Vendorisk.ai // Methodology

Public methodology // Transparency

How we score vendors

Vendorisk.ai produces advisory, source-cited vendor dossiers from public web material. Every published verdict stores enough provenance to re-derive the tier, the numeric risk score, and the evidence that supported them - not a black-box letter grade.

Last drafted: 2026-07-31 · Version: draft 0.1 · Effective date: [Policy effective date]

01. Show your work

Ask UpGuard why you're a B. Ask us why you're Elevated Risk - here are the sources.

Incumbent ratings tools often hide their inputs. Vendorisk.ai takes the opposite approach: each dossier links to the pages that were read, the model and prompt version that synthesised them, and the tier criteria applied. If you disagree with a verdict, you can inspect the same material we did.

See a live example on any vendor dossier under Evidence & provenance.

02. Risk tier criteria

The synthesis model must assign exactly one of four tiers. Criteria below are copied from the production system prompt - they are the rules the model is instructed to follow, not post-hoc marketing copy.

  • High Risk

    Active or recent unresolved breach (~12 months) with material impact; or sensitive data handled with essentially no public security posture plus concerning signals.

  • Elevated Risk

    Breach or incident 12–36 months ago with incomplete remediation; material legal or regulatory issues; repeated outages; weak public security disclosures relative to risk profile.

  • Moderate Risk

    Historical issues with credible remediation; incomplete public data but no active crisis; mixed typical SaaS signals.

  • Low Risk

    No material recent incidents found; coherent public security posture or certifications with corroboration; stable news - still advisory, not an attestation.

When evidence is ambiguous, the model is instructed to prefer the more conservative adjacent tier only when negative signals exist - not to invent Low Risk from silence when a vendor likely handles sensitive data and posture is unknown.

03. Risk score calibration

The headline tier is the primary output. The 0–100 risk score shown on dossiers is a deterministic adjustment on top of a tier base - it is not a separate proprietary model. Recomputing it from stored fields always yields the same number (review item R6: no hidden freshness drift).

Tier base (midpoint of quartile band)

  • Low Risk → base 15
  • Moderate Risk → base 40
  • Elevated Risk → base 65
  • High Risk → base 90

Adjustments

  • Incidents: +5 per recorded public incident, capped at +25 total.
  • Confidence:
    • complete-5 (Strong public evidence across sections)
    • partial+0 (Default when some sections lack data)
    • limited+8 (Sparse or conflicting public material)
  • Questionnaire posture (when your organisation has completed one): blends 25% of a posture-derived risk component with 75% of the score above - higher questionnaire scores reduce the final number.
  • Outside-in scan: bounded ±10 from the latest TLS / headers / breach-catalog / status-page checks. Applied on top of the persisted score so dossier, export, and API verdicts share one number.

Final score is rounded and clamped to 0–100. Higher = riskier.

04. Provenance & reproducibility

Each evaluation row stores everything needed to audit or reproduce the verdict later:

  • source_set - every URL retrieved, grouped by search bucket (company, product, security, news) with titles as retrieved.
  • generated_at - timestamp of the research run (sources were fetched during this window).
  • model_id and prompt_version - which LLM and which instruction set produced the synthesis.
  • model_params - temperature, top-p, and other inference settings used for that run.
  • citations - claim-level links from dossier prose back to specific URLs.
  • Tier, rationale, summaries, incident count, and confidence - the structured outputs that feed the executive strip and score.

Re-running research on the same vendor creates a new evaluation; prior rows are retained so you can compare what changed and when. Changelog pages record tier movements over time.

05. What we do not claim

Vendorisk.ai is an advisory research tool, not a certification, audit, or legal opinion. We read public material only; we do not pentest, questionnaire vendors on your behalf, or guarantee completeness of the open web. A dossier marked partial or failed means we could not gather enough cited evidence - the evidence panel will still show what we attempted.

Questions about a specific dossier? Use the contact page. For terms governing use of assessments, see Terms of Service.