Vendor & supplier security
Vendor security assessment, based on evidence
Replace long security questionnaires with Requirements-to-Evidence Mapping. Upload your security requirements once and let Governly verify them against the vendor's SOC 2, ISO 27001, penetration tests, security policies and architecture documents.
What the security assessment covers
- Identity & access — MFA, SSO, Entra ID, role separation
- Encryption in transit and at rest
- Data residency and EU hosting
- Logging, monitoring and incident response
- Business continuity and disaster recovery
- Vulnerability management and pen testing
- Sub-processor governance
- Exit, portability and data deletion