were checked and how many are source-linked), the date the evidence was retrieved, and links to the issuing source for every sourced finding. Screens are saved to your account history, and you can export results as JSON, CSV, or Word, which drop into common procurement and GRC tools. A full reviewer-action audit log (who viewed, exported, and changed what, and when) is on the roadmap for team plans, and we will not claim it before it ships.

"Can I configure risk criteria to match our policy?"

Partly, today. The inherent-risk intake (data type, volume, criticality, regulatory exposure) sets the scrutiny tier, which changes the required evidence and the depth of the asks, and you can override it. Fully configurable thresholds, custom risk tiers, and disposition rules mapped to your own policy are on the roadmap; if that is the deciding factor for you, tell us and it moves up.

"Do you integrate with ServiceNow, Archer, OneTrust, or Jira?"

Not natively yet. The exports (JSON, CSV, Word) are designed to import cleanly into those systems, and that is the honest current answer. Native integrations follow customer demand; the API is the first step on that path.

"What is VendorLens not?"

It is not a certification, a security assessment, or a replacement for your formal due diligence. It is the triage layer before that process: it tells you which vendors are worth the formal review, what the public record already answers, and exactly what to request for the rest.

Judge it on your own vendors.

Three pre-screens free, no credit card. Every finding arrives with its source, so you can check our work.

Try VendorLens free