Prospective → active → periodic-review → terminated.
Third-party & vendor risk, lifecycle, tiering, cross-credit from vendor certs.
TrustEdge manages the vendor lifecycle end to end (onboarding, tiering by criticality, assessment and periodic review) and pulls credit from a vendor's own certifications so you do not re-assess what a valid attestation already proves.
A vendor portal lets suppliers respond directly, in a scoped and time-boxed surface.
This section is being written for TrustEdge. It names who the product suits and, more usefully, who it does not. We would rather leave it blank than fill it with something generic.
Prospective → active → periodic-review → terminated.
Criticality-based tiering drives assessment depth.
A vendor's SOC 2 or ISO attestation credits their controls.
Suppliers respond in a scoped external surface.
| Feature | Milestone | Scope |
|---|---|---|
| Vendor register + lifecycle | v1.0 | In MVP v1.0 |
| Risk tiering T1-T4 | v1.0 | In MVP v1.0 |
| Vendor portal (external intake) | v1.0 | In MVP v1.0 |
| Cross-credit from vendor certs | v1.1 | Planned |
| 4th-party / sub-processor map | v1.2 | Planned |
Milestones are roadmap targets rather than shipped dates. Target for MVP v1.0: 2027 H1. Provisioning is white-glove, never self-serve.
Every SecureEdge Advisory product prepares you for a certification, an audit or an assessment. None of them awards one. A certificate is issued by an accredited certification body, an attestation opinion by an independent auditor, and a regulatory finding by a regulator. We prepare the position and facilitate the process; the affirmation is made by someone else, and we do not blur that line.
Everything a product reports is derived from information supplied by your organisation, or by the person representing it. Ratings, maturity levels, readiness figures, mappings between frameworks and any monetary exposure are calculated from those inputs. Where an input is incomplete, out of date or optimistic, the output carries that forward faithfully. A result is therefore a structured statement of the position you have described, not an independent verification that the position is true.
An assessment is a documented position at a point in time. It is useful precisely because it is explicit about what it rests on, and it should be read that way rather than as a proof. Nothing here is a substitute for an audit, and no output should be presented to a regulator, a customer or a board as one.
Part of a family of ten products sharing one governed control library. Provisioning is white-glove and scope follows a due diligence review.