Third-Party Risk Management

The riskiest vendor is the one that slips through.

A scanner grades one dimension. Risk lives in six. Polestead classifies every vendor across all of them — straight from your own register.

Book a demo Published pricing. No qualification quiz.
The turn

Scanners grade what a vendor shows the internet. Your exposure isn't on the internet.

It's in the data you shared, the network paths you opened, the assets you entrusted, the people you let inside. Only your side of the relationship knows — so that's where Polestead begins.

Everyone else
Context adjusts the score.
Polestead
Your classification is the architecture.
Inside-out risk

Six ways a vendor can touch you.

Data. Network. Facilities. Blueprints. People. Supply. Your exposure across these six decides how hard we look at each vendor — full-depth scrutiny for the few who could hurt you, a signed attestation for the print shop.

Depth follows exposure. Not vendor count.

Data
Network
Facilities
Blueprints
People
Supply
The long tail

Risk doesn't respect the shortlist.

Traditional per-vendor licensing prices each assessment like a luxury — so teams ration coverage to the vendors they already suspect, and hope they guessed right. But exposure — what a vendor holds, reaches, or walks through — doesn't follow anyone's picklist. Polestead's license is built so classifying the entire register is simply what the platform does, so a misclassified vendor can't quietly become next quarter's incident.

Risk review should be a culture — not a procurement decision.

The shortlist — where per-vendor licenses stop looking The long tail — classified by Polestead as a matter of course
dimensional exposure — data, people, facilities, supply

Priced so full coverage is the default — never a line item to defend.

CIICby polestead Incident response, regulator-ready

When it goes wrong, you have four hours.

DORA wants first word in ~4 hours. NIS2 gives you 24. GDPR, 72. CIIC already knows which regulators bind you — and on incident it hands you the plan, the clock schedule, and every regulator-ready report at once. Before you've finished the first call.

≈4h
DORA
Initial notice after major-incident classification.
24h
NIS2
Early warning — then 72h notice, one-month final.
72h
GDPR
To the supervisory authority.
Licensable standalone. EU baseline shown — verify national transposition. Dataset last verified July 2026. Informational, not legal advice.
Deployment

Public where it helps you. Private where it protects you.

Your trust center is built to be found. Your risk data is built to stay yours. Two different jobs — deployed two different ways.

Public — your trust center
A trust center that's free at full depth.

Your security story, reachable by every prospect, customer, and auditor — NDA gates, subprocessor lists, your own domain. Nothing held back for a paid tier. Answer once — and the library is yours to keep.

Private — your risk data
Everything else stays inside your walls.

Your register, your assessments, your incidents — on-premises, air-gapped, or single-tenant EU cloud. The US CLOUD Act reaches US platforms wherever the server sits. Self-hosted Polestead ends that question — deployed by your team, on your ground, inspectable by your auditors.

Can't host it yourself?
We'll run it for you — same platform, managed SaaS.

Single-tenant, EU-resident, transparent about its operating entity. And when you're ready to bring it inside your walls, the deployment moves with you — nothing to re-buy, nothing to migrate away from.

AI, on your terms

Your keys. Your spend. Your models. Or none at all.*

Every other platform runs your vendor intelligence through their models, on their infrastructure, under their terms. Polestead inverts it: the AI works for you because it literally runs as you.

Bring your own keys

Any provider. Any model. Your spend caps, your billing relationship, your audit trail. Switch models the day a better one ships — no waiting on our roadmap.

Nothing for us to train on

Your data never trains our models — not as a policy promise, but structurally. Inference never touches our infrastructure, so there is nothing to opt out of.

Zero-AI mode*

For estates where no external inference is acceptable, the platform runs without AI entirely — a supported configuration, not a degraded one.

*In zero-AI mode, vendor-name resolution falls back to deterministic matching, with lower match accuracy than AI-assisted resolution.

FAQ

Straight answers.

How is Polestead different from ratings platforms?+

Ratings platforms score vendors from external scans; context adjusts the score. In Polestead, your classification is the architecture: vendors are tiered by your exposure, and the tier decides how deep the assessment goes. External signals are optional evidence — never the verdict.

How is your licensing different from per-vendor pricing?+

Traditional per-vendor licensing prices each assessment slot so high that teams ration coverage to a shortlist. Polestead's license is built the other way: classifying your entire register is the default behavior of the platform, at a per-vendor economics that makes rationing pointless. You never have to justify covering a vendor.

Can Polestead run fully air-gapped?+

Yes. The register, assessments, incidents, and the platform itself deploy on-premises, air-gapped, or in single-tenant EU cloud. For teams that can't host, a managed single-tenant SaaS runs the same platform. The trust center is always SaaS, by design: it exists to be reachable.

Is the free trust center actually full-depth?+

Publishing is — NDA-gated documents, subprocessor lists, a reusable answer library, custom domain, access controls with a visitor log, unlimited imports, all free with no caps or expiry. Paid capabilities start where the trust center starts working for you: answering inbound questionnaires with human-in-the-loop workflows and pushing regulatory data.

Does customer data train your AI models?+

No — structurally. Inference runs on your own keys, with your spend caps and whatever model you choose. There is nothing for us to train on. A zero-AI configuration is supported too — vendor-name resolution then falls back to deterministic matching, at lower accuracy.

Is CIIC legal advice?+

No. CIIC — the Critical Incident Intelligence Center — is an operational control plane. Its regulatory dataset is verified against primary statutory sources and carries last-verified dates — and national transposition should always be verified with counsel.

See your register classified.

Bring a vendor-master export. Leave with your exposure mapped.

Book a demo Published pricing. No qualification quiz.
Polestead, in one paragraph

Polestead is a third-party risk management platform for regulated enterprises worldwide. It ingests the entire ERP vendor master, classifies every vendor by the buyer's own exposure across six access vectors (Internal Risk Classification), and scopes assessment depth by tier. CIIC (Critical Incident Intelligence Center), its regulatory incident-response control plane, maps sectors and jurisdictions to binding frameworks such as DORA, NIS2, and GDPR, and produces regulator-ready reports against statutory clocks. The platform deploys on-premises, air-gapped, in single-tenant EU cloud, or as managed single-tenant SaaS for teams that cannot self-host; the trust center is free at full depth and SaaS by design. AI runs on customer-supplied keys — any provider, any model; a zero-AI configuration is supported with deterministic name-matching at lower accuracy. Licensing is built so classifying the entire register is the default, rather than rationing coverage to a per-vendor shortlist.