VendorLens is trust center and vendor security assessment software for small and growing B2B companies. It helps teams share existing security, privacy and compliance evidence with customers while also assessing the suppliers they depend on.
The Trust Center module provides a branded external portal for documents such as SOC 2 reports, ISO certificates, data processing agreements, subprocessor lists, security policies and penetration-test summaries. Each document can be public, restricted behind an NDA and approval workflow, or private. Restricted PDF downloads can be watermarked for the requester and delivered through time-limited links. An activity log records views, requests, approvals, downloads and expirations.
The Vendor Assessments module, currently in Beta, supports point-in-time supplier reviews. Teams add a supplier, answer six exposure questions and receive an explainable inherent-risk rating. VendorLens then recommends a questionnaire pack based on the supplier’s exposure. Available packs include Lightweight Core and add-ons for personal data, critical services, payments and iGaming. Suppliers respond through an expiring link without creating an account and can provide supporting evidence. Reviewers can request clarification and record an approval, conditional approval or rejection, together with residual risk, rationale and the next review date.
Key capabilities include:
Branded trust portals with custom-domain support on eligible plans.
Public, NDA-gated and private document visibility.
Requester-specific PDF watermarking, expiring access and audit history.
Inherent supplier-risk scoring with the contributing factors displayed.
Supplier questionnaires, evidence collection, clarifications and recorded decisions.
VendorLens is designed for founders, operations teams, sales and RevOps, security and compliance teams, and people responsible for a manageable supplier portfolio. It is particularly relevant to B2B SaaS, fintech, payments, data and AI, and iGaming suppliers.
VendorLens is not an auditor, certification provider or security-rating service. It does not perform continuous supplier monitoring, automate internal compliance controls or replace a full enterprise GRC or TPRM programme.