VendorLens

    Welcome offer: 50% off your first 3 months

    New customers only. Applied automatically at checkout.

    20d:22h:36m:28s
    See pricing
    Trust center and lightweight supplier assessments (Beta)

    Share your security evidence, and assess the suppliers you depend on

    Publish your SOC 2 report, ISO certificates, DPA and policies on one branded page — customers self-serve what is public and request what is sensitive. Then run the reverse review: send a right-sized questionnaire to your own suppliers, score their inherent risk and record the decision.

    Free Community account — no card needed. Pro 14-day trial requires a card for verification; no charge until the trial ends. Vendor Assessments are in Beta. VendorLens is not a certification or audit service.

    VendorLens trust portal showing security certifications, document library and NDA-gated access
    Public trust portal
    NDA-gated document library
    Admin dashboard and audit log

    Two halves of the same security review

    You answer reviews from your customers, and you run reviews on your own suppliers. VendorLens covers both at a size a small team can actually operate.

    Controlled security disclosure

    Publish your SOC 2 report, ISO certificates, DPA, subprocessor list and policies on one branded trust center, with public, NDA-gated or private access per document and an audit trail of every request and download.

    • One branded page, on your own domain from Pro.
    • NDA request, approval, time-limited link and watermarked download.
    • Activity history of views, requests, approvals, downloads and expiries.

    Lightweight supplier assessment (Beta)

    Add the suppliers you depend on, answer six exposure questions to get an explainable inherent-risk rating, send a recommended questionnaire, collect answers and evidence through an expiring link, and record an approval decision with its rationale.

    • Source-controlled questionnaire packs: Lightweight Core plus Personal Data, Critical Service, Payments and iGaming add-ons.
    • Inherent risk scored server-side from your answers, with the factors shown.
    • Supplier link with autosave, evidence upload, file inspection and clarification requests.
    • Approve, approve with conditions or reject — with rationale, residual risk and a next review date.

    Vendor Assessments are in Beta — Community covers up to 10 suppliers and 10 live assessments; see the plan limits.

    Is this the right tool for you?

    VendorLens combines controlled security disclosure with lightweight supplier assessment. It is not continuous monitoring and not a full enterprise TPRM platform.

    A good fit
    • You have a SOC 2 report, ISO certificate, DPA or policy set already written.
    • Customers keep asking for the same files and someone re-sends them by hand.
    • You want sensitive documents behind an NDA, with a record of who downloaded them.
    • You also need to assess a handful of suppliers — questionnaire, evidence, decision.
    • You want the page on your own domain and in your own brand.
    What VendorLens is not
    • Not an auditor or certification body: VendorLens does not assess, verify or sign off on anyone’s controls, and issues no certificates.
    • Not continuous monitoring: no security ratings, external scanning, breach alerts or financial-health feeds.
    • Not a full enterprise TPRM suite: no portfolio-wide risk register, remediation programme management or fourth-party mapping.
    • Not a GRC platform: no internal control monitoring, evidence automation or policy authoring for your own compliance programme.
    • Not an answer robot: it does not auto-fill customer questionnaires and holds no AI answer library.

    Not sure what belongs on the page yet? Read what to include in a trust center.

    What sharing documents by hand actually costs

    Every one of these is fixable. None of them get better as deal volume grows.

    Email attachments

    The report leaves your control the moment it is sent. No expiry, no watermark, no way to pull it back.

    Drive links

    Access is granted per person and rarely reviewed, and forwarded links keep working long after the deal ends.

    Repeated NDA handling

    Each customer needs the same NDA step, chased manually between sales, legal and whoever holds the file.

    Version confusion

    Last year's report is still circulating because nobody knows who received which copy.

    No access history

    When someone asks who has your SOC 2 report, the honest answer is a search through inboxes.

    If most of your review time goes into forms rather than files, see the security questionnaire alternative.

    How it works

    Five steps, in the order you do them.

    1

    Upload your documents

    Add the reports, certificates and policies you already have.

    2

    Set the access level

    Mark each document Public, NDA-gated or Private.

    3

    Brand it and publish

    Add your logo and colours, then publish — on your own domain from Pro.

    4

    Share one link

    Sales sends the same URL to every customer instead of a new attachment.

    5

    Review activity

    See requests, approvals and downloads in the audit log.

    VendorLens demo trust portal showing SOC 2 and ISO 27001 certifications
    VendorLens demo document library with public and NDA-gated access controls

    These are screens from the live demo trust portal — open it and try a document request yourself.

    What teams publish

    The material customers ask for during a security review.

    SOC 2 reportType I and Type II, NDA-gated
    ISO 27001Certificate and scope
    DPAData processing agreement
    PoliciesSecurity, privacy, BCP/DR
    SubprocessorsVendors and infrastructure
    SOC 2 reports
    ISO certificates
    Data processing agreement (DPA)
    Subprocessor list
    Security and privacy policies
    Pen-test summaries
    Business continuity and DR information
    Cyber-insurance evidence

    Sharing an audit report is the most common starting point — see the security document portal.

    VendorLens, manual sharing and full GRC

    Three different jobs. VendorLens handles disclosure and right-sized supplier assessment — not continuous control monitoring, and not enterprise TPRM.

    Manual sharing

    Email, Drive, one customer at a time

    • Files leave your control once sent
    • NDA handled by hand for each customer
    • No record of who downloaded what
    • Costs nothing to start

    VendorLens

    Disclose your evidence, assess your suppliers

    • One branded link, on your own domain from Pro
    • Public, NDA-gated or Private per document
    • Watermarked, time-limited downloads and an audit log
    • Supplier questionnaires, inherent risk and recorded decisions (Beta)
    • No continuous monitoring or security ratings

    Full GRC platform

    Getting and staying compliant

    • Evidence collection and control monitoring
    • Policy management and auditor workflows
    • Control monitoring and audit readiness workflows
    • Sales-led pricing and a longer rollout

    Who it's for

    Lean B2B teams where security reviews land on people with other jobs.

    Founders and operations

    Answer the security request once, publish it, and stop rebuilding the same folder of PDFs for every deal.

    Sales and RevOps

    Send the trust center link during the first call instead of waiting on someone else to forward the report.

    Security and compliance

    Decide what is public, gate the rest behind an NDA, and keep a timestamped record of every download.

    Buying side of the table instead? See vendor assessments .

    Who you are dealing with

    You are about to put your security documents into someone else's product. Here is who that is.

    VendorLens Technologies Ltd

    VendorLens Technologies Ltd · Reg. HE488809 · Limassol, Cyprus

    Remote-first team operating across the EU

    Questions before you sign up: sales@vendorlens.io · Support: support@vendorlens.io · Security: security@vendorlens.io

    Pricing

    Published rates, no sales call required. Custom domains start on Pro.

    Community

    Free

    • Up to 10 documents
    • Published on a VendorLens URL
    • NDA-gated documents and audit log

    Pro

    $99/month

    • Unlimited documents
    • Custom domain included
    • NDA-gated documents and audit log

    Business

    $299/month

    • Unlimited documents
    • Custom domain included
    • NDA-gated documents and audit log

    Frequently asked questions

    What customers and prospective customers ask most often.

    Publish a customer-ready trust center

    Upload the documents you already have, decide who can see what, and send one link. Free to start.