An annual questionnaire tells you what was true last year
Fourteen external sources run between assessments. When one of them changes, the composite score moves and the change is routed to whoever owns that supplier.
What Altisium watches
Each source is a named adapter, not an unspecified feed. They are grouped by the plan that carries the provider cost, so what you get is legible before you buy.
US Treasury listings plus a self-hosted OpenSanctions index, screened against vendor entities and their principals.
Negative coverage and enforcement actions matched back to the supplier record.
Filing status, officers and registered particulars from the statutory register.
Published vulnerabilities correlated to the technology a supplier is known to run.
Internet-exposed services and open ports on the supplier estate.
Supplier domains observed being used in phishing campaigns.
Security headers and browser-facing configuration on supplier endpoints.
Certificate health and protocol support, checked on a schedule.
The commercial OpenSanctions dataset, broader than the self-hosted index.
What a suspect URL actually resolves to, rendered and recorded.
Exposed data stores and credential material surfaced against supplier domains.
Whether supplier infrastructure is observed in scanning or attack traffic.
What happens when something changes
A source reports a change against a supplier entity or domain.
The signal is matched to the vendor record it belongs to.
The composite risk score moves, and the reason is recorded.
The alert lands with the named owner for that supplier.
The action is tracked to closure and stays on the audit trail.
See what we would find on your suppliers.
Bring a short list and we will run the sources against it with you.
