Assurewright reads vendor SOC 1 and SOC 2 reports, surfaces the exceptions that actually matter, and keeps a record of every review decision that holds up when an examiner asks.
Built by a former Head of Internal Audit. Currently working with a small number of design partners.
Most third-party risk programs are one busy afternoon away from approving a vendor nobody actually vetted.
Extracts and analyses the document itself — auditor's opinion, report type and period, testing exceptions, carve-outs and CUECs — then presents the findings with the supporting passage highlighted.
The answers drive the workflow. Personal data pulls in Privacy, system access pulls in Network Security, non-standard payment terms pull in Accounts Payable. Configurable without a developer.
The requestor's intake answers and the vendor's own questionnaire are checked against each other. Contradictions on MFA, encryption or data handling are flagged before anyone approves.
Reviewers cannot approve a vendor without attesting that they reviewed each flagged finding. Rejecting or asking for more information carries no such gate.
Send DPAs and contracts to the vendor in-platform, receive their redlines, and see exactly which terms changed — liability caps, breach notification windows, sub-processor rights.
Every decision, rationale, flag, contradiction and workflow change is recorded with who did it and when. The answer to "why did we approve this" is on one screen.
Real output from a SOC 2 Type II in the demo — produced from the report itself, not the filename.
Kevin Burke — founder
I spent my career in internal audit, most recently as a Head of Internal Audit. I've sat on both sides of this process: reviewing vendors under time pressure, and being the person an examiner asks to justify a decision made eighteen months earlier.
Assurewright is the tool I wanted. It encodes the judgement that usually lives in one experienced reviewer's head — which findings matter, which are noise, and what has to be resolved before a vendor gets through.
I'm working with a small group of design partners to shape where it goes next. If third-party risk is your problem, I'd like to hear how you handle it today.
Most compliance software is built by engineers who interviewed a compliance team. The difference shows up in what the tool decides to flag — and in what it correctly ignores.