Security playbook · AI Employee: Sig

Vendor Security Review

Vendor risk decisions in 5 days, not 5 weeks

The problem

Every new vendor triggers a security review that takes 6-12 weeks. The security team requests SOC 2 reports, DPAs, pen-test summaries, questionnaires; the vendor's security team responds in batches; the reviewer reads a 200-page report to find the same 15 things they check every time. Meanwhile the business owner is blocked, the vendor is losing deal momentum, and the review queue grows. Vendors approved fast enough are the ones nobody actually reviewed.

At a glance
Trigger
Form
Approvals
Security approval before contract
What it does
Writes to your systems
Systems
Vanta · Drata · Ironclad
How it feels in production

An hour-by-hour walkthrough.

New vendor request from procurement: Acme Analytics, data-processing tool, will hold PII. Sig picks up the request and immediately gathers what's already public: their trust page, their SOC 2 report from a shared trust portal (WhistleIC, SafeBase, Vanta trust), their status page, their security disclosures. For each of the standard review dimensions — data handling, encryption, access control, incident history, subprocessors, breach history, insurance, jurisdictional posture — Sig extracts the answer from the available material with a citation. Where the material is silent or ambiguous, Sig drafts a minimal questionnaire (only the unresolved items, not the standard 200-question form) and sends it to the vendor with clear expected answers. Sig runs the vendor's domain through external signal collection: Have I Been Pwned, Shodan, cert transparency logs, breach databases. Cross-checks stated posture against observed reality — vendor claims all TLS 1.3, cert transparency shows a wildcard cert covering *.dev.acme.com with weak ciphers. Draft review packet lands in the security reviewer's queue: (1) risk score with the drivers, (2) answered dimensions with sources, (3) open questions with vendor's answers if received, (4) discrepancies between claimed and observed. Reviewer approves, requests more info, or declines — usually in 20-40 minutes rather than 6 weeks.
How it works

Step by step.

  1. 01

    Pull public material + trust portal contents

    Vendor's trust page, public SOC 2 (via shared trust portals), status page, security disclosures, published subprocessor list. Skip re-requesting what's already public.

    Trust portals · Web scraping · Cert transparency
  2. 02

    Extract answers to standard dimensions with citations

    Data handling, encryption at rest + in transit, access control, incident response, subprocessors, breach history, insurance, jurisdictional posture, sub-processor chain. Every extracted answer cites the source paragraph.

    Document parsing · Reasoning · Dimension model
  3. 03

    Draft minimal questionnaire for unresolved items

    Not a 200-question form — only the dimensions where the public material was silent or ambiguous. Vendor sees 15-30 targeted questions with clear expected answers; response time drops.

    Email · Portal · Questionnaire generator
  4. 04

    Run external-signal collection + discrepancy check

    Domain against breach databases, cert transparency, Shodan, vulnerability databases. Cross-check stated posture vs. observed. A vendor claiming TLS 1.3 with weak-cipher production endpoints is a discrepancy worth surfacing.

    HIBP · Shodan · Cert transparency · Vuln databases
  5. 05

    Assemble review packet + route for decision

    Review packet: risk score, answered dimensions with citations, open questions, discrepancies, recommended conditions (e.g. "approve subject to DPA signature"). Reviewer approves, declines, or requests more.

    Web UI · Slack · Approval flow · Vendor management system
Systems and wiring

What you connect to make this run.

SafeBase · WhistleIC · Vanta Trust

read

Shared trust portals expose SOC 2, ISO 27001, subprocessor lists, security posture. Sig reads these instead of requesting the same reports vendors publish publicly.

Vendor management system · Coupa · Ironclad

read+write

Read vendor intake requests + attached procurement context. Write completed review packets + risk scores + approval status back to the vendor record. Feeds procurement + legal downstream.

HIBP · Shodan · Cert transparency · CVE feeds

read

External-signal collection. Discrepancies between stated posture and observed reality are the single strongest signal for a targeted follow-up.

Email · Vendor portals

write

Send targeted questionnaires (not standard forms). Track responses + auto-nudge. Package responses into the review packet on receipt.

What changes

Before and after, honestly.

Time from vendor request to review complete
Before
6-12 weeks
After
3-7 business days
Reviewer hours per vendor
Before
8-20 hours
After
30-60 minutes
% of vendors reviewed to policy standard
Before
40-60% (rest fast-tracked without review)
After
95%+ (fast enough that no fast-track needed)
Deal cycle delays attributable to security review
Before
20-40% of enterprise deals
After
Under 5%
Frequently asked

Answers about this playbook.

What if the vendor refuses to share their SOC 2 under NDA?

Sig flags this as a signal — refusing to share is common at smaller vendors but noteworthy at any vendor claiming SOC 2 attestation. Reviewer can accept an alternative (attestation letter, summary), require NDA-gated share, or escalate.

How does it handle re-reviews (annual renewals)?

Re-reviews compare the current state against the previous review. Changes in subprocessors, incident history, or posture surface as focused-review items. Same-as-last-year renewals close in minutes.

Can the risk score be customised per data class?

Yes — vendors handling PII, PCI, PHI, or source code have different weighting. A vendor with weak access control is low-risk for a marketing analytics tool, high-risk for a data-processing tool.

What about open-source dependencies (not a vendor per se)?

Different playbook — dependency review runs in CI + Snyk / Dependabot. This playbook is for commercial vendors with a contract and a data-handling relationship.

How does it feed into contract terms?

The review packet flags required contract terms: DPA signature, notification-of-incident SLA, indemnification for breaches, right-to-audit. Legal picks these up in contract negotiation.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.