A passed assessment is a snapshot. Vendors get breached, certs lapse, a critical CVE lands, and you find out from the news. Scout watches all of it, on every vendor, and shows you exactly what is at stake.
A vendor uploads
a SOC 2. Hudson reads it.
Pen-test reports, ISO certificates, completed questionnaires. Hudson extracts the controls, writes the summary, surfaces the subprocessors and data connections buried in the appendices, and drafts the findings. Seconds, not an afternoon. Hit Analyze to watch it work.
Hudson is standing by.
Hit Analyze and watch a 47-page report turn into structured, decision-ready risk.
Northwind shows strong access management and encryption, but runs no formal vendor-risk program and discloses a one-week breach-notification window. Both are material for a vendor handling banking data.
Northwind lacks a documented risk program despite handling sensitive banking data, leaving gaps in how risk is identified and mitigated.
A one-week notification timeline far exceeds the 24 to 72 hours expected of a payment processor, slowing customer and regulatory response.
Act on
what matters.
A score is where Scout starts, not where it stops. It tracks the trend with context, reads every vendor in plain language, queues what is overdue, and shows exactly how your data flows.
The trend, in context
Your portfolio score over time, with every breach, score drop, completed assessment and new vendor marked right on the line.
A plain read on every vendor
Hudson grades each vendor in plain language, surfaces the alerts worth reviewing, and stays a click away for follow-ups.
Nothing slips past due
Every open finding across your stack, ranked by how overdue it is, so the most urgent work is always on top.
Every connection, inspected
Exactly which internal systems hand data to which vendor, by protocol, sensitivity and encryption.
Coverage, gaps called out
How much of your portfolio is assessed, current and monitored, with the gaps named so no vendor sits unwatched.
If Amazon Web Services has an outage, these vendors are impacted:
See the cascade before it hits
When a critical provider has an outage, Scout names every vendor that goes down with it, so your blast radius is never a surprise.
See your
vendors' vendors.
The subprocessors Hudson pulls out of those documents become a dependency graph across your whole portfolio. That is where concentration hides: nine of your vendors sitting on the same cloud, and no single questionnaire able to tell you so.
Amazon Web Services9 vendors depend on this
SSnowflake4 vendors depend on this
Google Cloud Platform3 vendors depend on this
Google Workspace3 vendors depend on this
Amazon Web Services9 vendors use this›
Cloudflare2 vendors use this›
Cloudflare Workers and WAF1 vendor uses this›
CrowdStrike, Inc.1 vendor uses this›
Amazon Web ServicesCloud infrastructureConcentration risk
SnykSaaS applicationsMedium
CloudflareData center / hostingHighIf Amazon Web Services experiences an outage, these vendors could be impacted:
SnykMedium
CloudflareHighAsk Hudson. Get answers,
not homework.
Hudson watches the whole portfolio around the clock. When something breaks, ask in plain language and get a grounded answer, the vendors actually affected, and the next actions already drafted, each waiting on your approval.
- Okta uses Northgate for SSO. Production identity data is in scope.
- Snowflake lists Northgate as a sub-processor in their SOC 2, appendix C.
- Plaid shares Northgate as a fourth-party CDN edge.
Or hand
the work over.
Scout is a platform you can run yourself. It is also a program we will run for you, on the same platform, with the decisions staying yours.
TPRM without the headcount.
We map the vendors, triage the alerts, chase findings to closure and brief your board. You approve, you decide, you own the relationship.
See Managed Scout →- 01Vendor intake and tiering, run to your risk appetite
- 02Assessments issued, chased and reviewed
- 03Alerts triaged daily, with only the real ones escalated
- 04A quarterly board pack, written from the live record
Bring us
your vendor list.
Send a real list and a real SOC 2. We will map the subprocessors underneath it and show you the concentration you did not know you had.