Third-party risk, quantified.
Premium supplier cybersecurity risk management for regulated teams. Tier vendors, run deterministic assessments, close control gaps, and deliver board-ready reports with a fully auditable evidence chain.
One platform, full lifecycle
TERTIQ covers every stage of third-party risk. From supplier onboarding to board reporting, everything lives in one deterministic, fully auditable system.
Register & tier
Capture suppliers, set inherent risk inputs, and auto-assign an assessment depth matched to exposure.
Assess & collect
Run tiered assessments with structured control coverage, and link policies, certs, scans and contracts.
Find & remediate
Extract control gaps as structured findings, assign owners, set due dates, and track completion evidence.
Report & review
Roll up risk posture per vendor, per criticality, or across the whole portfolio, ready for audit.
Deterministic risk engine
Suppliers are scored on the same seven dimensions: geography, sector, data type, access, concentration, maturity and resilience. No LLM opinions.
Secure by architecture
Neon Postgres with row-level org scoping, encrypted credentials, single-session sign-out and Resend-backed OTP authentication.
Live KPIs
Track criticality distribution, upcoming reviews, overdue assessments, and tier mix: all refreshed from the register in real time.
Audit-ready by default
Every assessment, finding, attachment and remediation event is timestamped, attributed and exportable for NIS2, ISO 27001, SOC 2 and GDPR.
Edge-first delivery, global CDN, and SOC 2 Type II infrastructure.
Point-in-time recovery, logical replication, and row-level security.
Session tokens, secure cookies, and OTP flows with hardened defaults.
DKIM-signed transactional delivery with full audit logging.
