Synced 16 Jun 2026 15:24 UTC Account
← Home

Vendor security assessment

A free vendor security & third-party risk assessment for any product you’re evaluating. Capture the vendor’s security, compliance and operations answers in one structured questionnaire — and see IsItPatched’s independently-verified vulnerability data right alongside. Two data origins, never blended. Browser-first, no login to start.

What are you assessing?

Independently checked by IsItPatchedSourced from NVD · CISA KEV · EPSS · endoflife.date — not the vendor’s claim, and not editable.

Pick a tracked product above to load its verified vulnerability, exploitation and end-of-life data.

Self-reported — entered by youNot verified by IsItPatched. These are the vendor’s stated answers, recorded by you.

Security

Single sign-on (SSO / SAML / OIDC)Centralises authentication so access is granted, revoked and audited in one place — and killed instantly when someone leaves.
Multi-factor authentication (MFA)Blocks the credential-stuffing and phishing attacks behind most account takeovers, even after a password leaks.
Role-based access control (RBAC)Limits each user to what their role needs, containing the blast radius if an account is compromised.
Audit logsLet you reconstruct who did what after an incident — and spot misuse before one.
Encryption at restProtects stored data if disks, backups or a database are stolen or exposed.
Encryption in transitStops data being intercepted between you and the vendor, and between their internal services.
Documented incident-response planA tested plan is the difference between a contained incident and a chaotic breach.
Penetration test in the last 12 monthsIndependent testing finds exploitable issues that internal reviews miss.

Compliance · Held? Add scope / expiry in the note.

ISO/IEC 27001Independent certification that the vendor runs a managed information-security program (ISMS).
SOC 2 (Type I / II)An independent auditor's report on security controls — Type II covers how they operated over time, not just one day.
GDPRGoverns how EU/UK personal data is handled — relevant if any personal data flows through the product.
Cyber Essentials / PlusA UK baseline certification covering five core technical controls — often required for public-sector work.
PCI-DSSRequired if the product stores, processes or transmits payment-card data.
HIPAARequired if the product touches US protected health information (PHI).

Operations

SLA availableA committed uptime/response target you can hold them to — and a basis for credits if missed.
Public status pageTransparent, real-time visibility into outages and incidents without raising a ticket.
Disaster recovery (DR) documentedShows they can recover the service after a major failure — and how long that takes (RTO/RPO).
Backup strategy documentedDetermines whether your data can be restored after corruption, deletion or ransomware.
Data residency optionsControls which country/region your data is stored in — often a legal or contractual requirement.
Sub-processor list availableReveals the third parties that can access your data — your risk extends to their supply chain.

Your work auto-saves as a draft on this device. Sign in to save it to your vendor assessments, keep it across devices, and export a clean report.

How it works

Does IsItPatched verify the vendor’s answers?

No. The questionnaire is self-reported — entered by you (or, on Pro, by the vendor). IsItPatched never asserts a vendor’s certifications, controls or breaches as its own claim. It independently verifies only the software-composition layer (known vulnerabilities, active exploitation and end-of-life) from public sources, and keeps that strictly separate from the self-reported answers.

What does the verified section come from?

The IsItPatched-verified section is sourced from NVD (CVE severity), CISA KEV (active exploitation), FIRST EPSS (exploitation probability) and endoflife.date (support status). It only appears for products we already track; it is never editable.

Do I need an account?

No — you can create and fill an assessment with no login, and your work is auto-saved as a draft on this device. Signing in lets you save it to your vendor assessments, keep it across devices and export a clean report.

Is there a single combined score?

No, deliberately. Blending self-reported answers with IsItPatched-verified data would launder unverified claims into a trusted number. The verified health score stands alone, scoped to software composition; the questionnaire stands alone as self-reported.

Self-reported fields are entered by the user and are not verified by IsItPatched. Verified fields are sourced from public vulnerability data (NVD, CISA KEV, EPSS, endoflife.date). IsItPatched is independent and not affiliated with those bodies, and this tool does not constitute a security audit or legal advice. See our disclaimer.