Platform — Internal Risk Classification

Classification is the architecture.

Every vendor in your register, tiered by your exposure — not their marketing, not their scan grade. The tier then decides everything downstream: assessment depth, monitoring, review cadence.

Six access vectors.

Cyber risk is multidimensional. The vectors are how a vendor can actually touch you — and only your side of the relationship knows their values.

Logical data access
What of your data they hold, process, or reach — classes, volumes, sensitivity.
Network connectivity
Standing connections into your environment — VPNs, APIs, integrations.
Physical & facility access
Who walks your floors, and where — sites, zones, escorted or not.
Design & IP custody
Drawings, specifications, formulas, source — your IP in outside hands.
Embedded personnel
Their people inside your teams, plants, and systems.
Product & component supply
What ships into your product and process — and what happens when it stops.
Anchored in NIST SP 800-161r1 · NIST CSF 2.0 GV.SC · CER Directive (EU) 2022/2557

Four tiers. Depth follows exposure.

Four assessment templates, 133 questions, 31 modules — applied where they're warranted, not everywhere. The tier is derived from the vectors; the depth is derived from the tier. No one hand-picks who gets scrutiny.

Tier
Exposure profile
Assessment
T1
Multiple high-value vectors — crown-jewel data, standing network access, design custody.
Full-depth template, all applicable modules, continuous review.
T2
Material exposure on one or two vectors.
Standard template plus the modules those vectors trigger.
T3
Limited, bounded exposure — escorted access, non-sensitive data.
Light template, annual review.
T4
No material exposure on any vector.
Signed attestation — on record, revisited if their vectors change.

Your register is the spine.

Polestead ingests the vendor master your ERP already owns — flat-file for air-gapped estates, API sync for connected ones — deduplicates it on ingestion, and resolves every record to a public identity so breach intelligence lands on the right vendor. Matching is high-confidence-only: uncertain matches go to human review, never to alerts.

Identity resolution
I.B.M. Deutschland GmbH Intl Bus Machines #4471 → one resolved identity, matched to breach intelligence

See your register classified.

Book a demo
FAQ

Common questions.

What are the six access vectors?+

Logical data access, network connectivity, physical and facility access, design and IP custody, embedded personnel, and product and component supply.

How are tiers decided?+

The vector profile yields a tier automatically, and the tier decides assessment depth — full scrutiny where exposure concentrates, an attestation where it does not.

Do I have to classify the whole register?+

Yes, by default. Classification is automatic and unlimited, so the risky vendor nobody nominated still surfaces.