Risk tiers
What the rating is based on
The rating combines three factors. Compliance posture carries the most weight, followed by company stability and jurisdiction.1
Compliance posture
The vendor’s security attestations and controls: SOC 2 (and whether it’s Type II), ISO 27001, 27701, and 42001, FedRAMP, HIPAA, PCI DSS, CSA STAR, and HITRUST, plus SSO/SAML and SCIM support, penetration testing cadence, a public trust center, privacy policy, DPA, subprocessor list, data residency options, SLA, status page, and bug bounty program.
2
Company stability
How likely the vendor is to be around — and properly resourced — for as long as you depend on it: employee count (the strongest signal), public or acquired status, funding stage and total funding, and company age.
3
Jurisdiction
The legal environment the vendor operates in, based on its headquarters country:
- Tier A (low risk) — United States, Canada, United Kingdom, EU and EEA countries (including Iceland, Liechtenstein, and Norway), Switzerland, Australia, New Zealand, Japan, Singapore, South Korea, and Israel.
- Tier B (medium risk) — all other countries, and vendors whose country is unknown.
- Tier C (high risk) — China, Russia, Hong Kong, Belarus, Iran, North Korea, Syria, and Venezuela.
Override rules
A few unambiguous cases override the combined score:- Hyperscaler class → Very Low. A public company with SOC 2 and ISO 27001 and 5,000+ employees is rated Very Low.
- Public and certified → Low at most. A public company with SOC 2 and ISO 27001 is never rated above Low.
- No certifications → High at least. A vendor with no listed certifications or compliance frameworks is never rated below High, however large or well-known it is.
- No certifications, tiny team, riskier jurisdiction → Critical. A vendor with no listed certifications, 10 or fewer employees, and a Tier B or Tier C jurisdiction is rated Critical.
- High-risk jurisdiction → Medium at least. A Tier C vendor is never rated below Medium. This rule applies last and overrides all the others.
Missing company data is treated as neutral, not as the worst case — an unknown employee count or country doesn’t push a vendor to Critical on its own. A complete absence of compliance evidence, however, is treated as a genuine red flag, because that’s exactly what vendor triage is meant to catch.
How vendor risk is used
- Final app risk — every discovered app’s final risk is the higher of its vendor risk and its OAuth scope risk. Hover over a Risk badge to see both.
- Filters — use the Vendor risk filter on the Systems and Discovered systems pages to find every app built by High or Critical risk vendors.
- Weekly digest — risky authorizations to apps from unknown or high-risk vendors are listed in their own section, so you can review them first.
- Vendor details — open Details on any discovered system to see the vendor’s compliance and stability scores and the rationale behind its rating.