Always-on vendor-risk monitoring. No regulator surprises.
Vendraft watches your third-party stack — SaaS, payments, KYC, cloud — and folds every SOC delta, status-page incident, breach disclosure, and OFAC hit into a fintech-shaped risk register that maps cleanly to the framework your supervisor reads against.
No regulator surprises
Every third-party finding converges into a single register mapped to DORA, FCA/PRA, and US Treasury.
Audit-grade weekly reports
A signed PDF + machine-readable JSON lands every Friday — ready for the supervisor inbox.
A live register, not a quarterly questionnaire
AI agents watch SOC deltas, status pages, breach disclosures, and OFAC hits 24 hours a day.
Aligned out of the box
- DORA · Art. 28 / 29
- FCA / PRA Operational Resilience
- EBA Outsourcing
- US Treasury
Pricing
Three tiers. Scales with the third parties you actually manage.
Every tier ships with the weekly audit-grade deliverable, regulator mapping, and the always-on surveillance layer. Pricing scales with vendors watched.
Starter
For early-stage fintechs getting their first audit-grade register off the ground.
From a low four-figure monthly fee
Talk to us about your vendor list
Request a demoGrowth
For scale-ups running weekly supervisor reviews and concentration risk as a standing agenda item.
Per-vendor pricing beyond the included quota
Annual contracts available
Request a demoEnterprise
For institutions with on-prem connectors, SSO, dedicated SLA, and named risk engineers on call.
Annual contract, volume-based
Talk to us about your vendor list
Request a demoPer-vendor pricing after the included quota · annual contracts available
Request a demo
See your vendor list in the register.
A 30-minute walkthrough with a risk engineer. Bring your vendor list and the frameworks you report against.
- Live register populated
- Friday report artefact
- Framework coverage statement