📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Vendor risk management with the homework already done

The compliance facts for 175+ common apps are already in the record. For everyone else, the questionnaire goes out in a click.

Third-party risk is mostly a research problem. Before you can record that a vendor is safe to use, someone has to find their trust centre, confirm the SOC 2 report is current, check whether they hold ISO 27001, read the data-processing agreement, and list the subprocessors. For your ten most common vendors, that information is public and it is the same for every customer who looks it up. Doing that lookup yourself, per vendor, per year, is wasted motion.

It starts filled, for 175+ vendors

Lavawall® ships with the compliance information already populated for more than 175 of the most common SaaS products, Microsoft 365 apps, and Google Workspace apps. When one of them is in your stack, its record is not a blank form.

Already in the recordSo you don't have to
SOC 2, ISO 27001, PCI DSSHunt for the report or certificate and confirm the vendor holds it.
HIPAA, GDPR, FedRAMPWork out whether the vendor meets the regime your obligation cares about.
Data-processing agreementFind the DPA and check it exists before you sign.
SubprocessorsChase down who the vendor hands your data to in turn.
Trust-centre linkSearch for the page where the vendor publishes all of the above, so you can verify the current position in one click.

For what isn't public, send the questionnaire

The library covers the common vendors. For the ones it does not, or when you need a vendor to attest to something in writing, Lavawall sends a compliance attestation questionnaire to the vendor automatically and tracks the response in the same place as everything else. Your effort goes to the handful of vendors that genuinely need a conversation, instead of being spread thin across all of them.

Part of the wider GRC platform

Vendor records do not sit in a silo. They feed the vendor and supply-chain controls in your framework mappings, so the work you do here counts as evidence toward the frameworks you carry. For an MSP, each client is its own tenant with its own vendor list, managed from one console. See the lighter vendor inventory for how the list builds itself, and Lavawall GRC for the platform around it.

The pre-filled information is a researched starting point that removes the lookup. For a formal risk decision, confirm the current certificate or report against the vendor's own trust centre, which each record links to.

Frequently asked

Which vendors come pre-filled?
More than 175 of the most common SaaS products, Microsoft 365 apps, and Google Workspace apps arrive with their compliance information already populated: SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR, FedRAMP, data-processing agreements, subprocessors, and trust-centre links. You start from a filled record instead of an empty one.
What about vendors that are not in the library?
For any vendor, you can send a compliance attestation questionnaire in a click and track the response in the same place. The library covers the common ones so your effort goes to the vendors that actually need a conversation.
Is the pre-filled information something I can rely on for an audit?
Treat it as a well-researched starting point that saves you the hunt. For a formal risk decision you confirm the current certificate or report against the vendor's own trust centre, which the record links to. The point is to remove the digging, not your judgment.

Data residency: We place your data and our AI processing in the region your obligations require: Canada, the United States, Europe, or Australia. How data residency works →