Continuous vendor risk monitoring

Every vendor.Always current.

One record per vendor that carries security, financial, compliance and spend signals, and tells you when it moves. AI reads the evidence. Your team decides.

Early access with design partners. Deploys into your own Microsoft 365 tenant.

Signal feed Northgate Logistics · 14 vendors live
72 Portfolio scoremean of 14, amber
Open alerts
5
1 unassigned
Changed, 30 days
8
7 down, 1 up
Expiring, 90 days
6
3 already lapsed
  1. 09:41SanctionsOrbit Customs Services · new director is a possible match on the EU consolidated sanctions list6645
  2. 09:38SecurityHarbourline Payroll · 2,140 employee credentials in a public breach dump7158
  3. 09:36OperationalBrightway Staffing · single source, 26% of total spend, no fallback agency7169
  4. 09:31ComplianceMeridian Freight Systems · SOC 2 Type II read, 23 fields extracted, 9 to review71
  5. 09:27SecurityAxion Telematics · advisory AX-2026-07, 412 gateways on affected firmware7264
  6. 09:22ComplianceLumen HR Suite · ISO 27001 expired 15 Aug, subscription renews in 45 days7267

last refreshed 4 min agonext check 09:00 · Tier 1 daily

One record per vendor.Security, financial, compliance, sanctions and spend on the same row. AI reads the evidence.SOC 2, certificates, questionnaires and contracts filed as dates and findings, for a person to confirm. Every alert has a source.What changed, why it matters, what to do next, with the link. Runs in your own tenant.Microsoft 365 and Dataverse, like Planvio. Documents never leave.

The register

Fourteen vendors. One screen.

Every vendor Northgate Logistics pays, and whether anything about it has moved.

The product

The screens your team
would actually open.

Each one is drawn here in the browser. Behind them is a demo company: Northgate Logistics, a regional freight and warehousing firm with about 900 staff and fourteen vendors on the register. Click through the modules and see where the work lands.

Register is the one list of everyone you pay. Each row carries what the vendor does for you, who owns the relationship, which tier it sits in and its current score. It is imported from the finance system, so it starts complete instead of starting empty.

  1. 01

    Start from the vendor master, not a blank sheet

    Connect Business Central, QuickBooks or Xero, or upload the vendor list. Every supplier with spend in the last 24 months gets a row with its trailing spend already filled in.

    Register → Import
  2. 02

    Give every vendor an owner and a tier

    Tiering rules ask four questions: does it touch personal data, does it touch production systems, what happens if it stops for a week, and is there a fallback. The answers put the vendor in Tier 1 to 4, and the tier decides how much checking it gets.

    Register → Vendor record → Tiering
  3. 03

    See the whole list, sorted by what needs attention

    Score, trend, open alerts, next expiry and spend on one row. Filter by tier, owner, category or "changed in the last 30 days".

    Register → Vendors

The modules

Modules that already know
about each other.

One record per vendor. The score, the documents, the spend and the alerts all hang off it, so the answer to "are we still fine with this supplier" is on one screen, not in four systems and a mailbox.

  1. 01

    Register

    Every supplier, one row, one owner. Tiered by what it does for you and what it touches.

  2. 02

    Onboarding

    A new vendor answers once, uploads once, and the record is built from that.

  3. 03

    Assessment

    AI reads the SOC 2, the questionnaire and the contract. It files dates, controls and gaps. A person confirms.

    See the reader
  4. 04

    Monitoring

    Daily checks against public and connected sources. Every change becomes an event with a link to where it came from.

  5. 05

    Scoring and alerts

    A score you can open. Every move has a reason, a source, a suggested next step and a name against it.

  6. 06

    Contracts and certifications

    SOC 2 periods, ISO certificates, insurance, DPAs and renewal dates on one calendar.

  7. 07

    Exposure

    Spend, share of spend, single-source flags and fallbacks, next to the risk score.

  8. 08

    Reporting

    The board view and the audit export come from the same records.

Assessment

AI reads it.
A person decides.

A SOC 2 report is a hundred pages; a questionnaire is two hundred answers. The reader pulls out the dates, the controls, the exceptions and the contradictions, shows each one next to the page it came from, and waits for a person to accept it. The record is built from accepted fields only.

  • Never sets the score
  • Never closes an alert
  • Never approves or offboards a vendor
  • Never contacts a vendor
Meridian Freight SystemsSOC 2 Type II · page 4 of 96
Section II. Independent service auditor’s report

Scope. We have examined Meridian Freight Systems’ description of its transport management platform throughout the period 1 April 2025 to 31 March 2026, and the suitability of the design and operating effectiveness of the controls stated in the description.

Opinion. In our opinion, in all material respects, the controls stated in the description were suitably designed and operated effectively throughout the period, except for the matters described in Section V, tests of controls.

Sub-service organisations. The description indicates that certain controls are performed by three sub-service organisations, listed in Section III, and excludes them from the scope of this examination.

Extracted fieldsEach one links to the page it came from
Report period end31 Mar 2026p. 4Accepted
Bridge letterNone on fileAcceptEdit
Auditor opinionUnqualified, with exceptionsp. 4Accepted
Exceptions noted2p. 41AcceptEdit
Sub-processors named3p. 4AcceptEdit
Encryption at rest (CC6.1)Coveredp. 52AcceptReject
Finding

Questionnaire Q41 says MFA is enforced for all administrator access. SOC 2 exception 2 (p. 41) notes three administrator accounts without MFA at 14 January 2026.

How it works

How work moves through Sentavo

  1. 01

    Register

    Every supplier gets a record, an owner and a tier.

  2. 02

    Assess

    AI reads the evidence and files the dates and gaps. A person confirms.

  3. 03

    Watch

    Daily checks write events. Events move the score.

  4. 04

    Act

    An alert says what changed, why, and what to do. Someone owns it.

  5. 05

    Report

    The board view and the audit export come from the same records.

Who it's for

Built for companies with vendors,
not for TPRM departments.

Sentavo is for the company where one person owns security and compliance, one person owns procurement, and both of them have other jobs.

Security and GRC teams

The person who owns the vendor questionnaire folder, the SOC 2 reports and the auditor's questions.

  • Know which vendors touch your data and systems, and hear when their posture or their certifications change, before a customer or an auditor asks.
  • Stop reading hundred-page reports by hand. The reader files the dates, exceptions and gaps; you confirm them.
  • Hand the auditor an export instead of a folder: the record, the evidence, the timeline and the alert outcomes for every vendor.

Procurement and finance teams

The people who approve the purchase orders, sign the renewals and answer for the spend.

  • See spend, share of spend and single-source exposure next to the risk score, from the ledger, not from a spreadsheet someone maintains.
  • Catch renewals on the last day you can still act, not on the end date.
  • Know before approving a large PO whether the supplier's filings, insurance or sanctions status has moved.

Compared

Replaces the review you
do once a year.

Instead ofYou getWhat changes
A vendor spreadsheet in procurement and a separate questionnaire folder in security. One record per vendor with security, financial, compliance, sanctions and spend signals on it. The question "are we still fine with this supplier" has an answer today, not as of last March.
An annual review that only reaches Tier 1, while the other 200 vendors are never looked at again. Daily checks that write events, with a link to the source, for every tier. The GRC analyst spends time deciding, not reading and retyping.
Reading a SOC 2 report by hand, or not reading it at all. Evidence read on arrival: dates, controls, exceptions and gaps filed for a person to confirm. Procurement and security look at the same record and stop disagreeing about the facts.
Finding out about a supplier's breach from LinkedIn and then asking "do we use them?" Alerts that say what changed, why it matters for that vendor, and what to do next, with an owner. The auditor gets an export, and the audit takes an afternoon instead of a fortnight.
Discovering a renewal after the notice window has closed, or a single-source dependency after it fails. A calendar of every expiry and notice deadline, and a spend and concentration view beside the score. Vendor documents and spend data never leave your own tenant.

Pricing

Two ways to run Sentavo

Edition 01 Available now, early access

Sentavo for Microsoft 365

Deploys into your own Microsoft 365 tenant on Dataverse, the same shape as Planvio for Microsoft 365. Vendor documents, spend data and records stay in your environment.

Fixed annual fee
For the early-access period, agreed per design partner. Not published yet.

  • Early access with a small number of design partners
  • Fixed early-access fee, no per-vendor meter
  • Direct access to the team, and a say in what gets built next
  • Vendor master imported, tiering rules set, monitoring started, with our help
  • All eight modules, in your own tenant
Ask for early access

Needs Microsoft 365 with Power Platform (Dataverse) licensing, billed by Microsoft. We help scope this.

Edition 02 Later

Sentavo Cloud

Hosted by Halvyn. Sign up and start, no tenant setup.

Not announced
Not available yet

  • Same product, same signals, same reader
  • No Microsoft tenant, no installation
  • Leave an email and we will tell you when it opens
Tell me when it opens

Sentavo is early. The signals, the reader and the alerts work today on the vendors our design partners have. Coverage of small private suppliers depends on public sources, which vary by country, and we say so on each record rather than showing a confident score built on nothing.

Questions

Questions we get asked

Is this a security rating service like BitSight or SecurityScorecard?

No. Those score a vendor from the outside, for a large security team, priced per vendor watched. Sentavo keeps a record of what the vendor does for you, what you spend, what they have shown you and what has changed, and it is priced for a company that has vendors but not a vendor-risk department. If you already pay for an external rating, it can be connected as one more source.

What does the AI actually read, what does it never decide, and where does the data go?

It reads the documents you or the vendor put on the record: SOC 2 reports, ISO and PCI certificates, insurance certificates, questionnaire answers and contracts. It extracts dates, controls, exceptions and contradictions and shows each one beside the page it came from, for a person to accept or reject. It writes the plain-language summary on each alert and answers questions in the Ask panel, always with the source cited. It never sets the score, closes an alert, approves or offboards a vendor, or contacts a vendor. Documents stay in your Microsoft 365 tenant. The reader calls a model API of your choosing, by default Azure OpenAI in your own subscription, and nothing is used for training.

Where does the monitoring data come from?

From sources that are public and cheap first: certificate and DNS checks on the vendor's domains, breach and security news, company registry filings where a country publishes them, sanctions lists through OpenSanctions, and the vendor's own status page. Then from what you connect: your finance system for spend, your service desk for incidents. Paid feeds such as credit scores or external security ratings are optional connectors if you already subscribe. Each event on the timeline links to where it came from.

How well does it cover small private suppliers?

Honestly, it varies. A small firm with one website and no filings gives few public signals. For those vendors, the useful signals are the ones you hold: their certificates and insurance expiry, their contract dates, your spend with them, and whether you have a fallback. Sentavo shows which signal groups have data for each vendor and which do not, instead of showing a confident score built on very little.

Does this replace our questionnaires?

It shortens them. The reader takes what a vendor already has (their SOC 2, their certificates, their last completed questionnaire) and fills the record from that, so the questions you still send are the ones the documents did not answer. Tier 3 and 4 vendors get a short form. Tier 1 vendors still get a full one, and their answers are checked against their report.

What do we need to run it, and how long does setup take?

Microsoft 365 with Power Platform (Dataverse), an admin who can install a solution, and a vendor list or a finance-system connection. Design partners have been live within two weeks: import the vendor master, set the tiering rules, upload the documents you have, and monitoring starts. We help with each of those steps.

Early access

See it on your
own vendor list.

A walkthrough of about forty minutes. We start by asking how you keep track of vendors today, then show the parts of Sentavo that would replace it. If you want to be a design partner, say so and we will explain what that involves.

  • No slide deck, the actual product
  • We say honestly whether the signals cover your suppliers
  • No obligation and no sales sequence
Please enter your name.
Please enter a valid work email.
Please enter your company.
Optional, but it makes the walkthrough far more useful.

We reply within one business day. Your details are used only to answer this request.