PRODUCT

Public Vendor Graph

The open catalogue of 200,000 SaaS vendors with hash-verifiable evidence.

Book a demo Start free

What it is

The TrustVendor Public Vendor Graph is a continuously updated, open catalogue of over 200,000 SaaS and cloud vendors. Every vendor profile is assembled from publicly accessible sources — trust centres, subprocessor pages, CT logs, EDGAR filings, and RDAP registries — crawled on a polite schedule and stored as immutable, content-addressed snapshots.

Unlike point-in-time vendor databases populated through questionnaires, the graph is a living index. When a vendor updates their subprocessor list, changes their data hosting regions, or publishes a new SOC 2 report, TrustVendor captures the change within hours, diffs it byte-for-byte against the previous snapshot, and propagates updated claims through the scoring pipeline.

The graph is free and openly queryable. No account is required to search it, resolve a vendor identity, or inspect what certifications a vendor currently holds. Commercial access to the monitoring layer — signals, historical diffs, and workspace features — begins with the Trust Workspace. The Vendor Pulse API gives GRC platforms and compliance tools direct, programmatic access to graph data.

How it works

Three steps, fully auditable.

01

Crawl

Polite, robots-compliant crawlers fetch trust centres, subprocessor pages, status pages, and public filings on a per-source schedule. Every response is stored as an immutable blob, keyed by SHA-256 content hash, so no byte is ever lost.

02

Extract

Model-emitted claims are grounded to exact character spans in the source text. Every claim includes a quote hash validated against the stored artifact before it is written — hallucinated locations are rejected at the database boundary.

03

Score

Deterministic Go arithmetic converts claims into posture and assurance scores. No model is involved in scoring. Every computation is versioned and replayable from the raw artifacts — auditors can verify the entire chain independently.

What you get

Built for compliance teams that have to prove things.

Instant vendor search

Hybrid semantic and keyword search across 200,000 profiles. Filter by certification, category, employee band, region, or assurance score band in a single query.

Hash-verifiable snapshots

Every document snapshot is content-addressed and publicly queryable. Your auditors can verify the SHA-256 hash of the source document without trusting TrustVendor as an intermediary.

Continuous freshness

Scores carry an assurance timestamp and evidence half-life. You always know whether a score is based on a document fetched yesterday or a certification that lapsed six months ago.

Sample

What it looks like in practice.

trustvendor.co/search
SOC 2 compliant HIPAA vendors, US-hosted, under 500 employees

Acme Analytics

acme.com

Posture

84

Assurance

71

SOC 2 Type II

BrightPath Health

brightpath.io

Posture

79

Assurance

68

SOC 2 + HIPAA BAA

ClearStream Data

clearstream.co

Posture

72

Assurance

81

SOC 2 Type II

Common questions.

Is the public vendor graph actually free?
Yes. Searching, resolving a vendor identity, and viewing current certifications and scores requires no account and no payment. Commercial features — monitoring your own vendor portfolio, receiving signals, exporting evidence, and API access — are part of the Trust Workspace and Vendor Pulse API products.
How do you handle vendors that block crawlers?
TrustVendor respects robots.txt and does not bypass access controls. For vendors that restrict crawling, we rely on data they publish via other channels: CT logs for certificate events, EDGAR for public company disclosures, and trust centres that explicitly permit automated access. Our bot policy is published at trustvendor.co/bot.
How current is the data?
Recrawl frequency varies by source type and vendor tier. High-traffic vendors in the public graph are crawled daily for dynamic sources (status pages, CT logs) and weekly for static documents (subprocessor lists). Monitoring customers get priority scheduling and near-real-time signals within hours of a change.
Can I submit a vendor that is not in the graph?
Yes. Any authenticated workspace user can nominate a vendor for addition. The identity resolver will attempt to build a profile from public sources within 24 hours. If the vendor has a trust centre, the extractor will process it immediately.

See Public Vendor Graph on your vendor data.

Book a 30-minute demo. We will run it live on vendors from your register.

We will respond within one business day.