Fair TPRM & GRC Platform — Version 2.6.2
This platform provides two integrated modules for managing your organization's security posture:
Administrators also have access to the Admin Portal for system configuration, user management, integrations, and maintenance.
Users are assigned to one or more ACL Groups that determine what they can see and do. An administrator assigns groups via → → Groups button.
| Group | What You Can Do |
|---|---|
| Administrator | Full access to everything — all modules, admin settings, user management, and system configuration |
| Cyber TPRM | Full access to the TPRM module — create/edit/delete vendors, run assessments, FAIR analysis, scoring |
| Cyber GRC | Full access to the GRC module — manage frameworks, run assessments, upload evidence, manage policies, run audits, manage risks |
| GRC Contributors | Limited GRC access — complete assigned tasks, provide evidence, answer assigned assessment questions |
| Auditor | Read-only access to both TPRM and GRC modules — can view everything, download evidence, and generate reports, but cannot create, edit, or delete |
| Procurement | Create and manage vendor onboarding requests, upload vendor documents |
| Stakeholder | View their own vendor requests and respond to tasks assigned to them |
https://tprm.yourcompany.com).
Version 2.6.2 adds several features focused on vendor onboarding, procurement collaboration, multi-language support, and shadow-SaaS discovery. If you have used an earlier version, here is what is new. Each item links to its full walkthrough later in this guide.
| New Feature | What It Does | Who It's For |
|---|---|---|
| Language settings | Use the platform in 8 languages. Each person picks their own language; admins choose which languages are available. | Everyone |
| Procurement Onboarding & Vendor ID | A vendor must be onboarded through procurement and have a valid Vendor ID (VID) before it can be submitted for cyber review. | Procurement, Stakeholders |
| AI Review for vendors | A dedicated review status for vendors whose services use AI, plus a "Force AI Review" action. | Cyber TPRM, Admins |
| Procurement Cyber Status | A live page showing vendors in review, with a running history of updates the cyber team shares with procurement, plus a weekly email digest. | Procurement, Cyber TPRM |
| Grip Shadow SaaS integration | Automatically discover SaaS apps used across your organization and pull them into the Shadow SaaS list. | Admins |
| Hero Shadow SaaS integration | An alternative Shadow SaaS provider: discover vendors and security issues from HERO Security and feed them into the same Shadow SaaS list. Grip and Hero are mutually exclusive — use one or the other. | Admins |
| Zscaler blocking | Block an unsanctioned app's web domain directly in Zscaler with one click. | Admins |
| In-app upgrades | Check your registry for a newer version and upgrade from inside the Admin Portal. | Admins |
| Phone & VAT question types | New assessment/onboarding field types: a phone number with a country-code & flag picker (auto-formatted), and an EU VAT number with double entry and free live validation against the official EU VIES service. | Everyone |
| Vendor data & search improvements | Store a VAT number on each vendor (shown on the vendor page with an "Add VAT" shortcut), find vendors by VAT number in the quick search, and a clearer Procurement-Onboarding scoring banner. | Procurement, Cyber TPRM |
| Large database backups | Backup and restore now support multi-gigabyte databases and very large records without timing out. | Admins |
| Assessment forms & AI Auto-Fill | Download an assessment as a fillable PDF or Excel workbook, import a completed file back, and — with an AI provider — auto-fill answers from the vendor's current certificates. | Cyber TPRM, Admins |
| Vendor Action Plan | Schedule follow-up actions against a vendor (contact, send assessment, force annual review) with due dates, owners, email alerts, and status notes. | Cyber TPRM, Admins |
| Custom onboarding fields & Custom Data | Capture extra, org-specific fields on a vendor with per-role visibility, edit them on the Custom Data tab, and read them in the CSV export and API. | Admins, Cyber TPRM |
| Breach / Cyber Alerts | A supply-chain breach feed (including Grip incidents) with an affected-users drill-down and bulk acknowledge / false-positive / delete. | Cyber TPRM, Admins |
| Custom access-control groups | Create your own ACL groups, clone permissions from an existing group, and set Read vs Read/Write per module. The shipped groups are protected. | Admins |
| Assessment Template Builder | New question types (multi-select, phone, VAT), template-driven certificate instructions, per-role field gating, and deactivated templates hidden by default. | Admins, Cyber TPRM |
The platform interface can be displayed in 8 languages. Every person chooses their own language — changing it only affects your screen, not anyone else's. Your choice is remembered every time you log in.
| Language | Shown in the menu as |
|---|---|
| English | English |
| Spanish | Español |
| Italian | Italiano |
| Ukrainian | Українська |
| Chinese (Simplified) | 中文(简体) |
| Hindi | हिन्दी |
| French | Français |
| Portuguese | Português |
Only the languages your administrator has turned on will appear in your list. English is always available and cannot be turned off.
Administrators decide the default language (used for brand-new users and for the sign-in page before anyone logs in) and which languages everyone is allowed to pick.
The Template Builder ( → ) gains two new question types that capture contact and tax details in a clean, consistent format. They can be used on any assessment or onboarding template, and like other questions they can be mapped to a vendor field so the answer flows onto the vendor record.
The Phone type shows a country selector with a flag and dialing code next to the number box. The United States is listed first; every other country follows in alphabetical order. Whatever format the person types — 314-444-5544, (314) 444-5544 or 3144445544 — the number is stored in one uniform international format (for example, picking the US flag and typing 3144445544 stores +13144445544). The default Vendor Onboarding Request form now uses this type for the primary contact's phone number, and the assessment attestation phone field uses it too.
The VAT type is for European VAT numbers. To guard against typos it must be entered twice, and the two entries must match before it is saved. The number is stored in a consistent form (uppercase, no spaces or punctuation — for example DE123456789).
vat_number field is available, so a VAT question mapped to it stores the value on the vendor. When you choose the VAT question type in the Template Builder, this mapping is selected for you automatically.
The vendor's VAT number is shown in the Vendor Information card on the vendor onboarding page. If no VAT is on file, an “+ Add VAT” button appears that jumps straight into edit mode with the VAT field focused.
The quick search box in the top-right of the platform now also matches on VAT number, alongside vendor name, domain, and stakeholder. Direct matches on a vendor's own name, domain, or VAT number are always shown first.
When a vendor's Procurement Onboarding status is set to No, a banner now makes clear that automated vendor scoring is disabled until the vendor completes Procurement Onboarding. It appears both on the vendor onboarding page and beneath the matching assessment question, and updates immediately as the answer changes.
When a vendor clicks Submit on an assessment, the platform now checks that every required question is answered before asking for the submitter's attestation details. Previously a missing answer was only reported after the attestation was filled in, forcing it to be re-entered.
Backup and restore ( → ) now handle multi-gigabyte databases and individual records approaching 1 GB without the operation being cut short by a timeout or running out of memory. Behind the scenes the database packet limit, network timeouts, upload size, and request time limits were all raised to accommodate very large data.
GRC stands for Governance, Risk, and Compliance. It is the practice of ensuring your organization meets regulatory requirements, follows security best practices, manages risks, and can prove compliance to auditors and regulators.
The GRC module helps you:
If you are brand new to the GRC module, follow these steps in order. By the end, you will have a completed compliance assessment with scores across all frameworks.
The recommended workflow is:
Each step is explained in detail below.
An Assessment is a compliance review of your organization. It represents a point-in-time evaluation where you answer security questions, record maturity ratings, and collect evidence. Think of it as a "compliance snapshot."
2026 Annual Security Assessment - ACME Corp2026 Annual Security AssessmentInitialAll Corporate IT SystemsJane SmithMarch 1, 2026April 30, 2026
| Status | Meaning |
|---|---|
| Draft | Assessment has been created but work has not started yet. Questions can be answered. |
| In Progress | Active assessment — team members are answering questions and uploading evidence. |
| Under Review | All questions answered — a lead auditor or validator is reviewing responses. |
| Completed | Assessment is finished and finalized. Responses are locked. |
| Archived | Historical assessment kept for records. No longer active. |
Once you have created an assessment, you need to answer the 146 unified security questions. Each question belongs to one of 14 security domains.
| Code | Domain Name | Questions | What It Covers |
|---|---|---|---|
GOV | Governance & Leadership | 12 | Security program leadership, strategy, budget, board reporting |
IAM | Identity & Access Management | 14 | User accounts, authentication, access controls, privileged access |
DSP | Data Security & Privacy | 12 | Data classification, encryption, privacy, data loss prevention |
EPS | Endpoint & Platform Security | 10 | Laptops, servers, mobile devices, patching, EDR |
NET | Network Security | 11 | Firewalls, segmentation, VPN, DNS security, Wi-Fi |
APS | Application Security | 10 | Secure development, code reviews, API security, WAF |
OPS | Security Operations | 12 | SIEM, logging, monitoring, vulnerability scanning, SOC |
INC | Incident Management | 10 | Incident response plans, tabletop exercises, breach notification |
SCM | Supply Chain & Third Party | 10 | Vendor management, supply chain risk, contracts |
PHY | Physical & Environmental | 8 | Data centers, badge access, CCTV, environmental controls |
HRS | Human Resources Security | 10 | Background checks, security training, termination procedures |
BCP | Business Continuity | 10 | Backup, disaster recovery, BCP testing, RTO/RPO |
CRY | Cryptography & Key Management | 8 | Encryption standards, key rotation, certificate management |
CMP | Compliance & Assurance | 9 | Regulatory compliance, internal audit, external audit readiness |
Evidence proves that your answers are accurate. Auditors will expect to see evidence for each compliance claim. Evidence can include screenshots, configuration exports, policy documents, audit logs, certificates, and more.
You can also manage evidence separately via → → . This page shows all evidence across all assessments and controls, with filtering by type, status, and expiry date.
As you answer questions, the platform calculates your compliance percentage for each framework in real-time.
The compliance percentage is calculated as:
(Conforming + Partial × 0.5) ÷ Applicable Requirements × 100| Framework | Version | Mapped Questions |
|---|---|---|
| NIST Cybersecurity Framework (CSF) | 2.0 | 146 |
| ISO/IEC 27001 | 2022 | 146 |
| SOC 2 Type II | 2017 | 146 |
| PCI DSS | 4.0 | 132 |
| CMMC / NIST 800-171 | v2.0 | 97 |
| CIS Controls | v8 | 95 |
| NIST SP 800-171 | Rev 2 | 90 |
| HIPAA Security Rule | 2013 | 61 |
Once you have answered questions, you can generate a detailed compliance report for any framework. This report is suitable for sharing with auditors, regulators, or management.
For each requirement in the report, you will see:
The CSF Maturity Score page provides a visual dashboard showing your organization's maturity across all 14 security domains, aligned to the NIST Cybersecurity Framework.
The Gap Analysis page pulls together every weakness found during an assessment — every question answered Non-Conforming or Partial — into one prioritised worklist. It answers the question "where are we falling short, and what does each shortfall affect?"
Four summary tiles at the top count your Total Gaps, Non-Conforming, Partial, and gaps With Linked Risk. Below them, each gap is listed as a row with:
GOV-08).
The Frameworks page is your central hub for viewing compliance status across all supported frameworks. It shows assessment-driven compliance data.
If you navigate to this page without selecting an assessment (or by clicking a framework link from elsewhere), you will see the Requirement Tree view. This shows the hierarchical structure of all requirements within a framework, along with mapped controls and implementation status. Administrators and Cyber GRC users can add, edit, and delete custom requirements here.
Internal Controls are the specific security measures your organization has implemented. Examples: "Multi-Factor Authentication on all systems," "Daily encrypted backups," "Annual penetration testing."
The Framework Crosswalk shows how compliance with one framework automatically provides coverage for another. For example, if you are SOC 2 compliant, how much of ISO 27001 do you already cover?
The Evidence Library is a centralized repository for all compliance evidence across your organization.
| Status | Meaning |
|---|---|
| Current | Active, valid evidence |
| Expired | Past its expiry date — needs to be refreshed |
| Superseded | Replaced by newer evidence |
| Draft | Uploaded but not yet reviewed or finalized |
The Policies page provides a full policy lifecycle — from drafting through approval, publishing, and periodic review.
Draft → Review → Approved → Published → (Periodic Review or Retired)
The Audits page manages the full audit lifecycle — from planning through fieldwork, findings, remediation, and closure.
| Status | Meaning |
|---|---|
| Planning | Defining scope, objectives, and schedule |
| Fieldwork | Active testing, evidence review, and interviews |
| Reporting | Drafting audit report and documenting findings |
| Remediation | Findings have been reported; team is fixing issues |
| Closed | All findings resolved and audit is complete |
The Risk Register tracks organizational risks with likelihood/impact scoring, treatment plans, and links to controls.
Continuous Monitors are automated checks that verify your security controls on a schedule (hourly, daily, weekly, or monthly).
The Task Inbox shows all GRC tasks assigned to you across all assessments. Tasks are created during assessments to delegate work like evidence collection, remediation, reviews, or documentation.
The GRC Dashboard is your compliance command center — a single-page overview of your entire GRC posture.
Navigate to → → .
Every company relies on outside vendors — cloud providers, payroll companies, marketing platforms, IT consultants. Each vendor may have access to your data or systems. TPRM helps you answer: "How risky is each vendor, and are they protecting our data?"
Vendors move through a defined lifecycle:
Draft → Pending Review → In Review → Approved (or Rejected) → Active → Annual Review → Offboarded
Each stage triggers appropriate workflows, notifications, and required actions.
Vendor assessments are security questionnaires sent to vendors to evaluate their security posture. Navigate to → to manage them.
Not every vendor wants to answer a questionnaire in the browser. From an individual assessment's page ( → → open an assessment) you can hand the vendor an offline copy, take back a completed file, or let an AI provider pre-fill answers from the vendor's own certificates. The buttons sit in a row near the top of the assessment.
.xlsx workbook that can be completed in Excel, Google Sheets, or LibreOffice. Single-choice questions get in-cell dropdowns, and conditional questions gray out automatically when they do not apply.When the vendor sends the finished file back, click Import Completed Assessment and upload it. The platform detects the format automatically — a completed PDF, Excel (.xlsx), or CSV — and merges the answers into the assessment's existing responses.
A vendor completing an assessment may be offered a shortcut: if they hold a relevant certification, they can upload it instead of answering every question. The “Do you have a Certificate?” prompt now shows whatever Certificate Upload Instructions the template author wrote, so it is no longer limited to ISO 27001 — a template can invite a SOC 2 Type 2, ISO 27001, or any other certificate. (Template authors set this text in the Template Builder; see Assessment Template Builder.)
If your administrator has configured an AI provider, an authorized reviewer can let the AI read the vendor's uploaded certification documents and pre-fill the questionnaire. Click ⚡ Auto-Fill from Certifications on the assessment page.
When you click it you are reminded: “This will analyze the vendor's certification documents and pre-fill unanswered questions. Existing answers will not be changed.” The AI then works through the vendor's certificates and reports, for example, “Filled 12 of 30 unanswered questions.” A few things to know:
The Action Plan tab on a vendor's page lets the cyber team schedule follow-up work against that vendor — contact the vendor, send another assessment, force an annual review — with a due date, owners, and a running set of status notes. A daily job fires each action when its date arrives and turns it into a tracked to-do.
Open a vendor from → → , then click the Action Plan tab. The tab is available to Administrators and Cyber TPRM users.
Each action fires once, on or after its due date. Firing creates a linked Cyber To-Do that deep-links back to this Action Plan tab, carries out the action (for Send Assessment it emails the vendor the questionnaire; for Force Annual Review it marks the annual review due), and — if you enabled it — emails the owners or the addresses you listed.
An action moves through these statuses:
Pending → In Progress (set automatically when it fires) → Completed, or Problem if something went wrong when it fired, or Cancelled if you cancel it before it fires. You can change the status yourself at any time; the daily job never overwrites a status you have set.
Open an action to add dated Status Notes as the work progresses. Type a note and click Add Note. You can edit or delete your own notes; administrators can edit or delete anyone's. Every create, edit, and delete is audit-logged.
The SRS provides an automated, external security score for each vendor based on DNS configuration, SSL/TLS, email security (SPF, DKIM, DMARC), open ports, and other technical indicators.
Navigate to → → .
FAIR (Factor Analysis of Information Risk) is a quantitative risk model that estimates the probable financial loss from a security event involving a vendor.
Navigate to → → to create and view analyses.
Track the vendors that your vendors rely on. If your cloud provider uses a subcontractor for data storage, that is a 4th-party risk. From the sidebar you can open (technology concentration), , and . It is available to administrators and Cyber TPRM users; auditors can view but not act.
Open to see the Subprocessor Concentration view: every subprocessor your vendors have declared, and how many of your vendors use each one. A subprocessor shared across several vendors is highlighted — that shared dependency is supply-chain concentration risk. (Subprocessors are added to a vendor from that vendor's detail page.)
When a subprocessor concentrates risk, you can survey the vendors that depend on it in one action:
Each selected vendor is emailed the questionnaire (a request-for-information), and a reminder is tracked so follow-ups go out automatically. Vendors with no email on file are skipped, and any send that fails is retried by the reminder job. The same Assign Assessment flow is available from the technology-concentration and CVE views.
Discover SaaS applications being used across your organization that may not have been formally approved or assessed. Navigate to → → . In v2.6.2 this list can be filled automatically by the Grip or Hero Shadow SaaS integration, and unsanctioned apps can be blocked in Zscaler.
A vendor onboarding request is how a new vendor enters the platform. It moves through a series of statuses from first draft to final decision. Before the cyber team will review a vendor, the vendor must first be onboarded through your procurement process and have a valid Vendor ID (VID). This section explains why, and exactly how it works.
| Status | What it means |
|---|---|
| Draft | The request is being filled in. It has not been sent for review yet. |
| Submitted | The request passed the submission checks and has been sent to the cyber team. |
| In Review | The cyber team is reviewing the vendor. |
| AI Review | The vendor's services use AI and it is in the dedicated AI review stage (see AI Review). |
| Evaluation | The vendor is being trialled or evaluated. |
| Approved | The vendor has been approved and is onboarded. |
| Rejected | The vendor was not approved. |
| Inactive | The vendor is no longer active. |
Go to → → . You will see a searchable list of vendors with their status, tier, security score (SRS), and quick actions (View, Edit). Use the filter pills at the top (for example All, Approved, Review) to narrow the list. Use + New Request to start a new vendor.
Open a vendor and look at the Vendor Information card. Two fields control whether the vendor can be submitted for cyber review:
Standard vendor fields (name, domain, tier, VAT, and so on) cover most needs, but every organization tracks something extra. In v2.6.2 an onboarding template can define custom fields that have no standard vendor column. Their values are captured per vendor and shown on the vendor's Custom Data tab.
Open a vendor ( → → → open a vendor). If the vendor's onboarding template defines any custom fields, a Custom Data tab appears alongside the other vendor tabs, with a count of how many custom values are on file. The tab is read-only until you click Edit; make your changes and click Save Custom Data. Fields are grouped by their template section. Users who are allowed to see a field but not edit it see it marked (view only).
A custom field is just a question on an Onboarding-category template whose Field Name is one that is not a built-in vendor column. There are two steps, both in the Admin Portal:
data_residency_region). Choose a column type (text, number, date, etc.) and the Onboarding category.Beyond the existing text, number, date, dropdown, and radio types, questions (custom or standard) can now use:
| Type | What the vendor sees |
|---|---|
| Checkboxes | A multi-select list — tick every option that applies. |
| Button Group (Multi) | The same multi-select, shown as a row of toggle buttons. |
| Phone | A phone number with a country-code & flag picker (see Phone & VAT Question Types). |
| VAT Number | An EU VAT number with double entry and live VIES validation (see Phone & VAT Question Types). |
The single-select counterparts (Dropdown, Radio Buttons, Button Group) are still available. Multi-select types need an Options list (one per line).
On onboarding templates, each custom section and question carries two role controls, so you can keep sensitive fields away from people who should not see them:
Both a section's grant and a question's grant must allow a person before they see that question, so you can hide a whole section or just individual fields within it.
custom:<field_name>, alongside the standard columns.GET /vendors/{id}) includes a custom_onboarding_data array; each entry has field_name, label, value, type, section, and template_name.Both read from the same place as the Custom Data tab and honor the same role-based visibility — a field the caller (or the API key's owner) cannot see is blanked or omitted.
Some vendors provide services that use artificial intelligence. These vendors can carry different risks, so v2.6.2 adds a dedicated AI Review status to track them separately during the review process.
On the Vendor Information card there is a Services Use AI field. When this is set to Yes, an authorized reviewer (a Cyber TPRM user or Administrator, while editing the vendor) sees a Force AI Review link directly beneath that field.
On the Procurement Cyber Status page and on the vendor list's Review filter, vendors in In Review and AI Review are shown together — so nothing in review is ever hidden just because it is being reviewed with AI.
The Cyber Status page gives the procurement team a simple, always-current view of which vendors the cyber team is reviewing and what the latest word is on each one — without needing access to the full security tooling. The cyber team posts short, dated updates; procurement reads them here (and in a weekly email).
Open it from → → . It is available to Procurement, Cyber TPRM, and Administrator users.
Cyber TPRM users and admins can post an update for one or more vendors at once:
To keep procurement informed without anyone logging in, the platform can email a weekly digest listing every vendor in review together with its most recent update. By default this is sent every Monday at 7:00 AM.
"Shadow SaaS" means cloud apps that employees use which were never formally approved. Grip Security is a service that discovers these apps. In v2.6.2 you can connect your Grip account so the platform automatically pulls in the apps Grip finds — along with how many people use each one, a risk score, and security alerts — and lists them on your Shadow SaaS page.
It is configured by an administrator at → on the Grip tab. Grip is one of two Shadow SaaS providers (the other is Hero); only one can be enabled at a time.
/public/saas, for example https://tenant.dep.grip.security/public/saas).
Use the shared Scheduled Rehydration card (below the provider tabs) to refresh the enabled provider's data on a schedule. Tick Enable scheduled rehydration and enter a Schedule (cron expression) — for example 0 2 * * * for daily at 2 AM; the card shows a plain-English summary of what you typed. The job is installed into the system scheduler automatically (no manual server steps) and survives restarts. You can also click Run Now to refresh immediately. The same schedule serves whichever provider (Grip or Hero) is currently enabled.
Discovered apps appear on the page as Pending entries with a risk score (shown on a 1–5 scale), category, and number of users. From there you can Allow an app (which begins onboarding it as a vendor), Deny it (mark it unsanctioned, and optionally block it in Zscaler), or Dismiss it.
On the Grip Security Connection card, Data source controls where Grip pages read from:
While a sync is running, the Last Sync card shows a live progress readout — “Hydrating per-app rosters — NN% (D / T apps)” — above a Stop Sync button that cooperatively cancels the run. To wipe the locally-served Grip data entirely, use Truncate Data on the same card: it clears the Grip mirror tables, the Grip rows on the Shadow SaaS list, and the Grip telemetry stamped on vendor records (the SaaS Data tab). Your sync history is kept, and the next sync re-hydrates everything from Grip.
When Grip is connected, an SSC column shows each app or vendor's SecurityScorecard letter grade (A–F) on the Shadow SaaS list and on the vendor SRS list, and on the vendor's SaaS Data tab. It appears only while Grip is enabled.
When a vendor matches a Grip-discovered app, a read-only SaaS Data tab appears on that vendor's page, surfacing the Grip telemetry gathered during sync without leaving the vendor: First Discovered, Active Accounts (a link into the affected-users list), Last Known Usage, app classification, the Security Scorecard grade, category, AI depth, compliance signals, and SAML/MFA support.
Grip can also feed security incidents into the platform. Tick Flow Grip breach information into Breach / Cyber Alerts on the connection card and Grip “Security Incident Detected” alerts are written into your Breach / Cyber Alerts list on each sync. (This also requires the Breach/Cyber Alerts feature to be enabled under → .)
HERO Security is an alternative Shadow SaaS provider. Instead of Grip, you can connect a HERO account and the platform pulls the vendors HERO discovers — with their status, a risk score, the most-active contact, and a user count — into the same Shadow SaaS list. Grip and Hero are mutually exclusive: enabling Hero automatically disables Grip (and vice-versa), so the list is always fed by exactly one provider.
It is configured by an administrator at → on the Hero tab.
https://api.herosecurity.ai/stable unless told otherwise, and paste your Client ID and Client Secret.HERO vendors appear on the page the same way Grip apps do — as Pending entries you can Allow, Deny, or Dismiss. For each vendor the platform records:
Some columns that other sources provide (application category, MFA support, breach history, traffic volumes, file-sharing) are not part of the HERO API, so they remain blank for Hero rows.
Zscaler is a web-security service that can block access to websites. With this integration, when you Deny an unsanctioned app on the Shadow SaaS page, the platform can automatically add that app's web domain to a blocking list in your Zscaler account — so people can no longer reach it. Clicking Allow later removes the block.
It is configured by an administrator at → , on the Zscaler Connection card.
.zslogin.net).https://api.zsapi.net), ZIdentity Vanity Domain, Client ID, Client Secret, and the URL Category name.
The Breach / Cyber Alerts page collects breach and threat-intelligence signals for your vendor supply chain in one place. Open it from the sidebar under → ; a red badge shows the number of new alerts.
Alerts include breaches surfaced by the AI Breach & OSINT scanners (see AI Integration) and, when enabled, security incidents from Grip. Each alert shows the affected entity, users potentially impacted, technology, and when it was detected. An incident on a SaaS app you have not onboarded as a vendor is tagged “Shadow SaaS” with the number of users potentially impacted; if that app is later onboarded, future incidents attach to the vendor instead.
For a Grip-sourced incident, the impacted-user count links to an affected-users list for that app. The list is paged and filterable (for example by authentication method), and has a Search by name or email box to find a specific person. Because the roster is stored encrypted, the search runs over the decrypted data in the application, so it works the same as sorting and paging.
Administrators and Cyber TPRM users get a multi-select toolbar on the list. Tick the alerts you want (or use Check all) and apply an action to all of them at once:
The Admin Portal is accessible via in the sidebar (admin users only) or the Admin link in the top bar.
General Settings include: application name, company name, support email, and system-wide configuration options.
Customize the platform appearance: upload your company logo, set sidebar colors, header colors, button colors, and navigation width. Navigate to → .
Manage user accounts and group assignments. Navigate to → .
Beyond assigning the shipped groups, super administrators can build their own groups with a custom permission set — see ACL Groups & Custom Access Control.
The platform ships with seven built-in groups (administrator, cyber_tprm, procurement, stakeholder, auditor, cyber_grc, grc_contributors). In v2.6.2, super administrators can also create their own groups and tune exactly what each one can do. Open → → . Any administrator can view this page; only super administrators see the create, edit, and permission controls.
The seven built-in groups are marked System. They cannot be deleted or renamed, and their permissions are read-only — you can open View Permissions to see exactly what they grant, but not change them. This keeps the defaults everyone relies on stable.
Open a custom group's Permissions. Permissions are grouped by module (Vendor Onboarding, FAIR Analysis, Assessments, Security Rating (SRS), Annual Reviews, GRC, and Other). Each permission is tagged as either Read or Read/Write, and each module has three one-click presets:
Click Save Permissions when done. Granting Read never implies write access — the ability to change something is always a separate, explicit grant. All group changes are audit-logged.
The Template Builder ( → ) is where administrators and Cyber TPRM users design assessment and onboarding questionnaires. Use + Add Section and + Add Question to build a template. A few v2.6.2 additions are worth calling out.
A question's Question Type now includes Phone, VAT Number, Checkboxes, and Button Group (Multi) in addition to the familiar text, dropdown, and radio types (see Custom Onboarding Fields for what each captures). A question's Field Name maps its answer onto a vendor field; pick a built-in field or a custom one you registered under → .
On a template you can fill in Certificate Upload Instructions — the text shown to a vendor in the “Do you have a Certificate?” prompt. This lets a template invite any certificate (SOC 2 Type 2, ISO 27001, and so on), not just ISO 27001. If you leave it blank, a generic message is shown.
For onboarding templates, custom sections and questions carry Visible to Roles and Visible and Editable Roles controls, so you decide who can see and edit each custom field. See Custom Onboarding Fields & the Custom Data Tab.
The template list shows only active templates. If any have been deactivated, a Show Deactivated (N) button reveals them (and toggles back to Hide Deactivated (N)), keeping a long-lived tenant's list focused on the templates actually in use without losing access to retired ones.
Configure SMTP settings for sending email notifications. Navigate to → . Settings include SMTP host, port, username, password, encryption method (TLS/SSL), and sender address.
Configure Single Sign-On using SAML 2.0. Navigate to → . This allows users to log in using your organization's identity provider (Okta, Azure AD, etc.).
By default, enabling SSO does not turn off the local username/password form — the login page shows a Sign in with SSO button and a local sign-in option, so both work side by side. The behaviour is controlled by a single local-login switch:
| Mode | What users see |
|---|---|
| Local login enabled (default) | SSO button and the username/password form. Use this to run both at once. |
| Local login disabled (SSO-only) | SSO is the only path for normal users. The designated break-glass admin account can still sign in locally, so a broken identity provider can never lock everyone out. |
If SAML is not actually configured, the switch is ignored and local login always stays available (anti-lockout safety net).
The local-login switch can be set two ways. The config-file setting, when present, takes precedence over the database value — a break-glass control that needs no database access, so you can always restore local login even if SSO is misbehaving.
| Where | How |
|---|---|
| Admin → SAML page | In the Connection Settings card, tick or untick Allow local username/password login (in addition to SSO) and click Save SAML Configuration. This writes the local_login_enabled setting (enabled by default) — no SQL needed. |
| Config file (wins if set) | In config/config.php, under the auth block, set 'local_login_enabled' => true to keep local login always available (both local + SSO), or false for SSO-only. This overrides the toggle above; while it is set, the checkbox on the SAML page is shown read-only. Remove the line to manage it from the UI again. Restart the container after editing config.php. |
To run both SAML and local login with no database changes, configure SAML as above and add this to the auth block of config/config.php, then restart the container:
'auth' => [
// ...
// Break-glass: true = local login always available alongside SSO;
// false = SSO-only (break-glass admin can still log in locally).
'local_login_enabled' => true,
],
Enable AI-powered features including assessment note refinement, control suggestions, vendor commentary, AI-assisted FAIR risk analysis, and report language assistance. Navigate to → to choose a provider and enter its API key. Only one platform is active at a time.
Supported AI platforms:
claude-opus-4-8). Paste your Anthropic API key; the endpoint defaults to the standard Messages URL. Supports live web search, so Breach Alerts and OSINT scans are grounded on current, cited sources.gpt-4o). Paste your OpenAI API key. For Breach & OSINT scans it uses a web-search-capable model (default gpt-4o-search-preview) so those scans are grounded on live sources.Choosing & loading a model: after entering and saving a key, click Load Models on that platform's card to fetch its available model list (OpenWebUI / LibreChat / OpenAI). For Anthropic, type the model name directly (e.g. claude-opus-4-8).
Breach Alerts grounding: the Breach & OSINT scanners need a provider that can search the web. Anthropic (Claude) and OpenAI (ChatGPT) both ground natively; OpenWebUI / LibreChat ground only if the underlying agent has browsing; the Custom platform grounds only when a Web Search URL is configured.
The active AI provider also powers automatic translation of assessment questions (see Changing Your Language).
Administrators can check for and apply new versions from inside the platform. Navigate to → .
Type a keyword below to instantly filter the questions — for example language, VID, onboard, Grip, or password.
Yes. Enabling SAML/SSO does not turn off local login by default — the login page shows a Sign in with SSO button and a local username/password option together. You control this with the Allow local username/password login checkbox on the → page (leave it ticked to run both; untick it for SSO-only, where the break-glass admin can still log in locally). For a no-database break-glass control, the same setting can be forced in config/config.php via 'local_login_enabled' => true, which overrides the checkbox. See SAML / SSO.
Use the break-glass control: in config/config.php, under the auth block, set 'local_login_enabled' => true and restart the container. This re-enables the local username/password form regardless of the database setting, so you can sign in and fix the SAML configuration. See SAML / SSO.
Click Profile (top-right), open the Language Preference card, choose your language, and click Update Language. This only changes your own screen. See Changing Your Language.
English, Spanish, Italian, Ukrainian, Chinese (Simplified), Hindi, French, and Portuguese. Your administrator decides which of these appear in your list; English is always available.
A few different things can stay in English even after you switch language:
If you see an interface label that should be translated but is not, let your administrator know so the missing text can be added.
A vendor can only be submitted once it has completed Procurement Onboarding (set to Yes) and has a valid Vendor ID (VID) of 4–8 digits. Open the vendor, fill in both on the Vendor Information card, save, then click Submit for Review. See Vendor Onboarding and Troubleshooting.
The VID is a 4–8 digit number assigned to the vendor by your procurement system when the vendor is onboarded. It links the vendor here to your procurement and finance records. If you don't have one, the vendor has not finished procurement onboarding yet.
They are the same field. It was renamed to the clearer "Procurement Onboarding" in v2.6.2. If your screen still shows "VSU Onboarded", your instance hasn't been upgraded to the latest v2.6.2 image yet — the behaviour is identical.
It is a separate review status for vendors whose services use AI, so they can be tracked apart from ordinary reviews. A Cyber TPRM user or admin moves a vendor into it with the Force AI Review link. See AI Review for Vendors.
It only appears when you are editing the vendor with approval permission, the vendor's Services Use AI field is Yes, and the vendor is not already in AI Review.
A plain-language page (TPRM → Procurement → Cyber Status) where procurement can see which vendors the cyber team is reviewing and read dated updates the cyber team posts. See Procurement Cyber Status.
An administrator turns on the Procurement Update Digest under Admin → Email Settings and adds recipient addresses. It is emailed weekly (by default Mondays at 7:00 AM) and can also be sent on demand.
Grip Security discovers SaaS apps used across your organization. When connected (Admin → Shadow SaaS), the platform automatically pulls those apps, their user counts, risk scores, and alerts into your Shadow SaaS list. See Grip Shadow SaaS Integration.
Both feed the same Shadow SaaS list from a third-party discovery service — Grip Security or HERO Security — and both share the Zscaler blocking and the Scheduled Rehydration job. They are mutually exclusive: enabling one disables the other, so you run whichever provider your organization uses. See Hero Shadow SaaS Integration.
Confirm the Server (Tenant Base URL) ends in /public/saas, that the API Token is current, and that your server can reach the Grip endpoint. A token error reports "Unauthorized — token rejected"; a URL error reports "Endpoint not found — check base URL".
When you Deny an unsanctioned app, the platform can add its web domain to a blocking URL Category in your Zscaler account so people can't reach it. Clicking Allow later removes the block. See Zscaler Blocking Integration.
Allow begins onboarding the app as a vendor; Deny marks it unsanctioned (and can block it in Zscaler); Dismiss hides it from the list. Dismissed apps stay dismissed even after future syncs.
Users in the Administrator, Cyber GRC, or Auditor groups. If you don't see it, ask your administrator to add you to one of these groups. See User Roles & Permissions.
Open Profile and use the Two-Factor Authentication (TOTP) card to enable it with an authenticator app such as Google Authenticator or Microsoft Authenticator.
Yes. Click Download PDF at the top of this page. It produces a formatted document with a cover page, table of contents, and page numbers.
Administrators can check Admin → Version. This guide describes v2.6.2. See Updating the Platform.
No questions match your search. Try a different keyword.
This is the single most common thing that stops a vendor from moving forward, so it is worth understanding. The platform will not let a vendor be submitted for cyber review until two procurement facts are recorded on the vendor:
Why enforce this? Because the VID is the shared key that links this vendor to procurement, finance, and contract records. If the cyber team reviewed and approved a vendor that procurement had never onboarded, you would end up with duplicate or "ghost" vendors, security work that can't be tied back to a real purchase order, and reports that don't reconcile. Requiring procurement onboarding first keeps the security review and the procurement record pointing at the same, real vendor.
| Symptom | Likely cause & fix |
|---|---|
| "Cannot submit: Vendor must be onboarded at VSU before submission…" | The Procurement Onboarding field isn't set to Yes. Set it to Yes on the Vendor Information card and save. |
| "Cannot submit: A valid Vendor ID (VID) is required (4-8 digits)…" | The Vendor ID is missing or not 4–8 digits. Enter a valid VID from procurement. |
| "Only draft requests can be submitted for review." | The vendor is already past Draft. You can only submit a request that is still in Draft status. |
| The Submit for Review button isn't visible | It only appears for vendors in Draft when you have edit permission. |
| "AI Review can only be forced for vendors whose services use AI." | Set Services Use AI to Yes on the vendor before forcing AI Review. |
| I can't see the GRC module in the sidebar | You need to be in the Administrator, Cyber GRC, or Auditor group. Ask an administrator. |
| My language change didn't stick | Make sure you clicked Update Language (not just changed the drop-down), and that the language is enabled by your administrator. |
| Grip "Test Connection" fails | Check the base URL ends in /public/saas and the API token is valid and current. |
| Denying a Shadow SaaS app didn't block it in Zscaler | Zscaler blocking must be enabled and configured, and the named URL Category must already exist in Zscaler. |
| Procurement didn't receive the digest email | Confirm the digest is enabled with recipients under Admin → Email Settings, and that Admin → Email SMTP settings are correct. |
| The Upgrade button says "Could not fetch manifest" | A registry/network issue reaching your image registry. Verify the Registry Hostname under Admin → Version and that the host can reach it. |
| Term | Definition |
|---|---|
| ACL | Access Control List — defines what actions users in a group can perform |
| Action Plan | A per-vendor tab for scheduling follow-up actions (contact, send assessment, force annual review) with due dates, owners, and status notes; fired daily by the Vendor Remediation Schedule job |
| AI Review | A vendor onboarding status for vendors whose services use AI, tracked separately during review |
| Assessment | A point-in-time compliance evaluation using the unified questionnaire |
| CIS Controls | Center for Internet Security Controls — a prioritized set of security best practices |
| CMMC | Cybersecurity Maturity Model Certification — required for US Department of Defense contractors |
| Conformity Status | Whether a requirement is Conforming, Partial, Non-Conforming, Not Applicable, or Not Assessed |
| Control | A specific security measure implemented to meet compliance requirements |
| Crosswalk | A mapping between two frameworks showing which requirements overlap |
| CSF | NIST Cybersecurity Framework — a widely-used cybersecurity risk management framework |
| Custom Field / Custom Data | An organization-specific onboarding field with no standard vendor column; captured per vendor and shown on the vendor's Custom Data tab, with per-role visibility (see Custom Onboarding Fields) |
| Domain | A category of security questions (e.g., Governance, Identity & Access Management) |
| Evidence | Documents, screenshots, or files that prove a compliance claim |
| FAIR | Factor Analysis of Information Risk — a quantitative risk analysis methodology |
| FairScore | The platform's overall maturity score calculated from assessment responses |
| Finding | An issue discovered during an audit (nonconformity, observation, opportunity, or strength) |
| Framework | A compliance standard like SOC 2, ISO 27001, PCI DSS, etc. |
| GRC | Governance, Risk, and Compliance |
| Grip | Grip Security — a service that discovers SaaS apps in use; can feed the Shadow SaaS list (see Grip Shadow SaaS Integration) |
| Hero | HERO Security — an alternative Shadow SaaS discovery service that can feed the Shadow SaaS list (mutually exclusive with Grip; see Hero Shadow SaaS Integration) |
| HIPAA | Health Insurance Portability and Accountability Act — US healthcare data protection law |
| ISO 27001 | International standard for information security management systems |
| Maturity Rating | A 1-4 score indicating how mature a security practice is (1=Ad Hoc, 4=Optimized) |
| NIST 800-171 | NIST guidelines for protecting Controlled Unclassified Information (CUI) |
| PCI DSS | Payment Card Industry Data Security Standard |
| PII | Personally Identifiable Information (names, emails, addresses, etc.) |
| Procurement Onboarding | Confirmation (Yes/No) that a vendor has been set up through your procurement process; required, along with a valid VID, before a vendor can be submitted for review. (Labelled "VSU Onboarded" on instances upgraded from earlier releases.) |
| Requirement | A specific clause or control objective within a compliance framework |
| SaaS | Software as a Service — cloud applications accessed over the web |
| Shadow SaaS | SaaS apps used in the organization that were never formally approved or assessed |
| SOC 2 | Service Organization Control Type 2 — trust services criteria for service organizations |
| SPII | Sensitive PII (SSNs, financial data, health records) |
| SRS | Security Risk Scorecard — the platform's external security rating/grade for a vendor |
| SSC (SecurityScorecard) | A third-party security letter-grade (A–F) shown for Grip-discovered apps and vendors when Grip is connected |
| Subprocessor | A vendor's own downstream vendor; the same subprocessor shared across several of your vendors indicates supply-chain concentration (see 4th Party Risk) |
| TPRM | Third Party Risk Management |
| Unified Question | A single security question that maps to requirements across multiple frameworks |
| VID | Vendor ID — a 4–8 digit identifier assigned to a vendor by your procurement system |
| VSU | The procurement/vendor-setup function; "onboarded at VSU" means the vendor has completed Procurement Onboarding |
| Zscaler | A web-security service that can block website domains; integrated so unsanctioned apps can be blocked on Deny (see Zscaler Blocking) |
Fair TPRM is free software for the world to download and self-host. Security teams with limited budgets can deploy full TPRM and GRC capabilities at no cost. Try the live demo or clone the repository and deploy on your own infrastructure.