Vendor Risk Reports
Assessments ThirdProof has run and published. Each one investigates a vendor across 27 independent sources — certification registries, sanctions lists, domain and infrastructure security, adverse media, subprocessor chains — and records what it found, what it could not establish, and the date it looked.
None of it is self-reported by the vendor. Risk tiers come from a deterministic rules engine, not a model. Free to read, no account needed — a report is delivered by email.
Showing 22 of 22 vendors
Popular Reports
cloud infrastructure
communications
compliance automation
developer tools
e-signature
email delivery
file storage
identity management
marketing
observability
password management
payments
payroll
project management
video messaging
Don't see your vendor?
These are the vendors we publish. ThirdProof can investigate any vendor by domain — run one now, no account needed.
Assess a Vendor Free →No credit card required
Want to see how a conclusion is reached first? Read the methodology, the 27 sources behind every assessment, the FedRAMP status table, or the guide to which offering a FedRAMP listing covers.