vendor-risk-management

(9)
Company
Strike Graph Wants to Turn Your Next Security Audit From a Fire Drill Into a Background Task
Saas · Enterprise · Ai

Strike Graph Wants to Turn Your Next Security Audit From a Fire Drill Into a Background Task

The Seattle startup began with one founder's bruising SOC 2 experience. Six years and $20.4 million later, it is betting that graph-based data and small, private AI models can make compliance useful between audits - not merely survivable during them.

compliance-automation · grcRead →
Company
The Company That Made Audit Season Boring
Saas · Ai · Enterprise

The Company That Made Audit Season Boring

Meiran Galis spent years at EY watching startups treat security audits like a fire drill. Scytale is his bet that compliance can run in the background instead of eating a quarter.

soc-2 · iso-27001Read →
Company
Black Kite
Saas · Ai · Enterprise

Black Kite

Black Kite is a Boston-based cybersecurity company that rates and monitors the cyber risk posed by an organization's third-party vendors and supply chain. Built from a hacker's perspective, its platform combines non-intrusive external assessments, ransomware-likelihood scoring, standards-based compliance mapping, and Open FAIR financial-impact modeling so risk teams can see, quantify, and act on the exposure hiding inside their vendor ecosystem.

third-party-cyber-risk · tprmRead →
Company
Compyl
Saas · Ai · Enterprise

Compyl

Compyl is a New York-based SaaS company that unifies governance, risk, and compliance (GRC) on a single platform. Founded in 2020 by former CISOs, it pulls evidence directly from more than 125 integrated systems, maps controls across 70+ frameworks like SOC 2, ISO 27001 and HIPAA, and uses agentic AI to draft evidence, score vendors and answer security questionnaires while keeping humans in control of decisions. Compyl raised a $12M Series A in June 2025 to scale its AI-led platform for mid-market and enterprise security teams.

grc · governance-risk-complianceRead →
Company
Rescana
Ai · Saas · Enterprise

Rescana

Rescana is a cybersecurity company that builds autonomous, AI-agent-driven third-party risk management (TPRM) and external attack surface management software. Its platform discovers, classifies, assesses, monitors, and helps remediate risk across a company's vendor ecosystem - including vendors with no web presence - using agentic AI and open-source intelligence (OSINT). Founded by Guy Halfon and based between New York and Tel Aviv, Rescana targets regulated, vendor-heavy industries such as banking, telecom, healthcare, real estate and government, promising vendor-risk oversight that scales without a proportional increase in security headcount.

cybersecurity · third-party-risk-managementRead →
Company
Osano
Saas · Enterprise · Developer Tools

Osano

Osano is an Austin-based data privacy platform that helps companies comply with GDPR, CCPA, and 95+ global privacy laws through consent management, cookie banners, subject rights automation, data mapping, vendor risk monitoring, and privacy assessments. Founded in 2018, it is the first data privacy platform certified as a B Corporation and backs its software with an industry-only 'No Fines, No Penalties' guarantee. Osano processes over a billion consents a month for thousands of companies.

data-privacy · consent-managementRead →
Company
Clearly AI
Ai · Saas · Enterprise

Clearly AI

Clearly AI is a Seattle-based, Y Combinator-backed startup that automates security and privacy reviews for regulated enterprises. Its AI-native platform gathers context, assesses risk, and flags where human review is actually needed - so security, privacy, and compliance teams can clear their review backlogs and ship products faster without sacrificing trust. Founded in 2024 by former Amazon security engineers Emily and Joe Choi-Greene, the company raised an $8.4M seed round in February 2026 and counts Fortune 500 brands like Ericsson, Rivian, and HID Global among its customers.

clearly-ai · security-review-automationRead →
Company
RiskOpsAI
Ai · Saas · Enterprise

RiskOpsAI

RiskOpsAI (formerly OptimEyes AI) is an AI/ML-driven integrated risk modeling and decisioning platform that helps Fortune 2000 and Global 500 organizations discover, measure, prioritize, predict and optimize cyber risk, data privacy, third-party threat exposure and regulatory compliance. Its patented, AI-native risk quantification aggregates data from multiple risk sources into a single source of truth, giving CXOs a near real-time, transparent view of enterprise-wide risk and the actions to remediate it.

ai-risk-management · grc-platformRead →
Company
Manifest
Enterprise · Saas · Ai

Manifest

Manifest is a software and AI supply chain security platform built to answer a deceptively simple question: what is actually inside the software and AI you build and buy? Founded by national security veterans from Palantir and the Pentagon, the company turns Software Bills of Materials (SBOMs) and AI Bills of Materials (AIBOMs) from compliance paperwork into a living risk inventory - generating, importing, enriching and monitoring component data so security teams can find vulnerabilities, track open-source and vendor risk, and prove compliance. Manifest serves mission-critical organizations across defense, government, automotive, medical devices, financial services and healthcare, and counts customers such as the U.S. Air Force and the Department of Homeland Security.

sbom · aibomRead →