PlatformCommand · Scout · Anvil Third-party risk · Nth-party mapping · Continuous monitoring
ScoutProduct 02 of 03

Your vendors change.
Scout never blinks.

Scout is AI-native third-party risk. Assessments still matter, but Scout goes further: Hudson reads each vendor's own SOC 2 to map the subprocessors underneath them, then watches all of it around the clock and shows you the blast radius the moment one slips.

See how it works

Fig. 01 · Scout dashboard · 41 vendors, this morning

The Scout dashboard: portfolio grade, attention-required stories, the action queue, risk movers, portfolio trend and vendor heatmap
Watching, every day Security posture Vulnerabilities Breaches Financial health Data residency Concentration

A passed assessment is a snapshot. Vendors get breached, certs lapse, a critical CVE lands, and you find out from the news. Scout watches all of it, on every vendor, and shows you exactly what is at stake.

§ 01Assess

A vendor uploads
a SOC 2. Hudson reads it.

Pen-test reports, ISO certificates, completed questionnaires. Hudson extracts the controls, writes the summary, surfaces the subprocessors and data connections buried in the appendices, and drafts the findings. Seconds, not an afternoon. Hit Analyze to watch it work.

PDF Northwind-SOC2-TypeII-2025.pdf47 pages · uploaded just now
Controls extracted0 of 8

Hudson is standing by.
Hit Analyze and watch a 47-page report turn into structured, decision-ready risk.

Hudson analysis

Northwind shows strong access management and encryption, but runs no formal vendor-risk program and discloses a one-week breach-notification window. Both are material for a vendor handling banking data.

Suggested sub-processors3 found
Suggested data connections2 found
Patient DatabaseNorthwindSFTP
API GatewayNorthwindAPI
Drafted findings2
MediumSecurity governance
No formal risk management program

Northwind lacks a documented risk program despite handling sensitive banking data, leaving gaps in how risk is identified and mitigated.

MediumIncident response
Breach notification window exceeds best practice

A one-week notification timeline far exceeds the 24 to 72 hours expected of a payment processor, slowing customer and regulatory response.

0 added to profile
§ 02Act

Act on
what matters.

A score is where Scout starts, not where it stops. It tracks the trend with context, reads every vendor in plain language, queues what is overdue, and shows exactly how your data flows.

Portfolio score87▲ 430d
Vendor breach · GlacierDetectedApr 18Score impact−6 ptsExposure1.2M records

The trend, in context

Your portfolio score over time, with every breach, score drop, completed assessment and new vendor marked right on the line.

HHalcyonIdentity provider · reassessed 12d agoB
Hudson’s read External posture is solid, with valid certs and no exposed admin surfaces. One medium finding: SPF is soft-fail. Two new sub-processors this quarter. No breach signals in 90 days.

A plain read on every vendor

Hudson grades each vendor in plain language, surfaces the alerts worth reviewing, and stays a click away for follow-ups.

Action queue12 open
Expired SOC 2 reportGlacier12d overdue
Critical CVE unpatchedBeacon5d overdue
Re-attestation dueHalcyondue today
DPA renewal pendingRelayin 3d

Nothing slips past due

Every open finding across your stack, ranked by how overdue it is, so the most urgent work is always on top.

Data connections3 systems
Critical Patient DBInternal system Medium API GatewayInternal system Object StoreInternal system
StrataData platform

Every connection, inspected

Exactly which internal systems hand data to which vendor, by protocol, sensitivity and encryption.

Coverage142 vendors
Vendors assessed92%
Documents current78%
Assessments current84%
Monitoring enabled96%
3 vendors with coverage gaps

Coverage, gaps called out

How much of your portfolio is assessed, current and monitored, with the gaps named so no vendor sits unwatched.

Cascade impact

If Amazon Web Services has an outage, these vendors are impacted:

SSnykMedium
AAdvosecHigh
PPlaidHigh
PPrime SolutionsCritical

See the cascade before it hits

When a critical provider has an outage, Scout names every vendor that goes down with it, so your blast radius is never a surprise.

§ 03Map

See your
vendors' vendors.

The subprocessors Hudson pulls out of those documents become a dependency graph across your whole portfolio. That is where concentration hides: nine of your vendors sitting on the same cloud, and no single questionnaire able to tell you so.

Scout Supply chain intelligence
Supply Chain IntelligenceNth-party risk and dependency mapping across your vendor ecosystem By vendorBy sub-processor+ Add sub-processor
34Sub-processors
36Dependencies
5Concentration risks
8Critical links
Concentration risk detected
Amazon Web Services9 vendors depend on this SSnowflake4 vendors depend on this Google Cloud Platform3 vendors depend on this Google Workspace3 vendors depend on this
Sub-processors34
Amazon Web Services9 vendors use this
AAuth01 vendor uses this
BBastionX, Inc0 vendors use this
CChargebee, Inc.0 vendors use this
Cloudflare2 vendors use this
Cloudflare Workers and WAF1 vendor uses this
CrowdStrike, Inc.1 vendor uses this
Amazon Web ServicesCloud infrastructureConcentration risk
Used by 9 vendors
SnykSaaS applicationsMedium
AAdvosecConsulting servicesHigh
PPlaidPayment & bankingHigh
CloudflareData center / hostingHigh
TTwilioCloud infrastructureHigh
PPrime SolutionsHealthcare / benefitsCritical
Cascade impact

If Amazon Web Services experiences an outage, these vendors could be impacted:

SnykMedium
AAdvosecHigh
PPlaidHigh
CloudflareHigh
TTwilioHigh
PPrime SolutionsCritical
HHealthFitCritical
WWorkdayCritical
AABC AnalyticsCritical
Fig. 03 · Supply chain intelligence · nth-party dependency mappingExtracted from vendor documents, not from a questionnaire
Hudson
§ 04The analyst

Ask Hudson. Get answers,
not homework.

Hudson watches the whole portfolio around the clock. When something breaks, ask in plain language and get a grounded answer, the vendors actually affected, and the next actions already drafted, each waiting on your approval.

Live Northgate Identity disclosed a breach · 14m ago Hudson · always on
You
Northgate just disclosed a breach. Are we exposed?
Hudson
Yes. Northgate is a sub-processor for 3 vendors in your portfolio, and two of them touch production identity data. Here is what I found.
Sources · 3 SOC 2s · 1 breach feed · supply-chain graph
What is exposed
  • Okta uses Northgate for SSO. Production identity data is in scope.
  • Snowflake lists Northgate as a sub-processor in their SOC 2, appendix C.
  • Plaid shares Northgate as a fourth-party CDN edge.
Recommended actions, drafted
Email Okta security for breach-impact confirmation
Open a finding on Snowflake sub-processor exposure
Notify the IR channel in Slack
Hudson answered in 1.2s
§ 05Operated for you

Or hand
the work over.

Scout is a platform you can run yourself. It is also a program we will run for you, on the same platform, with the decisions staying yours.

Managed Scout

TPRM without the headcount.

We map the vendors, triage the alerts, chase findings to closure and brief your board. You approve, you decide, you own the relationship.

See Managed Scout
  • 01Vendor intake and tiering, run to your risk appetite
  • 02Assessments issued, chased and reviewed
  • 03Alerts triaged daily, with only the real ones escalated
  • 04A quarterly board pack, written from the live record
§ 06Next

Bring us
your vendor list.

Send a real list and a real SOC 2. We will map the subprocessors underneath it and show you the concentration you did not know you had.

All three products