Third-party risk is mostly a research problem. Before you can record that a vendor is safe to use, someone has to find their trust centre, confirm the SOC 2 report is current, check whether they hold ISO 27001, read the data-processing agreement, and list the subprocessors. For your ten most common vendors, that information is public and it is the same for every customer who looks it up. Doing that lookup yourself, per vendor, per year, is wasted motion.
It starts filled, for 175+ vendors
Lavawall® ships with the compliance information already populated for more than 175 of the most common SaaS products, Microsoft 365 apps, and Google Workspace apps. When one of them is in your stack, its record is not a blank form.
| Already in the record | So you don't have to |
|---|---|
| SOC 2, ISO 27001, PCI DSS | Hunt for the report or certificate and confirm the vendor holds it. |
| HIPAA, GDPR, FedRAMP | Work out whether the vendor meets the regime your obligation cares about. |
| Data-processing agreement | Find the DPA and check it exists before you sign. |
| Subprocessors | Chase down who the vendor hands your data to in turn. |
| Trust-centre link | Search for the page where the vendor publishes all of the above, so you can verify the current position in one click. |
For what isn't public, send the questionnaire
The library covers the common vendors. For the ones it does not, or when you need a vendor to attest to something in writing, Lavawall sends a compliance attestation questionnaire to the vendor automatically and tracks the response in the same place as everything else. Your effort goes to the handful of vendors that genuinely need a conversation, instead of being spread thin across all of them.
Part of the wider GRC platform
Vendor records do not sit in a silo. They feed the vendor and supply-chain controls in your framework mappings, so the work you do here counts as evidence toward the frameworks you carry. For an MSP, each client is its own tenant with its own vendor list, managed from one console. See the lighter vendor inventory for how the list builds itself, and Lavawall GRC for the platform around it.
The pre-filled information is a researched starting point that removes the lookup. For a formal risk decision, confirm the current certificate or report against the vendor's own trust centre, which each record links to.
Frequently asked
- Which vendors come pre-filled?
- More than 175 of the most common SaaS products, Microsoft 365 apps, and Google Workspace apps arrive with their compliance information already populated: SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR, FedRAMP, data-processing agreements, subprocessors, and trust-centre links. You start from a filled record instead of an empty one.
- What about vendors that are not in the library?
- For any vendor, you can send a compliance attestation questionnaire in a click and track the response in the same place. The library covers the common ones so your effort goes to the vendors that actually need a conversation.
- Is the pre-filled information something I can rely on for an audit?
- Treat it as a well-researched starting point that saves you the hunt. For a formal risk decision you confirm the current certificate or report against the vendor's own trust centre, which the record links to. The point is to remove the digging, not your judgment.