aCyberSec Logo
Back to tools

ACyberSec Vendor Risk Scorecard

Assess third-party cybersecurity, privacy, AI, cloud, and software supply-chain risks before approving a vendor.

Privacy note: This tool runs locally in your browser for the MVP version. Do not enter confidential contracts, credentials, secrets, regulated data, or private customer data.

1. Vendor Information

Criticality

2. Data Access

What type of data will the vendor access?

3. System Access

What level of system access will the vendor have?

4. Security Controls

Which security controls does the vendor provide?

5. AI Risk

Does the vendor use AI or machine learning?

Does the vendor train models on customer data?

Can the customer opt out of model training?

Does the vendor store prompts, documents, or uploaded files?

Does the vendor provide data deletion controls?

Does the vendor use subcontractors or third-party model providers?

Does the vendor provide enterprise privacy controls?

6. Software Supply Chain Risk

Does the vendor provide software, code, SDKs, APIs, packages, or integrations?

Does the vendor provide SBOM documentation?

Does the vendor disclose known vulnerabilities?

Does the vendor have a patch management process?

Does the vendor sign software releases?

Does the vendor use secure development practices?

7. Compliance and Legal

Disclaimer: This tool provides a basic educational risk assessment and does not replace a formal vendor security review, legal review, compliance review, or professional cybersecurity assessment.