What ThirdProof Checks on a Vendor
Every assessment queries 27 sources in parallel, grouped into the evidence categories below. Each entry says what the category examines and what it can actually establish — which is also what bounds it.
Providers within a category change as sources are added, replaced or retired, so the categories are the stable unit rather than the vendor names behind them. How the results become a risk tier is in the methodology, and source categories explains why a finding is never corroborated by its own category.
Sanctions Screening
Screens vendors against OFAC SDN, consolidated sanctions lists, PEP databases, and international sanctions regimes. Entity name verification reduces false positives from similar names.
Business Registration
Verifies legal entity identity via the GLEIF LEI registry, confirming jurisdiction, formation date, active status, and registered address. Name matching is verified to prevent misattribution.
Adverse Media
Screens recent news coverage for regulatory actions, lawsuits, data breaches, financial distress, and fraud allegations across multiple news sources.
Domain Analysis
Validates SSL certificates, HTTPS enforcement, domain age, registrar information, and DNS configuration.
Infrastructure Exposure
Identifies open ports, exposed services, cloud hosting footprint, and network-level security indicators.
Threat Intelligence
Multi-engine threat analysis checking for malware association, phishing indicators, abuse reports, botnet participation, and safe browsing status.
Company Intelligence
Provides firmographic data including industry classification, company size estimates, technology stack, and operational context.
Domain Registration
Queries WHOIS records for registrant information, registration dates, and registrar details.
Certificate Transparency
Reviews SSL/TLS certificate issuance history, subdomain enumeration, and certificate authority validation.
HTTP Security
Evaluates security headers, content security policies, and browser security configurations.
IP Reputation
Checks IP addresses against known blocklists, spam databases, and abuse registries.
Malware & Phishing Detection
Scans domains against malware databases, phishing registries, and unsafe browsing indicators.
Website Security Scan
Performs live website scanning to detect technologies in use, screenshot capture, and threat indicators at the URL level.
Web Archive
Analyzes historical web presence to assess operational longevity and content consistency over time.
Community Sentiment
Reviews public tech community discussions for vendor-related feedback, incident reports, and reputation signals.
Trust & Compliance Page Scan
Scans vendor trust, security, and compliance pages for certification claims (SOC 2, ISO 27001, HITRUST, PCI-DSS, FedRAMP, and more). Cross-references the FedRAMP public registry for independent verification. Detects aspirational language to distinguish current certifications from in-progress efforts.
Supply Chain & Subprocessor Discovery
Discovers vendor subprocessor pages and extracts third-party dependencies. Runs sanctions screening and safe browsing checks against each subprocessor to surface supply chain risk.
FDIC Institution Check
Searches the FDIC BankFind registry for failed bank records associated with the vendor. Verifies entity identity through name match confirmation.
SEC Filing Search
Searches SEC EDGAR full-text search for enforcement-related filings mentioning the vendor in the last 5 years. Findings indicate the vendor is mentioned in a filing, not necessarily the subject of enforcement.
Historical Media Search
Searches Google News archives for adverse media beyond the 12-month primary media scan window. Surfaces older regulatory actions, lawsuits, and security incidents.
Certification Registry Verification
Independently verifies compliance certifications via public registries: FedRAMP Marketplace, HITRUST directory, IAF CertSearch (ISO 27001), PCI Security Standards Council, and SOC 2 enhanced claim detection.
AI Data Usage & Model Disclosure
Discovers and extracts vendor AI data usage policies. Identifies training commitments, third-party AI providers (OpenAI, Anthropic, Google, etc.), data retention periods, and opt-out mechanisms.
See these sources applied to a real vendor in a published assessment, or browse all vendor reports.
Questions about data coverage, or want the provider list for a specific category? Contact support@thirdproof.ai.