Every system asks if an action is allowed. None asks if it should happen.

Vendor Onboarding

Each vendor checked against the obligations that apply, with the evidence collected.

Not a questionnaire that ages. Tredy works out which obligations apply to this vendor, requests the evidence, checks what came back against the rule, and escalates anything that lapses.

Book a demo

Governing AI and human actions across the tools your teams already use

  • Claude
  • ChatGPT
  • Slack
  • Microsoft Teams
  • Microsoft 365
  • Gmail
  • GitHub
  • GitLab

What it does

  • Determines which obligations apply to this vendor, at this criticality
  • Requests the evidence that would satisfy them
  • Checks what was returned against the rule, not against a checkbox
  • Escalates anything lapsed or missing to the named risk owner
  • Keeps the file current as certificates roll, without a new cycle

What you get

An evidence file per vendor

An evidence file per vendor: the obligations that apply at this criticality, the evidence requested, what came back, what was accepted against the rule, and what lapsed. It stays current as certificates roll rather than ageing between review cycles.

What it needs from you

Your vendor list with a criticality rating, and wherever the evidence lives today — a drive, a GRC tool, an inbox. Tredy works from that rather than starting a fresh collection round.

Where it stops

It does not accept a vendor. It reports what the evidence supports and what lapsed; the risk owner decides whether to proceed.

What starts it

A new vendor

A vendor enters onboarding and needs to be assessed before it is used.

A renewal

A contract reaches renewal and the file must be current to proceed.

A lapse

A certificate, attestation or insurance cover expires or is withdrawn.

Start with one service.

A 30-minute scoping session with your risk owner and your IT contact.