Every vendor in your register, tiered by your exposure — not their marketing, not their scan grade. The tier then decides everything downstream: assessment depth, monitoring, review cadence.
Cyber risk is multidimensional. The vectors are how a vendor can actually touch you — and only your side of the relationship knows their values.
Four assessment templates, 133 questions, 31 modules — applied where they're warranted, not everywhere. The tier is derived from the vectors; the depth is derived from the tier. No one hand-picks who gets scrutiny.
Polestead ingests the vendor master your ERP already owns — flat-file for air-gapped estates, API sync for connected ones — deduplicates it on ingestion, and resolves every record to a public identity so breach intelligence lands on the right vendor. Matching is high-confidence-only: uncertain matches go to human review, never to alerts.
Logical data access, network connectivity, physical and facility access, design and IP custody, embedded personnel, and product and component supply.
The vector profile yields a tier automatically, and the tier decides assessment depth — full scrutiny where exposure concentrates, an attestation where it does not.
Yes, by default. Classification is automatic and unlimited, so the risky vendor nobody nominated still surfaces.