.png&w=256&q=75)
1
1
Looking for experience!

Enterprises depend on dozens of third-party vendors, and when one is breached they usually learn from the news - weeks too late. The hardest part isn't a single vendor; modern breaches cascade. One stolen OAuth token (Salesloft-Drift), one compromised identity provider (Okta), one poisoned dependency silently spreads to every connected vendor. Companies have a vendor list but no visibility into the connections between vendors - so they can't answer the question that matters: which of my other vendors are now exposed, and must I act today? Vendor Risk Radar turns the live web into continuous, cited vendor risk intelligence. For each vendor it runs real-time discovery across Google News, breach trackers, CVE feeds, status pages and regulatory portals, extracts structured risk signals with AI, and computes a transparent 0–100 risk score with recency decay - every signal backed by a real source URL, never invented. Our differentiator, Blast Radius, reads recent security incidents across all vendors, automatically discovers the connections between them (shared attacker, OAuth token, identity provider, cross-vendor mention), and clusters them into single incidents. For each it issues a clear verdict—INVESTIGATE / MONITOR / NO ACTION - with reasoning and citations, correctly separating the 4-vendor Salesloft-Drift OAuth cascade from the Okta–Cloudflare identity incident. Built with Bright Data SERP API for live discovery and Web Unlocker to bypass bot-protected breach trackers and trust centers (provable 403→200), plus AI/ML API (Claude) for extraction. A hosted MCP server exposes the data to any AI agent—just ask "Am I exposed to a cascading breach this week?" The stack (FastAPI + React + SQLite) is containerized and deployed live on Hugging Face Spaces, moving third-party risk from reactive headlines to proactive, connection-aware monitoring.
31 May 2026