> ## Documentation Index
> Fetch the complete documentation index at: https://docs.synk.to/llms.txt
> Use this file to discover all available pages before exploring further.

# SaaS Vendor Categories

> How Synk.to categorizes SaaS vendors into sectors and tags, and which company, compliance, and security data it gathers on every vendor in its catalog.

Every OAuth app Synk.to discovers in your environment is resolved to the **vendor** behind it — the company that built the app and will hold your data. Synk.to maintains a catalog of **3,000+ SaaS vendors**, each with a normalized category and a profile covering company details, compliance posture, and security controls.

This page explains how vendors are categorized and what information Synk.to gathers on each of them. For how that information turns into a risk rating, see [Vendor Risk Assessment Methodology](/getting-started/vendor-risk-assessment).

## How a discovered app is matched to a vendor

When Synk.to discovers an OAuth app, it resolves it to a catalog vendor in the following order:

1. **Known system** — if the app is a system already in the Synk.to catalog, the vendor of that system is used.
2. **OAuth client ID** — the app's OAuth client ID is matched against the OAuth app IDs recorded for each vendor's products. This is the most reliable match, since client IDs are stable even when an app is renamed.
3. **Name** — as a fallback, the app name is matched against vendor and product names.

If no vendor can be matched, the app is still listed and scored on its OAuth scopes — see [GWS OAuth Scope Risk](/getting-started/gws-oauth-scope-risk).

## Vendor categories

Vendors describe themselves in thousands of different ways ("AI", "Artificial Intelligence", "Generative AI", "Enterprise AI"…). To make the catalog filterable, Synk.to normalizes these free-form descriptions into a two-level controlled taxonomy:

* **Primary category** — exactly one broad **sector** per vendor (for example, *Security & Compliance*). This is what you see in the **Category** column and filter.
* **Categories (tags)** — one or more specific **tags** from a controlled vocabulary of about 100 tags (for example, *IAM*, *Security*). Each tag belongs to exactly one sector.

When a vendor spans several sectors, its primary category is picked by sector priority — more specific sectors (such as *AI/ML*, *Security & Compliance*, *Finance & Accounting*) win over horizontal ones (such as *Productivity & Collaboration*). For example, Stripe carries the tags *Payments*, *FinTech*, and *Dev Tools*, and its primary category is *Finance & Accounting*.

### Sectors and example tags

| Sector                       | Example tags                                                                 |
| ---------------------------- | ---------------------------------------------------------------------------- |
| AI/ML                        | GenAI, Chatbots, AI Agents, Voice AI, Computer Vision, MLOps, AI Search      |
| Security & Compliance        | Security, IAM, GRC, Privacy, Threat Intel, Cloud Security, Fraud             |
| Healthcare                   | Healthcare, Digital Health                                                   |
| Legal                        | Legal, Contracts                                                             |
| Finance & Accounting         | Accounting, Payments, FinTech, Billing, Expenses, ERP                        |
| HR & Recruiting              | HR, Recruiting, Payroll, Engagement, Performance                             |
| E-commerce & Retail          | E-commerce, Retail, Marketplace                                              |
| Logistics & Supply Chain     | Logistics, Fleet, Procurement                                                |
| Education                    | EdTech, L\&D                                                                 |
| Sales & Marketing            | CRM, Marketing, Sales, SEO, AdTech, Email, RevOps, Lead Gen, Loyalty         |
| Customer Support & Success   | Support, Customer Success, Contact Center, CX                                |
| Design & Creative            | Design, Creative, Video                                                      |
| Vertical/Industry-Specific   | PropTech, InsurTech, Manufacturing, Construction, Travel, GovTech, Nonprofit |
| Consumer & Media             | Consumer, Media, Gaming, Music, Social Media, Creator                        |
| Data & Analytics             | Analytics, BI, ETL, Data Platform, Product Analytics, Geospatial             |
| Developer Tools & DevOps     | Dev Tools, DevOps, Observability, APIs, Low-Code, QA                         |
| Product & Project Management | Project Mgmt, Product, Automation                                            |
| IT & Cloud Infrastructure    | Cloud, IT, Networking, Database, IoT                                         |
| Communication                | Communication, Conferencing                                                  |
| Productivity & Collaboration | Productivity, Collaboration, Documents, Knowledge, Scheduling, Localization  |
| Business Software/Other      | SaaS                                                                         |

<Tip>
  Use the **Category** filter on the Systems and Discovered systems pages to answer questions like "which AI tools are connected to our Google Workspace?" or "which HR vendors hold employee data?".
</Tip>

## Information gathered on each vendor

Each vendor record is built from public sources — the vendor's website, trust center, security and legal pages, and company databases. It is grouped into four areas.

<AccordionGroup>
  <Accordion title="Company" icon="building">
    * **Description** — what the company and its products do
    * **Primary category** and **other categories**
    * **Website**
    * **Founded** — founding year
    * **Country** — headquarters country, used for the jurisdiction tier
    * **Employees** — employee size range
    * **Ownership** — public, private, or acquired
    * **Products** — the products the vendor ships, each with its own OAuth app IDs
    * **Investment stage** and **total funding**
  </Accordion>

  <Accordion title="Compliance" icon="certificate">
    * **Certifications** — SOC 2 (with report type), ISO 27001, ISO 27701, ISO 42001, FedRAMP (with impact level), HIPAA, PCI DSS, CSA STAR, HITRUST, and other listed frameworks
    * **Privacy policy**
    * **Data Processing Agreement (DPA)**
    * **Trust center**
    * **Subprocessor list**
    * **Status page**
    * **Bug bounty** page
    * **Data residency** options
  </Accordion>

  <Accordion title="Security" icon="lock">
    * **SSO / SAML** support
    * **SCIM** provisioning support
    * **SSO tier** — which plan SSO is available on
    * **Pentest cadence** — how often independent penetration tests are performed
    * **Bug bounty program**
    * **SLA uptime** commitment
  </Accordion>

  <Accordion title="Scores & rationale" icon="chart-simple">
    * **Compliance score** and **Stability score** — the sub-scores feeding the vendor risk rating
    * **Rationale** — the key drivers behind the vendor's rating
    * **Vendor risk** — the final Very Low to Critical rating, see [Vendor Risk Assessment Methodology](/getting-started/vendor-risk-assessment)
  </Accordion>
</AccordionGroup>

## Where to find vendor information

Open any system on the **Discovered systems** page:

* The **vendor summary** at the top shows the website, employee count, country, founding year, category pills (primary category first), and certifications.
* The **Details** button opens the full vendor profile with the Company, Compliance, Security, and Scores & rationale sections described above.

Fields Synk.to couldn't find are hidden rather than shown as empty.

<Note>
  Vendor data is collected from public sources and refreshed periodically, so treat it as a triage signal rather than an audit conclusion. A vendor whose trust center we couldn't find may look weaker than its true posture. If you spot outdated or incorrect vendor information, let us know at [support@synk.to](mailto:support@synk.to).
</Note>
