A vendor reports a data breach. Somewhere upstream, a security team must decide whether its own company is exposed. The awkward question is rarely whether the supplier has a handsome security policy. It is whether anyone can find the supplier’s records quickly enough to make a decision.
In an account published by Findings, an unnamed enterprise had already documented the vendor in its risk system. Its team assessed the exposure in 15 minutes and determined that no additional action was required. Findings said the same exercise without those records would have taken days. An anonymous company account is a modest piece of evidence. It does, however, explain the business rather better than another promise about artificial intelligence.
Findings sells software for third-party risk management: the unglamorous work of assessing suppliers, collecting proof, tracking weaknesses and following up. Its premise is that a company’s security extends beyond the systems it owns. The supplier spreadsheet deserves the same attention as the firewall.
- Automates vendor assessments and follow-up.
- Lets suppliers share evidence with permission.
- Adds connected cloud monitoring to written answers.
Two people, one very crowded inbox
Founded in 2018 by CEO Kobi Freedman and CTO Jonatan Perry, Findings began with cybersecurity automation and expanded into sustainability and compliance. Freedman’s background spans security and enterprise risk; Perry’s work centres on cloud security and the machinery of automated assessment. The company’s stated values include trust, visibility and efficiency. Those are useful aspirations in a business whose raw material is other people’s assurances.
The distinctive choice is to serve both participants in an assessment. Buyers need credible answers. Suppliers need to stop answering versions of the same questions for every customer. PowerVRM handles assessments, evidence analysis, tasks and risk workflows. Trust Exchange provides a consent-based way to share verified assessment information across customer relationships.
That changes the economics of repetition. A reusable answer can save work for the vendor and the buyer, provided the evidence is current and relevant to the next request. Findings treats supplier participation as part of the product. Anyone who has watched a questionnaire disappear into an inbox will appreciate the distinction.
KOBI FREEDMAN / CEO
JONATAN PERRY / CTOA questionnaire cannot watch a cloud
CloudVRM adds a different kind of evidence. Findings describes secure, read-only integrations that collect configuration and control information from vendor cloud environments. Instead of waiting for the next questionnaire, a team can examine information about access controls, encryption and logging, mapped to its compliance frameworks.
AssessmentAI, announced in 2023, addressed the paperwork from both ends. For suppliers, it offered explanations and suggested responses in multiple languages. For buyers, the announced capabilities included evidence review, gap analysis and risk-reduction plans. The current AiVRM offering extends the company’s cloud approach to exposure associated with AI-assisted development and vendor AI use.
The market includes UpGuard, Bitsight and SecurityScorecard, as well as compliance platforms with vendor-risk features. Findings stakes its position on connected cloud evidence, reusable assessments and workflow automation. That is a product proposition, rather than proof that every competing system misses every risk. Buyers should compare the actual evidence each tool can obtain from their particular suppliers.
- 01CollectAssessments + connected cloud controls
- 02CheckReview evidence + identify gaps
- 03ActAssign fixes + keep monitoring
“You can’t reduce risk without seeing it.”
Findings / its stated visibility principle
The buyers have suppliers of their own
Findings targets enterprises with complicated supplier networks, especially financial services, defence and critical infrastructure. Its July 2026 company presentation names example customers including Micron, FIBI, NEC, SL Green and the Johannesburg Stock Exchange. The names indicate its intended enterprise setting; the presentation does not establish the size or terms of each account.
The sustainability expansion followed customer demand. In its December 2021 launch announcement, Findings said customers wanted ESG practices within the platform. It introduced industry benchmarking and reporting for companies, asset owners, asset managers and vendors. Cybersecurity and sustainability share a practical nuisance: both require information from organisations outside the buyer’s direct control.
Partnerships extend that reach. Findings announced a documentation-verification partnership with Billon in January 2023 and a supply-chain security and compliance collaboration with IBM Federal in January 2024. The former concerned recording and validating compliance documents; the latter targeted government organisations and critical domains. Announced partnerships should be read as arrangements with a purpose, rather than receipts for customer results.

A price tag, then a deal that stopped
The business model is B2B software as a service, with enterprise quotes and a free entry tier described on its website. One concrete price appears in AWS Marketplace: the Findings.co MSCRM offering lists a 12-month contract for up to 10 reviews at $10,710, or up to 100 reviews at $92,856. These are prices for that specific managed offering, not a universal Findings tariff. A 30-day trial for up to 10 reviews is listed at zero dollars.
In August 2025, Diginex signed a non-binding acquisition memorandum with a headline consideration of up to $305 million. Most of it was shares; part of the cash depended on performance. By December, Diginex said diligence and agreement drafting had paused because of insufficient substantive progress.
In July 2026, Globes reported that Findings was pursuing a merger into Wilk, a Tel Aviv-listed shell formerly involved in cultured milk. The proposed route was a striking change of vehicle. Findings’ July presentation reported $9 million in annual recurring revenue. That is a company-reported run rate, not audited annual sales or evidence that either transaction closed.
Up to 10 reviews in the AWS Marketplace MSCRM listing. Scope matters; this is one offering.
Keep the evidence. Assign the decision.
The useful lesson is small enough to copy without buying software: keep a live supplier inventory, make evidence reusable, and give someone responsibility for acting when a control changes. Findings’ own monitoring guidance recommends beginning with high-risk vendors and building alerts that lead to action.
Connected monitoring still depends on suppliers agreeing to the necessary access. Shared assessments depend on compatible requirements and permission to reuse the information. Neither a cloud configuration nor an AI-drafted answer settles every question about a supplier’s conduct. A team that collects alerts without assigning an owner merely acquires a more expensive inbox.
Findings is most interesting where it reduces the distance between an assertion and a decision. The buyer gets evidence. The supplier gets fewer repeated requests. And when the next breach notice arrives, somebody has a place to start looking.