← All help articles

Vendor Breach Watch — third-party risk

Monitor the SaaS tools and suppliers your business depends on, tell breach status apart from website posture, and add or remove a vendor.

Most breaches that hurt a small business don't start on your own systems — they start at a supplier who holds your data. Vendor Breach Watch keeps an eye on the SaaS tools and suppliers you depend on, so you hear about a compromise in time to rotate credentials before an attacker reaches you.

What it monitors

For every vendor you add, we track two separate signals — and it's important not to confuse them:

  • Breach status — has this vendor actually been breached? When we detect an open breach finding for a watched vendor, a red alert appears at the top of the page telling you what to do (usually: rotate any passwords or API keys you share with them).
  • Website posture — how healthy does the vendor's own security look from the outside? This is a 0–100 score where higher is healthier, refreshed by a daily check.

A vendor can have a solid posture score and still be caught in a breach, or a weak posture score with no active breach. That's why we show them apart rather than rolling them into one traffic light.

Behind the two signals is a risk register that blends them with a few more factors — how critical the vendor is to you, whether a security questionnaire is on file, and how long since you last reviewed them — into one plain-language risk rating. Unknowns (never reviewed, no questionnaire) push the risk up, never down, and any active breach automatically floors a vendor to at least high risk.

How to set it up

  1. Open Vendor Breach Watch.
  2. In the Add vendor form, enter the vendor's domain (for example stripe.com) and, optionally, a friendly name.
  3. Repeat for each supplier that holds customer data, payment data, or credentials for you.
  4. To stop watching a vendor, use its remove action in the list. You can add or remove vendors at any time.
  5. Optionally record how critical each vendor is, what data you share, and their questionnaire status in the register — this sharpens the risk rating.

How to read your results

  • Red breach banner — one or more of your vendors has an active breach. Open it, read the "What to do" line, and rotate shared secrets first.
  • Risk rating per vendor — critical/high/medium/low, with a one-sentence explanation such as "Has an active breach affecting data you share with them" or "Has no security questionnaire on file and was last reviewed 200 days ago."
  • Posture score — trend it over time; a falling score is an early warning even before any breach is confirmed.

Checks run daily, so a newly added vendor is fully evaluated within about a day.