Kenzer grades every vendor from what it can actually see on their infrastructure, keeps that grade current, and gives them a way to fix what it finds. When one of their providers has an incident, you'll know which vendors are affected.
| Kenzer | Questionnaires | |
|---|---|---|
| Where the answer comes from | What we observe on their live infrastructure | What the vendor tells you |
| How current it is | Rescanned on your schedule | Out of date once it's signed |
| How a vendor improves | They fix the issue and the next scan confirms it | They fill in the form again |
| Their suppliers | Provider incidents flag every affected vendor | Usually not covered |
| Forgotten systems | Found through Subdomain Center | Only what they declare |
Most vendor risk tools stop at handing over a score. Kenzer helps the vendor do something about it.
Give their team a login that only covers their own organization.
Every issue, ranked by severity and by how exploitable it is.
Their own team works the list, without tickets bouncing through yours.
The next scan confirms the fix and both of you see the grade improve.
A 13-tier grade from O to F, recalculated after every scan across twelve risk factors.
Log an incident at a shared provider like AWS or Okta once, and every vendor that relies on it is flagged.
Stolen staff and customer credentials from infostealer logs, with recent ones flagged first.
Compare a vendor with its tier and industry, and see who's improving or getting worse.
Model a vendor's subsidiaries as sub-organizations that roll up into one grade.
A no-login link for onboarding reviews, or for a vendor to show its own customers.
Vendors who connect a repository get SAST, SCA and DAST in the same grade.
Accepting a risk records who, when and why. If the issue comes back, so does the review.
Export a vendor or your whole portfolio as a branded PDF, with the history you choose to include.
From what we actually find on their infrastructure, weighted by severity and by how exploitable each issue is, and mapped onto a 13-tier grade from O to F across twelve risk factors.
No. Passive checks need nothing from the vendor. Inviting them to fix issues, or asking for permission to scan deeper, is a separate and optional step.
On a schedule you set per vendor or tier, so your riskiest suppliers are checked most often.
Most teams use Kenzer as the objective view of what's exposed, alongside questionnaires for the things a scan can't see, like policies and training.
Never. A vendor's login only covers their own organizations. Anything else simply doesn't exist for them.
A scorecard link is read-only and shows the grade. A login lets the vendor see each finding and fix it.
Grade the portfolio, give vendors a way to fix what's found, and let the next scan confirm it.