Third-party risk management

A vendor-risk program you can stand up in an afternoon.

Auditors and enterprise buyers now demand a defensible vendor-risk process. Covenant gives you the register, the questionnaires, the scoring, and the evidence — without the $16,000 platform.

The program

From register to evidence, in one place

Vendor register

Catalog vendors with category, owner, data-sensitivity, access, and criticality. Bulk-load a sample portfolio to see it working immediately.

Risk tiering

Covenant tiers each vendor Critical → Low from sensitivity × access × criticality, with a PHI floor so a business associate is never under-rated.

Security questionnaires

SIG/CAIQ-lite, a HIPAA Security Rule attestation, and an SMB Lite questionnaire. Each risky answer is weighted and folded into the score.

Explainable scores

A composite 0–100 grade where every factor — inherent exposure, questionnaire, findings, BAA gap — is itemized with its delta. No mystery score swings.

Finding tracker

Log external-posture findings (TLS, headers, email-auth, breach) with severity and dispute / accept / remediate actions.

Framework coverage

Evidence maps to NIST SR, HIPAA, SOC 2 CC9.2, and ISO 27001 A.5.19–23, and publishes to the shared DosanjhLabs evidence graph for Sightline and Bastion.

Why teams switch

Match the cheap tool on price, beat the expensive one on features

CapabilityCovenantSpreadsheetEnterprise TPRM
Flat price, no per-vendor feeYesFree$79–$2,000/vendor
HIPAA BAA lifecycleNativeManualAdd-on / none
Explainable scoringItemizedNoneOften opaque
Self-serve, no sales callYesQuote-only
Cross-product evidence graphYesNoNo

Build the program your auditor expects.

Start with 10 vendors free, then grow without paying per vendor.

Start free →