Continuous TPRM · built for fintech compliance

Always-on vendor-risk monitoring. No regulator surprises.

Vendraft watches your third-party stack — SaaS, payments, KYC, cloud — and folds every SOC delta, status-page incident, breach disclosure, and OFAC hit into a fintech-shaped risk register that maps cleanly to the framework your supervisor reads against.

No regulator surprises

Every third-party finding converges into a single register mapped to DORA, FCA/PRA, and US Treasury.

Audit-grade weekly reports

A signed PDF + machine-readable JSON lands every Friday — ready for the supervisor inbox.

A live register, not a quarterly questionnaire

AI agents watch SOC deltas, status pages, breach disclosures, and OFAC hits 24 hours a day.

Aligned out of the box

  • DORA · Art. 28 / 29
  • FCA / PRA Operational Resilience
  • EBA Outsourcing
  • US Treasury

Pricing

Three tiers. Scales with the third parties you actually manage.

Every tier ships with the weekly audit-grade deliverable, regulator mapping, and the always-on surveillance layer. Pricing scales with vendors watched.

Launch

Starter

For early-stage fintechs getting their first audit-grade register off the ground.

From a low four-figure monthly fee

Talk to us about your vendor list

Request a demo
Most chosen

Growth

For scale-ups running weekly supervisor reviews and concentration risk as a standing agenda item.

Per-vendor pricing beyond the included quota

Annual contracts available

Request a demo
Regulated

Enterprise

For institutions with on-prem connectors, SSO, dedicated SLA, and named risk engineers on call.

Annual contract, volume-based

Talk to us about your vendor list

Request a demo

Per-vendor pricing after the included quota · annual contracts available

Request a demo

See your vendor list in the register.

A 30-minute walkthrough with a risk engineer. Bring your vendor list and the frameworks you report against.

  • Live register populated
  • Friday report artefact
  • Framework coverage statement