Sentrix

Platform · Third-party risk

Know your vendor risk before your auditor does.

Sentrix gives you continuous visibility into every vendor's risk posture, not a point-in-time questionnaire that is already stale the day after you send it.

Vendor onboarding

From vendor email to scored dossier.

Send an automated security questionnaire, pull in the vendor's existing certifications, and map their posture to your internal risk taxonomy, without a single spreadsheet or back-and-forth email chain.

  • Automated questionnaire dispatch with smart follow-up reminders
  • Auto-import of SOC 2, ISO 27001, and CAIQ reports from vendor portals
  • Risk scoring based on criticality, data access, and control coverage
  • Vendor-facing portal so suppliers can update their posture directly

Risk scores refresh continuously, not quarterly when someone remembers to ask.

Continuous monitoring

Drift alerts before they become audit findings or incidents.

Vendor risk is not static. Sentrix monitors every vendor's compliance posture continuously and alerts you the moment their certifications lapse, their security policies drift, or new vulnerabilities surface in their stack.

  • Automatic alerts when vendor SOC 2, ISO 27001 or PCI certifications expire or lapse
  • Continuous monitoring of vendor security news and breach disclosures
  • Escalation workflows with configurable SLA timers and owner assignments
  • Audit-ready vendor risk dossiers exportable in one click for your assessors

Everything your vendor risk program needs. Nothing it does not.

Automated questionnaires

SIG Lite, CAIQ, NIST and custom questionnaires dispatched automatically with intelligent follow-up. Vendors complete online, no PDFs, no email chains.

Risk-tiered onboarding

Classify vendors by criticality and data access type. Critical suppliers get deeper scrutiny; low-risk SaaS tools get streamlined lightweight reviews.

Continuous certification tracking

Track SOC 2, ISO 27001, PCI and HIPAA certifications across your entire vendor portfolio. Automated renewal reminders 60 and 30 days before expiry.

Concentration risk

Surface single points of failure in your vendor ecosystem. Required for DORA, NIS2 and financial regulator examinations of ICT third-party dependencies.

Remediation workflows

Assign remediation tasks to internal owners and external vendors with tracked deadlines, escalation paths and audit-ready completion evidence.

Board-ready reporting

Vendor risk posture summaries, heat maps and trend reports formatted for board risk committees and regulator examinations, generated in one click.

See your vendor risk posture in real time.

We map your critical vendors during the demo and show you risk scores before the call ends.

Contact us

Frequently asked questions

What questionnaires does Sentrix support for vendor assessments?
SIG Lite, CAIQ, NIST and custom questionnaires are dispatched automatically with intelligent follow-up reminders. Vendors complete them online, no PDFs, no email chains. Sentrix also pulls in the vendor's existing SOC 2, ISO 27001 and CAIQ reports from vendor portals, and a vendor-facing portal lets suppliers update their posture directly.
How does Sentrix score vendor risk?
Vendors are classified by criticality and data access type, then scored based on that criticality, their data access, and their control coverage. Critical suppliers get deeper scrutiny; low-risk SaaS tools get streamlined, lightweight reviews. Scores refresh continuously rather than quarterly, so the register reflects the vendor's current posture.
How does Sentrix monitor vendors after onboarding?
Vendor risk is not static, so Sentrix monitors every vendor's compliance posture continuously and alerts you the moment their certifications lapse, their security policies drift, or new vulnerabilities surface in their stack. Escalation workflows carry configurable SLA timers and owner assignments, and vendor risk dossiers export in one click for your assessors.
Can Sentrix track vendor certifications like SOC 2 and ISO 27001?
Yes. Sentrix tracks SOC 2, ISO 27001, PCI and HIPAA certifications across your entire vendor portfolio, with automated renewal reminders 60 and 30 days before expiry. Automatic alerts fire when a vendor's SOC 2, ISO 27001 or PCI certification expires or lapses, so a lapsed report becomes a tracked task instead of an audit finding.
Does Sentrix support concentration risk requirements like DORA or NIS2?
Yes. Sentrix surfaces single points of failure in your vendor ecosystem, which is required for DORA, NIS2 and financial regulator examinations of ICT third-party dependencies. Vendor risk posture summaries, heat maps and trend reports are formatted for board risk committees and regulator examinations and generated in one click.

Let's talk about your compliance program.

Last updated: 2026-09-17