GRC Oversight

Live demoFictional sample data. Nothing is saved.

Sign up

12GRC

Vendor Risk

Maintain Northwind Robotics's vendor inventory with criticality and status. Upload a vendor's SOC 2 report (PDF) and the parser detects the auditor's opinion (Qualified vs Unqualified), the system description, and control exceptions, then derives a risk rating.

Vendors (10)

  • AWS

    CRITICALACTIVE
    Monitoring:· last scan 6/30/2026
    LOW riskUnqualified opinion, no exceptions
    SOC 2 Type II covering infrastructure, security, availability. No exceptions noted.
  • GitHub

    HIGHACTIVE
    Monitoring:· last scan 6/28/2026
    LOW riskUnqualified opinion, no exceptions
    Covers Enterprise Cloud. Bridge letter on file for current period.
  • Datadog

    MEDIUMACTIVE
    Monitoring:· last scan 6/14/2026
    LOW riskUnqualified opinion, 1 minor exception
    Exception: one access-review cadence lapse noted, remediated within 30 days per management response.
  • Slack

    MEDIUMACTIVE
    Monitoring:· last scan 6/9/2026
    LOW riskUnqualified opinion, no exceptions
    Part of Salesforce Trust umbrella report.
  • Google Workspace

    HIGHACTIVE
    Monitoring:· last scan 7/1/2026
    LOW riskUnqualified opinion, no exceptions
    Covers Gmail, Drive, Calendar, and Admin Console.
  • Stripe

    CRITICALACTIVE
    Monitoring:· last scan 6/26/2026
    LOW riskUnqualified opinion, no exceptions
    PCI DSS Level 1 service provider; SOC 2 Type II annually renewed.
  • Zendesk

    MEDIUMUNDER_REVIEW
    Monitoring:· last scan 5/19/2026
    MEDIUM riskQualified opinion, 2 exceptions
    Exceptions relate to change-management ticket documentation. Under review by security team.
  • Rippling

    HIGHACTIVE
    Monitoring:· last scan 6/4/2026
    LOW riskUnqualified opinion, no exceptions
    HRIS system of record; scope includes PII and payroll data handling.
  • Notion

    LOWACTIVE
    Monitoring:

    No SOC 2 assessment yet.

  • Figma

    LOWACTIVE
    Monitoring:

    No SOC 2 assessment yet.