Skip to main content
Every OAuth app Synk.to discovers in your environment is resolved to the vendor behind it — the company that built the app and will hold your data. Synk.to maintains a catalog of 3,000+ SaaS vendors, each with a normalized category and a profile covering company details, compliance posture, and security controls. This page explains how vendors are categorized and what information Synk.to gathers on each of them. For how that information turns into a risk rating, see Vendor Risk Assessment Methodology.

How a discovered app is matched to a vendor

When Synk.to discovers an OAuth app, it resolves it to a catalog vendor in the following order:
  1. Known system — if the app is a system already in the Synk.to catalog, the vendor of that system is used.
  2. OAuth client ID — the app’s OAuth client ID is matched against the OAuth app IDs recorded for each vendor’s products. This is the most reliable match, since client IDs are stable even when an app is renamed.
  3. Name — as a fallback, the app name is matched against vendor and product names.
If no vendor can be matched, the app is still listed and scored on its OAuth scopes — see GWS OAuth Scope Risk.

Vendor categories

Vendors describe themselves in thousands of different ways (“AI”, “Artificial Intelligence”, “Generative AI”, “Enterprise AI”…). To make the catalog filterable, Synk.to normalizes these free-form descriptions into a two-level controlled taxonomy:
  • Primary category — exactly one broad sector per vendor (for example, Security & Compliance). This is what you see in the Category column and filter.
  • Categories (tags) — one or more specific tags from a controlled vocabulary of about 100 tags (for example, IAM, Security). Each tag belongs to exactly one sector.
When a vendor spans several sectors, its primary category is picked by sector priority — more specific sectors (such as AI/ML, Security & Compliance, Finance & Accounting) win over horizontal ones (such as Productivity & Collaboration). For example, Stripe carries the tags Payments, FinTech, and Dev Tools, and its primary category is Finance & Accounting.

Sectors and example tags

Use the Category filter on the Systems and Discovered systems pages to answer questions like “which AI tools are connected to our Google Workspace?” or “which HR vendors hold employee data?”.

Information gathered on each vendor

Each vendor record is built from public sources — the vendor’s website, trust center, security and legal pages, and company databases. It is grouped into four areas.
  • Description — what the company and its products do
  • Primary category and other categories
  • Website
  • Founded — founding year
  • Country — headquarters country, used for the jurisdiction tier
  • Employees — employee size range
  • Ownership — public, private, or acquired
  • Products — the products the vendor ships, each with its own OAuth app IDs
  • Investment stage and total funding
  • Certifications — SOC 2 (with report type), ISO 27001, ISO 27701, ISO 42001, FedRAMP (with impact level), HIPAA, PCI DSS, CSA STAR, HITRUST, and other listed frameworks
  • Privacy policy
  • Data Processing Agreement (DPA)
  • Trust center
  • Subprocessor list
  • Status page
  • Bug bounty page
  • Data residency options
  • SSO / SAML support
  • SCIM provisioning support
  • SSO tier — which plan SSO is available on
  • Pentest cadence — how often independent penetration tests are performed
  • Bug bounty program
  • SLA uptime commitment
  • Compliance score and Stability score — the sub-scores feeding the vendor risk rating
  • Rationale — the key drivers behind the vendor’s rating
  • Vendor risk — the final Very Low to Critical rating, see Vendor Risk Assessment Methodology

Where to find vendor information

Open any system on the Discovered systems page:
  • The vendor summary at the top shows the website, employee count, country, founding year, category pills (primary category first), and certifications.
  • The Details button opens the full vendor profile with the Company, Compliance, Security, and Scores & rationale sections described above.
Fields Synk.to couldn’t find are hidden rather than shown as empty.
Vendor data is collected from public sources and refreshed periodically, so treat it as a triage signal rather than an audit conclusion. A vendor whose trust center we couldn’t find may look weaker than its true posture. If you spot outdated or incorrect vendor information, let us know at support@synk.to.