Platform capability
Vendor Risk & Privacy Posture Scoring
Every vendor gets an automatic risk score from LLM analysis of privacy policies, security pages, sub-processors, and breach history — re-scored monthly.
Start a 30-day trial02 · RISK SCORING
Vendor Risk & Privacy Posture Scoring
Every vendor in your inventory — including the long tail of small AI SaaS tools that manual vendor databases never cover — gets an automatic risk score within minutes of discovery. ScopeMantle's LLM analysis engine reads each vendor's privacy policy, security page, sub-processor list, and known breach history, and produces a confidence-scored posture assessment broken into four axes: Security, Privacy, Scope Sanity, and Breach History.
This is not a static database. Every score re-evaluates monthly, and a change in policy or a new breach disclosure pushes an alert into your event stream, Slack, or SIEM the same day.
- SOC 2 / ISO 27001 / HIPAA presence detection per vendor
- Scope-sanity red-flagging (the Context.ai signal)
- AI-training-on-customer-data clause detection
- Sub-processor graph per vendor
- Correlation with HIBP, CISA, and public breach sources
- Monthly re-score with change alerts
- Source-cited — every score links to the policy passages that produced it
Notion · privacy posture
notion.so/privacyIdentity · Communications · File contents · Behavioral telemetry
AWS (us-east-1, eu-west-1) · Stripe · Datadog · Twilio · Snowflake
EU → US under SCCs (2021/914) · UK IDTA · No data transferred to China
Account data: 30d post-cancellation · Logs: 12 months · Backups: 35 days
72 hours from confirmed breach (Article 33-aligned)
Extracted facts are evidence-linked back to the source URL · re-runs monthly or on policy change detection
Frequently asked
Platform — common questions
Find the Context.ai in your org before the attacker does.
15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.
Book a demo to see the inventory on your own tenant.