> ## Documentation Index
> Fetch the complete documentation index at: https://docs.synk.to/llms.txt
> Use this file to discover all available pages before exploring further.

# Vendor Risk Assessment Methodology

> How Synk.to rates every SaaS vendor from Very Low to Critical risk based on compliance posture, company stability, and jurisdiction.

Knowing that an app is connected to your Google Workspace is only half the picture. The other half is whether the **company behind the app** can be trusted with your data. Synk.to answers that with a **vendor risk rating** for every vendor in its [catalog](/getting-started/saas-vendor-categories).

The rating answers a single triage question: **how risky is it to rely on this vendor, based on its security and compliance posture, company stability, and jurisdiction?**

## Risk tiers

| Tier                                  | Plain meaning               | Typical profile                                                              |
| ------------------------------------- | --------------------------- | ---------------------------------------------------------------------------- |
| <Badge color="green">Very Low</Badge> | Trust by default            | Mature vendor with strong attestations (SOC 2, ISO 27001), large or public   |
| <Badge color="green">Low</Badge>      | Safe with light review      | Solid certifications, established but not at hyperscaler scale               |
| <Badge color="yellow">Medium</Badge>  | Review before relying       | Partial certifications, or a strong company with thin security evidence      |
| <Badge color="red">High</Badge>       | Diligence required          | No listed certifications, or small and early-stage with weak signals         |
| <Badge color="red">Critical</Badge>   | Avoid or run deep diligence | No compliance evidence, a tiny team, and a medium- or high-risk jurisdiction |

## What the rating is based on

The rating combines three factors. **Compliance posture carries the most weight**, followed by company stability and jurisdiction.

<Steps>
  <Step title="Compliance posture">
    The vendor's security attestations and controls: SOC 2 (and whether it's Type II), ISO 27001, 27701, and 42001, FedRAMP, HIPAA, PCI DSS, CSA STAR, and HITRUST, plus SSO/SAML and SCIM support, penetration testing cadence, a public trust center, privacy policy, DPA, subprocessor list, data residency options, SLA, status page, and bug bounty program.
  </Step>

  <Step title="Company stability">
    How likely the vendor is to be around — and properly resourced — for as long as you depend on it: employee count (the strongest signal), public or acquired status, funding stage and total funding, and company age.
  </Step>

  <Step title="Jurisdiction">
    The legal environment the vendor operates in, based on its headquarters country:

    * **Tier A (low risk)** — United States, Canada, United Kingdom, EU and EEA countries (including Iceland, Liechtenstein, and Norway), Switzerland, Australia, New Zealand, Japan, Singapore, South Korea, and Israel.
    * **Tier B (medium risk)** — all other countries, and vendors whose country is unknown.
    * **Tier C (high risk)** — China, Russia, Hong Kong, Belarus, Iran, North Korea, Syria, and Venezuela.
  </Step>
</Steps>

## Override rules

A few unambiguous cases override the combined score:

* **Hyperscaler class → Very Low.** A public company with SOC 2 and ISO 27001 and 5,000+ employees is rated Very Low.
* **Public and certified → Low at most.** A public company with SOC 2 and ISO 27001 is never rated above Low.
* **No certifications → High at least.** A vendor with no listed certifications or compliance frameworks is never rated below High, however large or well-known it is.
* **No certifications, tiny team, riskier jurisdiction → Critical.** A vendor with no listed certifications, 10 or fewer employees, and a Tier B or Tier C jurisdiction is rated Critical.
* **High-risk jurisdiction → Medium at least.** A Tier C vendor is never rated below Medium. This rule applies last and overrides all the others.

<Note>
  Missing company data is treated as **neutral**, not as the worst case — an unknown employee count or country doesn't push a vendor to Critical on its own. A complete **absence of compliance evidence**, however, is treated as a genuine red flag, because that's exactly what vendor triage is meant to catch.
</Note>

## How vendor risk is used

* **Final app risk** — every discovered app's final risk is the **higher** of its vendor risk and its [OAuth scope risk](/getting-started/gws-oauth-scope-risk). Hover over a **Risk** badge to see both.
* **Filters** — use the **Vendor risk** filter on the Systems and Discovered systems pages to find every app built by High or Critical risk vendors.
* **Weekly digest** — risky authorizations to apps from unknown or high-risk vendors are listed in their own section, so you can review them first.
* **Vendor details** — open **Details** on any discovered system to see the vendor's compliance and stability scores and the rationale behind its rating.

<Tip>
  The vendor rating is a triage signal based on publicly available information, not an audit conclusion. A vendor rated High may simply not publish its certifications — ask the vendor for its SOC 2 report or security documentation, and let us know at [support@synk.to](mailto:support@synk.to) if a record should be updated.
</Tip>
