The Third-Party Risk Management module offers organizations the tools to assess, monitor, and mitigate risks from third-party vendors and internal systems. With features like security ratings, vendor risk intelligence, and breach detection, it ensures a comprehensive view of your risk portfolio. The module includes issue tracking, remediation planning, compliance mapping with 8,300+ misconfiguration checks, and vendor risk questionnaires for detailed assessments. Track your organization's security rating history, compare against peers, and leverage custom rating algorithms for tailored insights. Notifications and company profiles provide actionable updates to ensure security compliance and resilience.
Highlights
Comprehensive risk intelligence with security ratings, vendor risk assessments, issue tracking, and remediation planning.
Advanced compliance mapping with 8,300+ checks, custom rating algorithms, and peer comparisons for actionable insights.
Real-time notifications, vendor questionnaires, and detailed company profile insights to enhance decision-making.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Gain foundational visibility into your brand risk landscape with continuous monitoring for up to 200 vendors. Strengthen protection by identifying and mitigating brand threats, including impersonation, phishing, and other risks.
$36,000.00
Professional Plan
Expand monitoring to 1,000 vendors with advanced risk detection, detailed reporting, and seamless integrations for comprehensive brand protection and threat mitigation.
$54,000.00
Enterprise Plan
Unlimited vendor monitoring with tailored solutions, enterprise-grade risk detection, and dedicated support for comprehensive brand protection in large-scale environments.
You buy this product as a contract, and the three plans work as tiers based on how many vendors you monitor. The Essential Plan covers up to 200 vendors. The Professional Plan raises that limit to 1,000 vendors and adds detailed reporting and integrations. The Enterprise Plan removes the vendor cap for unlimited monitoring and adds dedicated support for large-scale environments. As your vendor count grows, you move up to the plan that matches your monitoring scale and support needs.
Top-of-mind questions for buyers
What counts as one vendor for billing across these plans?
A vendor is one third-party supplier or partner you monitor. The platform continuously discovers each vendor's assets, IPs, and cloud exposures, assigning a security rating per vendor. The Essential Plan counts up to 200 vendors, the Professional Plan up to 1,000, and the Enterprise Plan removes the cap.
What happens if my vendor count grows past my plan's limit?
Each plan sets a vendor monitoring ceiling: 200 for Essential and 1,000 for Professional. To monitor more vendors than your plan allows, you move up to the next tier. The Enterprise Plan removes the cap entirely for unlimited vendor monitoring in large-scale environments.
Do Professional and Enterprise plans add capabilities beyond a higher vendor count?
Yes. Beyond raising the vendor limit, the Professional Plan adds detailed reporting and integrations for threat mitigation. The Enterprise Plan adds tailored solutions and dedicated support for large-scale environments. The Essential Plan covers foundational monitoring, identifying threats like impersonation and phishing.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Protect your brand reputation with advanced detection and remediation of brand abuse, impersonation, and online threats across social media, surface, deep, and dark web.
Identity Intelligence provides real-time monitoring and analysis of identity-related data to detect fraud, prevent impersonation, and protect individuals and organizations from identity theft and misuse.
Threat Intelligence provides real-time insights into emerging cyber threats, helping organizations detect, analyze, and respond to vulnerabilities, malware, and attacks to enhance their security posture.
RiskProfiler Makes CVE Prioritization Clear with Exploitation and Targeting Insights
Reviewed on Sep 11, 2026
Review provided by G2
What do you like best about the product?
RiskProfiler helps us examine CVEs alongside active exploitation and attacker targeting. It also supports our vendor risk assessment, asset analysis, and threat intel identification to find out which vulnerability findings matter to our environment.
What do you dislike about the product?
The attack probability scoring logic was initially difficult to understand.
What problems is the product solving and how is that benefiting you?
Exploitation information is connected to organizational exposures, making it easier to understand why a CVE deserves closer attention.
Information Technology and Services
Real-Time Vendor Risk Scoring That Strengthens Supply Chain Security
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
The vendor risk scoring helps us monitor and identify security lapses in our supply chain in real time, helping us take action before things escalate. I also find it useful to see how those findings relate to other exposures we are investigating, providing better context and prioritization logic.
What do you dislike about the product?
It takes time to understand the scoring logic and questionnaire distributing logics initially.
What problems is the product solving and how is that benefiting you?
It helps us understand third-party security concerns as they happen instead of waiting for pre-scheduled risk assessments. We can follow up with evidence and specific questions instead of starting with a general request for an update.
Information Technology and Services
Review Assets and Threats Together for Faster, More Confident Decisions
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
I can review an exposed asset and the related threat information together. That helps me decide whether a finding needs immediate attention or further investigation.
What do you dislike about the product?
Getting familiar with the findings took some time initially.
What problems is the product solving and how is that benefiting you?
We previously had to piece together asset information and threat alerts before deciding what to fix. Having that context together makes our external exposure reviews easier to work through.
Information Technology and Services
Adaptive TPRM That Automates Questionnaires and Keeps Risk Assessments Up to Date
Reviewed on Sep 04, 2026
Review provided by G2
What do you like best about the product?
The adaptive TPRM process is the strongest area for our use case. Questionnaires can be distributed automatically, follow-up questions can adjust to previous answers, compliance controls are mapped, and risk assessments update when vendor posture or supporting evidence changes.
What do you dislike about the product?
Understanding the logistics behind vendor scoring and benchmarking takes some time.
What problems is the product solving and how is that benefiting you?
RiskProfiler has streamlined vendor onboarding and periodic reassessment with its AI agents, improving the workflows from a simple static checklist. The combination of questionnaire evidence, external exposure, and attack-path context gives us a more current view of third-party risk.
Information Technology and Services
Identity Exposure + EASM: Clear Visibility Into Attack Paths
Reviewed on Sep 04, 2026
Review provided by G2
What do you like best about the product?
The connection between identity exposure and EASM is what I value most. Exposed credentials can be evaluated alongside internet-facing services and potential attack paths into sensitive applications.
What do you dislike about the product?
The platform offers services for different threat modules, making initial onboarding and understanding a bit complex.
What problems is the product solving and how is that benefiting you?
The platform's agentic AI engine helps us understand how an external leak or exposed service might be used as the first step in a broader compromise. That context improves decisions around authentication controls and unnecessary access.