Skip to main content
Probo’s vendor management module gives you a central registry for all third-party software and service providers your organization uses. For each vendor you can record contact details, compliance documents, risk assessments, and the specific services they provide.

Vendor categories

When creating a vendor you assign it to one of the following categories:
CategoryExamples
ANALYTICSProduct analytics, BI tools
CLOUD_MONITORINGInfrastructure monitoring, APM
CLOUD_PROVIDERAWS, Google Cloud, Azure
COLLABORATIONSlack, Microsoft Teams, Notion
CUSTOMER_SUPPORTZendesk, Intercom
DATA_STORAGE_AND_PROCESSINGSnowflake, Databricks
DOCUMENT_MANAGEMENTDocuSign, Google Workspace
EMPLOYEE_MANAGEMENTRippling, Workday, Gusto
ENGINEERINGGitHub, CircleCI, Datadog
FINANCEStripe, QuickBooks
IDENTITY_PROVIDEROkta, Auth0
ITIT management and support tools
MARKETINGHubSpot, Mailchimp
OFFICE_OPERATIONSFacilities and office management
PASSWORD_MANAGEMENT1Password, Bitwarden
PRODUCT_AND_DESIGNFigma, Linear
PROFESSIONAL_SERVICESConsulting and advisory firms
RECRUITINGGreenhouse, Lever
SALESSalesforce, HubSpot CRM
SECURITYSecurity tooling and MSSP
VERSION_CONTROLGitHub, GitLab
OTHERAnything that does not fit above

Vendor profile fields

Each vendor record can store the following information:
  • Name — display name of the vendor
  • Legal name — official registered entity name
  • Description — what the vendor does and why you use them
  • Category — one of the categories listed above
  • Headquarter address — physical address of the vendor’s headquarters
  • Countries — ISO 3166-1 alpha-2 country codes where the vendor operates or processes data
  • Website URL — vendor’s main website
  • Privacy policy URL — link to their privacy policy
  • Terms of service URL — link to their terms of service
  • Service level agreement URL — link to their SLA document
  • Data processing agreement URL — link to their online DPA
  • Business associate agreement URL — link to their online BAA (for HIPAA)
  • Subprocessors list URL — link to their list of subprocessors
  • Security page URL — link to their security overview or trust page
  • Trust page URL — link to their trust center (if they have one)
  • Status page URL — link to their operational status page
A free-text list of certifications the vendor holds (e.g. ["SOC 2 Type II", "ISO 27001"]). These are used to display certification badges on your trust center when you enable a vendor there.
Each vendor has two optional owner fields:
  • Business owner — the team member responsible for the business relationship
  • Security owner — the team member responsible for the security review
Both owners are members of your organization.

Risk assessments

You perform a vendor risk assessment to formally evaluate how much risk a vendor represents. Each assessment records:
FieldOptions
Data sensitivityNONE, LOW, MEDIUM, HIGH, CRITICAL
Business impactLOW, MEDIUM, HIGH, CRITICAL
NotesFree-text notes on the assessment
Expires atWhen this assessment should be reviewed again
Creating a new risk assessment automatically expires any previous non-expired assessment for the same vendor. Only one assessment is active at a time.

Data sensitivity

Use data sensitivity to classify the most sensitive data the vendor processes on your behalf:
LevelMeaning
NONENo sensitive data is shared with this vendor
LOWNon-personal or publicly available data
MEDIUMInternal business data
HIGHPersonal data or confidential business information
CRITICALSpecial category personal data, financial data, or credentials

Business impact

Use business impact to reflect how severely your operations would be affected if this vendor became unavailable:
LevelMeaning
LOWMinor inconvenience; easy to replace
MEDIUMMeaningful disruption; replacement requires effort
HIGHSignificant operational impact
CRITICALCore business operations would stop

Compliance documents

For each vendor you can upload and manage three categories of compliance documents:
A BAA is required under HIPAA when a vendor handles Protected Health Information (PHI) on your behalf. Upload the signed BAA file to the vendor record to keep it easily accessible during audits.BAA records include metadata such as the document’s effective date and an optional description.

Vendor contacts

Add individual contacts within a vendor organization for each key relationship:
  • Security team contacts for security reviews
  • Legal or privacy contacts for data protection questions
  • Account managers for contract and billing matters
Each contact has a name, email address, and optional role description.

Vendor services

Vendor services let you document the specific products or features you use within a vendor’s portfolio. For example, within an AWS vendor record you might have separate service entries for S3, RDS, and Lambda. Each service has a name and description.

AI-powered vendor assessment

Probo can automatically populate a vendor record by analyzing the vendor’s public website. Provide the website URL and Probo will attempt to extract the vendor’s name, description, category, legal name, headquarters, and relevant compliance URLs.
AI-generated vendor profiles should be reviewed for accuracy before being used for compliance purposes. Probo does not guarantee the completeness or correctness of extracted information.

Risk management

Score and track risks associated with your vendors.

Trust center

Show vendor certifications on your public trust center.

Compliance frameworks

Link vendor controls to framework requirements.

Policies and documents

Manage vendor-related policies and agreements.

Build docs developers (and LLMs) love