Reads what the assurance report actually says
Third-party security review has become a ritual. A vendor sends a completed questionnaire and an assurance report, somebody files them, and the vendor is approved. The documents are rarely read closely, because doing it properly means knowing what to look for in a hundred pages of language written to reassure.
What matters is almost never in the answers. It is in the scope statement — an assurance report covering a different product than the one you are buying is common and worth nothing to you. It is in the exceptions, which every report has and no summary mentions. It is in the period, because a report covering a year that ended fourteen months ago says nothing about the company today. It is in the subprocessors, the vendor's own supply chain that inherits your data, usually listed on a web page rather than committed in a contract.
And above all it is in the mismatch between what the questionnaire claims and what the report actually tested. That is the most useful check available and almost nobody performs it, because it means reading both documents against each other.
This agent does that reading and reports what it found, what it could not verify, and the specific questions to put back to the vendor. It approves nothing and scores nothing: a risk decision belongs to the person accountable for it.
Rather than filing documents and calling it diligence.
Which is what moves a vendor, not a generic follow-up.
Of what was checked and what was accepted, with reasons.
A report covering a different product than the one you are buying is common, worth nothing, and stated in one paragraph nobody reads.
Every report has them and no summary mentions them. An opinion with four exceptions is not a clean one.
A report that ended fourteen months ago describes a company that may no longer exist in that form.
Your data's onward journey. Usually a web page the vendor can change without telling you.
Where the questionnaire asserts something the report never tested. The most useful check there is, and the least performed.
It produces findings and the questions to ask. Accepting a risk belongs to the person accountable for it.
Why Cybersecurity in particular. What matters is never in the answers — it is in the scope paragraph, the exceptions the summary omits, the period that ended over a year ago, and the claims the report never tested.
Runs unattended
Started by you or by an event, and it finishes on its own. Nothing waits for someone to be at a desk.
The same standard every time
The two-hundredth item is held to the bar the first one was. Consistency is the part people cannot sustain.
It cannot act on its own
Vendor Security Review Agent has no path to sending, spending or committing. That limit is why its output is safe to act on.
This agent runs server-side through the PROMIVO runtime. Each run is logged step by step and every tool call is permission-checked before it executes.
Read-only by design. This agent has no path to sending, spending, publishing or committing anything. Where that limit is the product, removing it would remove the reason to trust the output.
Demo dataIllustrative sample output, abridged.
{
"vendor": "Northwind Analytics",
"reviewDate": "2026-09-02",
"serviceBeingBought": "Hosted reporting platform"
}{
"scope": {
"note": "You are buying the hosted reporting platform. The report covers the data warehouse product only. Everything below applies to a system you are not purchasing.",
"entityCovered": "Northwind Holdings Inc.",
"productCovered": "Northwind Data Warehouse",
"matchesServiceBought": false
},
"period": {
"covers": "1 Jan 2025 – 31 Dec 2025",
"current": false,
"endedMonthsAgo": 20
},
"escalate": true,
"disclaimer": "A reading of the documents supplied. No vendor system was tested or contacted, no approval or risk rating is given, and no statement is made that this vendor is secure or compliant. An untested claim is unverified rather than false.",
"exceptions": [
{
"meaning": "The same control failure that would put your data in reach of someone who has left their company. Present in the detail; absent from the summary they sent.",
"exception": "Two instances where access for departed personnel was not revoked within the stated period.",
"affectsOurData": true
}
],
"subprocessors": [
"A cloud hosting provider (US)",
"A support ticketing provider (US)",
"An email provider (EU)"
],
"couldNotAssess": [
"Incident response times — no evidence supplied and the report does not test them."
],
"escalationReason": "The assurance report covers a different product than the one being bought, its period ended 20 months ago, and a questionnaire claim about subprocessor location is contradicted by the vendor's own published list.",
"questionsToSendBack": [
"Send the assurance report covering the hosted reporting platform, or confirm in writing that none exists.",
"Confirm whether customer-managed keys are available on the reporting platform, and whether any assessment has tested it.",
"Reconcile questionnaire item 6.1 with the two US subprocessors on your published list."
],
"claimsVersusEvidence": [
{
"claim": "\"All customer data is encrypted at rest with customer-managed keys.\"",
"source": "Questionnaire item 4.2. The report tests encryption at rest but says nothing about customer-managed keys.",
"status": "asserted-but-untested"
},
{
"claim": "\"We do not use subprocessors outside the EU.\"",
"source": "Their published subprocessor list names two US-based providers.",
"status": "contradicted"
}
],
"canAddSubprocessorsWithoutNotice": true
}No integrations required.
Before data reaches them, while you still have leverage.
Whether last year's assurance still describes this year's vendor.
What has changed in their posture and their supply chain.
Knowing what your vendors would survive.
$399/month
Billed monthly through your PROMIVO subscription. Cancel at any time.
Runs consume your plan allowance for agent executions and tokens. See plan limits.
No. It reports what the documents support and what they do not. Accepting a risk is a decision that belongs to whoever is accountable for it, with business context this cannot see.
Never. It performs no scanning, probing or testing of any kind. It reads the documents you were given.
Then that is the finding, stated plainly. "No assurance evidence was provided" is more valuable than a review that treats marketing material as evidence.
No reviews yet. Reviews open once customers have run this agent.
Tell us what to change and our team will scope a customised version for your business.
Customize this agent