Know exactly what your contracts require of your vendors

VendorScore reads your prime contracts, flags the compliance and security clauses that matter, and shows you exactly what flows down to your subcontractors — so you can send the right assessments and track every vendor in one place.

See how it works →
VendorScore splash screen listing supported compliance frameworks: CMMC, TISAX, HIPAA, SOC 2, ISO 27001, NIST, and ITAR public/screens/VendorScore_LoginPage.png
Operating since 2009
Frameworks CMMC · NIST 800-171 · DFARS · TISAX
Built by The compliance team at Praetorian Secure

Your obligations don't stop at your own walls

The compliance and security obligations you agree to flow down to the vendors and subcontractors you rely on — and missing one puts your own standing at risk. Most companies track this in spreadsheets and hope. VendorScore replaces the hope with a system.

VendorScore vendors dashboard listing subcontractors with risk posture, findings, and CMMC/SPRS status public/screens/Vendors_Dashboard.png

How VendorScore works

01

Upload the prime contract

Upload the solicitation or award your customer sent you. VendorScore reads it immediately and pulls out the compliance and security clauses that matter, so you are not scanning a 200-page package by hand.

VendorScore contract review showing detected clauses with flow-down status and implied vendor requirements public/screens/Contract_Review.png
02

See what flows down

Every clause is marked with whether it flows down to your subcontractors or stops with you. You get a clear read on what the contract actually obligates your vendors to do, and what it does not.

VendorScore AI-generated narrative summarizing a contract's compliance obligations and flow-down clauses public/screens/Ai_Contract_Narrative.png
03

Send the right assessment

VendorScore recommends the assessment that matches what the contract requires, not a generic questionnaire. Send it, track responses, and see where every vendor stands in one place.

VendorScore CMMC Level 2 vendor risk assessment showing submitted responses and raised findings public/screens/Vendor_RiskAssessment.png

It knows the clauses that matter.

FAR 52.204-21 Basic safeguarding of covered contractor information
DFARS 252.204-7012 Safeguarding covered defense information
DFARS 252.204-7019 NIST SP 800-171 assessment requirements
DFARS 252.204-7020 SPRS assessment reporting
DFARS 252.204-7021 CMMC requirements

Flow-down status is tracked per clause, so you know which obligations reach your subcontractors and which stop with you.

Built to hold data you are accountable for

VendorScore is used by contractors who answer to their own customers for how supplier information is handled. Here is how it is built.

Tenant isolation

Every organization's data is separated at both the application and the database layer. Queries are scoped to your organization, and PostgreSQL row-level security enforces that same boundary independently underneath. A mistake in one layer does not expose another tenant's records.

Data handling

VendorScore is built for Federal Contract Information. Controlled Unclassified Information is prohibited by policy, not by preference. Uploads require an explicit attestation, and documents carrying CUI markings are detected and quarantined rather than processed.

Access control

Access is role-based and scoped to your organization. Vendors reach only their own portal and see only what you choose to send them. Administrative functions are separated from everyday user roles.

See it on your own contracts

Bring a real contract and we'll show you what VendorScore flags and how the workflow fits your business. Twenty minutes, no obligation.