Discovery
The live inventory under every vendor-control mapping. Okta, Google Workspace, Entra (roadmap).
Read moreScopeMantle is SOC 2 Type II in progress, read our trust commitments →
FOR COMPLIANCE & GRC
ScopeMantle exports audit-ready packages mapped to SOC 2, ISO 27001, HIPAA, and the frameworks that matter to your industry, from a live source of truth, not a spreadsheet.
847 apps across Okta and Google Workspace
| App | Source | Users | Scopes | Risk | First seen | |
|---|---|---|---|---|---|---|
SLSlack | Okta · Google | 1,247 | 12 | Medium | Mar 14, 2024 | |
HUHubSpot | 389 | 8 | Low | May 02, 2023 | ||
MIMixpanel | 86 | 9 | High | Jun 12, 2024 | ||
REReplit | 12 | 14 | Critical | Aug 21, 2025 | ||
FIFigma | Okta | 2,103 | 6 | Low | Feb 18, 2022 | |
ACAnthropic Console | 41 | 3 | Low | Dec 08, 2024 | ||
ZAZapier | 67 | 21 | High | Jul 11, 2023 | ||
CACalendly | Google · Okta | 912 | 4 | Low | Jan 05, 2023 |
PROBLEM → ANSWER
Audit evidence is assembled from screenshots and email threads, fragile, manual, and unverifiable.
Pre-built evidence templates per framework. SOC 2 Trust Services Criteria, ISO 27001 Annex A controls, HIPAA Security Rule safeguards, exported as signed PDF + structured JSON.
Control mappings are stale the moment they're filed. Every audit cycle is a re-derivation of the same facts.
Live control state derived from the inventory in real time. "Control CC9.2 is operating effectively" stops being a quarterly assertion and becomes a live status.
Vendor risk assessments aren't tied to actual access. The risk register and the live environment drift apart.
Vendor risk tiers computed from scope set, user count, data category, and contract status, not a one-time questionnaire that nobody re-runs.
IN THE FIELD
“Our SOC 2 Type II audit shrank by three weeks of evidence pulls.”
Pre-mapped evidence templates dropped straight into the auditor portal. Sample selections were satisfied from ScopeMantle's exported registers; the auditor's vendor-management section closed in one cycle instead of three.
“Our risk register finally matches reality.”
Vendor tiers update automatically when a scope changes or a user count crosses a threshold. The risk team stopped maintaining two parallel inventories, one for the auditor, one for security.
“Vanta now pulls from ScopeMantle for our vendor controls.”
We treat ScopeMantle as the system of record for third-party access. Our GRC tool consumes the API, and the controls in Vanta stay green because the underlying inventory is live.
CAPABILITIES FOR COMPLIANCE & GRC TEAMS
Same platform, these are the surfaces compliance & grc teams live in.
The live inventory under every vendor-control mapping. Okta, Google Workspace, Entra (roadmap).
Read morePolicy enforcement evidence, every revoke, every approval, every escalation, captured as a signed control event.
Read moreNormalized control-relevant events feeding your GRC platform via API or webhook on a stable schema.
Read morePROOF
“We used to dread the vendor management section of the audit. Now we point at ScopeMantle, the auditor pulls a sample, and we move on. It's the difference between defending a process and proving one.”
15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.
Book a demo to see the inventory on your own tenant.