How a discovered app is matched to a vendor
When Synk.to discovers an OAuth app, it resolves it to a catalog vendor in the following order:- Known system — if the app is a system already in the Synk.to catalog, the vendor of that system is used.
- OAuth client ID — the app’s OAuth client ID is matched against the OAuth app IDs recorded for each vendor’s products. This is the most reliable match, since client IDs are stable even when an app is renamed.
- Name — as a fallback, the app name is matched against vendor and product names.
Vendor categories
Vendors describe themselves in thousands of different ways (“AI”, “Artificial Intelligence”, “Generative AI”, “Enterprise AI”…). To make the catalog filterable, Synk.to normalizes these free-form descriptions into a two-level controlled taxonomy:- Primary category — exactly one broad sector per vendor (for example, Security & Compliance). This is what you see in the Category column and filter.
- Categories (tags) — one or more specific tags from a controlled vocabulary of about 100 tags (for example, IAM, Security). Each tag belongs to exactly one sector.
Sectors and example tags
Information gathered on each vendor
Each vendor record is built from public sources — the vendor’s website, trust center, security and legal pages, and company databases. It is grouped into four areas.Company
Company
- Description — what the company and its products do
- Primary category and other categories
- Website
- Founded — founding year
- Country — headquarters country, used for the jurisdiction tier
- Employees — employee size range
- Ownership — public, private, or acquired
- Products — the products the vendor ships, each with its own OAuth app IDs
- Investment stage and total funding
Compliance
Compliance
- Certifications — SOC 2 (with report type), ISO 27001, ISO 27701, ISO 42001, FedRAMP (with impact level), HIPAA, PCI DSS, CSA STAR, HITRUST, and other listed frameworks
- Privacy policy
- Data Processing Agreement (DPA)
- Trust center
- Subprocessor list
- Status page
- Bug bounty page
- Data residency options
Security
Security
- SSO / SAML support
- SCIM provisioning support
- SSO tier — which plan SSO is available on
- Pentest cadence — how often independent penetration tests are performed
- Bug bounty program
- SLA uptime commitment
Scores & rationale
Scores & rationale
- Compliance score and Stability score — the sub-scores feeding the vendor risk rating
- Rationale — the key drivers behind the vendor’s rating
- Vendor risk — the final Very Low to Critical rating, see Vendor Risk Assessment Methodology
Where to find vendor information
Open any system on the Discovered systems page:- The vendor summary at the top shows the website, employee count, country, founding year, category pills (primary category first), and certifications.
- The Details button opens the full vendor profile with the Company, Compliance, Security, and Scores & rationale sections described above.
Vendor data is collected from public sources and refreshed periodically, so treat it as a triage signal rather than an audit conclusion. A vendor whose trust center we couldn’t find may look weaker than its true posture. If you spot outdated or incorrect vendor information, let us know at support@synk.to.