Kenzer continuously maps every vendor's external infrastructure from passive reconnaissance and grades it O through F. A shared provider going down automatically flags every vendor exposed to it.
When a grade needs work, a scoped login lets the vendor's own team see what's driving it and fix it directly.
Point-in-time attestations and self-reported questionnaires go stale the day they're signed.
Kenzer re-observes on a schedule, entirely from passive sources, so a vendor's grade reflects their infrastructure today, not six months ago. Active verification is available once a vendor authorizes it.
| Kenzer | Questionnaire-based tools | |
|---|---|---|
| Data source | Passive reconnaissance, active verification with authorization | Self-reported answers |
| Freshness | Continuous, scheduled rescans | Point-in-time, goes stale |
| Vendor can dispute the score | Fix the finding, rescan proves it | Re-answer the form |
| Fourth-party visibility | Automatic breach cascade detection | Not typically covered |
| Shadow IT discovery | Full subdomain & asset enumeration | Limited to declared assets |
Most vendor risk tools stop at handing over a scorecard the vendor can't act on. Kenzer goes one step further.
Grant a vendor's team account access to exactly their own organization — no visibility into anyone else's data.
Every open finding, ranked by severity and real exploit likelihood — not just a number.
The vendor's own team fixes the issue directly — no ticket bouncing through your risk team.
The next scheduled rescan picks up the fix — visible to both sides, no manual re-attestation.
13-tier O to F grading recomputed after every scan.
A diminishing-returns risk curve means one bad finding doesn't collapse the score.
See a vendor's grade against its own industry tier and peer set.
Track portfolio-wide trends — improving vs. worsening, at-risk counts.
Log an incident at a shared provider once.
Every vendor with a detected dependency on it is flagged automatically.
Score a vendor's subsidiaries or business units as sub-organizations.
Rolls up into one parent score automatically.
Every vendor gets a public, no-login scorecard link — for onboarding review, or to prove posture to its own customers.
A vendor's login gets a 404, not a 403, on anything outside its grant.
It can't even confirm another organization exists.
No re-attestation, no “please confirm you fixed this” email.
The platform verifies remediation the same way it found the issue: by scanning again.
A vendor running several subsidiaries can be granted exactly the set they're responsible for — no more, no less.
The same scoping mechanism works for an internal business unit or, for government deployments, an individual ministry.
See Government & CERTs.
From real findings across discovery, port/service enumeration, web and vulnerability scanning.
Weighted by severity — critical findings weighted far more heavily than low-severity ones — then mapped onto a 13-tier grade.
Yes — passive reconnaissance doesn't require vendor participation or notice.
Granting them remediation access, or requesting authorization for active verification, is a separate, optional step.
On a schedule you control per vendor or tier — higher-risk vendors can be rescanned more frequently than low-risk ones.
Most programs use Kenzer as continuous, objective ground truth alongside — not instead of — internal control questionnaires for things a scan can't see (policies, training, contracts).
Yes, at any time — access is a grant your admin manages, not a permanent credential handed to the vendor.
Yes — the public scorecard link is read-only and shows the grade.
A scoped login lets the vendor actually see finding-level detail and take action.
Score the portfolio, hand vendors the access to fix what's found, and let the next scan confirm it.