Kervo AI
Platform/Know/Vendor Risk
Kervo AI · Know

Your vendors' real security posture, continuously.

Questionnaires tell you what a vendor claimed once. Kervo AI monitors their real external posture continuously, without needing anything from them.

platform.kervo.ai / know / vendors
Know / Vendorsliveacme-prodVENDORS84 monitoredPayCoTier 1DCloudPixTier 2COktaTier 1ADataBridgeTier 3BShipFastTier 2CNotelyTier 3ANo questionnaires. Outside-in, checked daily.PAYCO · TIER 1re-tiered · critical41GRADE DTLS 1.0 · api.payco.ioBreach notice · leak siteSPF record expiredOpen RDP · 2 hostsposture · 90dEVIDENCE GENERATEDSOC 2 · CC9.2 Vendor riskISO 27001 · A.15.2NIS2 · Art. 21(2)(d)DORA · ICT third-partyFiled automatically against each framework
Outside-in
no vendor cooperation required
Continuous
posture changes flagged when they happen
Generates compliance evidence
satisfies TPRM controls automatically
[ The problem ]

The problem with questionnaires

Send a spreadsheet, wait, file the answers, repeat next year. It is self-reported, a snapshot, and it does not scale: a mid-market company depends on fifty to three hundred vendors, so the process covers the fifteen obvious ones and ignores the small SaaS tool with an API key into your CRM.

The vendor who gets you is rarely the one whose questionnaire you scrutinised.

[ What Kervo AI does ]

What Kervo AI does

Kervo AI monitors vendors the way an attacker would assess them: from the outside, continuously, without permission. It maps their attack surface, fingerprints services, matches known CVEs, checks certificates and watches breach sources.

Each vendor gets a risk score combining observed posture with their criticality to you. A vendor whose posture degrades in March generates an alert in March. Questionnaire workflows exist where a contract or regulator requires attestation.

[ Capabilities ]6 capabilities
01

Continuous outside-in monitoring

Each vendor's attack surface, open ports and services, software versions, known CVEs, certificate validity and cipher strength, assessed continuously with no vendor involvement.

02

Vendor dark web monitoring

Whether your vendors' credentials or data appear in breach sources. A vendor breach frequently precedes a supply chain attack on their customers.

03

Risk scoring and tiering

Observed posture combined with what data they hold, what access they have, and whether you could operate without them. Concentrate monitoring depth where the consequences are real.

04

Change alerting

New exposure, a critical vulnerability in their stack, credentials surfacing, a certificate lapsing. Alerted immediately with the context to raise it with them.

05

Compliance evidence for TPRM controls

SOC 2, ISO 27001 and NIS2 all require documented third-party risk management. Continuous monitoring generates that evidence as a by-product: assessment records, scores, change history, all exportable.

06

Questionnaire management

Templates, distribution, tracking and storage for contractual or regulatory attestation, alongside the monitoring rather than instead of it.

[ How it works ]

How it works

Add vendors manually, import from procurement or finance, or let Kervo AI discover them from DNS records, email headers, code dependencies, SaaS integrations and cloud configurations. That step regularly surfaces vendors nobody had on the list.

Monitoring uses the same external discovery engine Kervo AI runs against your own estate. Everything is passive or lightweight, and identical to what any external observer could do.

[ One data model ]

Why vendor risk belongs in the same platform

A vendor's risk to you is a function of what they can reach in your environment, and a standalone vendor-risk tool cannot know that. Kervo AI holds both sides: the vendor's observed posture and the access they have into your systems. A vendor with a critical exposure and an integration into your CRM is an attack path from their infrastructure into yours.

See how this fits into Know
[ FAQ ]Vendor Risk
What is third-party risk management?

Identifying and monitoring the security risk introduced by vendors, suppliers and partners with access to your systems or data.

Does this require vendor cooperation?

No. Outside-in monitoring uses the same techniques any external observer could. Questionnaire workflows are available where attestation is contractually required.

How many vendors can we monitor?

Professional covers up to 100 vendors. Enterprise is unlimited.

Is monitoring a vendor's infrastructure legal?

Yes. Passive discovery and lightweight, non-intrusive fingerprinting, with no exploitation attempts and no unauthorised testing.

How does this satisfy compliance requirements?

Kervo AI generates continuous monitoring records, risk scores and change histories, exportable as evidence of ongoing monitoring rather than an annual snapshot.

[ More in Know ]
Get started

See what your vendors' security actually looks like.

Bring your top ten vendors to the demo. We'll run the outside-in assessment live.