For regulated teams · SOC 2-aligned · Audit-ready

Third-party risk, quantified.

Premium supplier cybersecurity risk management for regulated teams. Tier vendors, run deterministic assessments, close control gaps, and deliver board-ready reports with a fully auditable evidence chain.

Designed for regulated industriesZero third-party data sharingDeterministic scoringBoard-ready reports
Core platform

One platform, full lifecycle

TERTIQ covers every stage of third-party risk. From supplier onboarding to board reporting, everything lives in one deterministic, fully auditable system.

Register & tier

Capture suppliers, set inherent risk inputs, and auto-assign an assessment depth matched to exposure.

Assess & collect

Run tiered assessments with structured control coverage, and link policies, certs, scans and contracts.

Find & remediate

Extract control gaps as structured findings, assign owners, set due dates, and track completion evidence.

Report & review

Roll up risk posture per vendor, per criticality, or across the whole portfolio, ready for audit.

Security and depth

Deterministic risk engine

Suppliers are scored on the same seven dimensions: geography, sector, data type, access, concentration, maturity and resilience. No LLM opinions.

Secure by architecture

Neon Postgres with row-level org scoping, encrypted credentials, single-session sign-out and Resend-backed OTP authentication.

Live KPIs

Track criticality distribution, upcoming reviews, overdue assessments, and tier mix: all refreshed from the register in real time.

Audit-ready by default

Every assessment, finding, attachment and remediation event is timestamped, attributed and exportable for NIS2, ISO 27001, SOC 2 and GDPR.

Trusted infrastructure
Hosted on Vercel

Edge-first delivery, global CDN, and SOC 2 Type II infrastructure.

Data on Neon Postgres

Point-in-time recovery, logical replication, and row-level security.

Auth by Auth.js

Session tokens, secure cookies, and OTP flows with hardened defaults.

Email via Resend

DKIM-signed transactional delivery with full audit logging.