EU AI Act. High-risk obligations apply from 2 August 2026. See what Altisium tracks
Continuous monitoring

An annual questionnaire tells you what was true last year

Fourteen external sources run between assessments. When one of them changes, the composite score moves and the change is routed to whoever owns that supplier.

The sources

What Altisium watches

Each source is a named adapter, not an unspecified feed. They are grouped by the plan that carries the provider cost, so what you get is legible before you buy.

All plansFree and commercial-safe sources. On every tier, Starter included.
OFAC · Yente
Sanctions screening

US Treasury listings plus a self-hosted OpenSanctions index, screened against vendor entities and their principals.

News and enforcement
Adverse media

Negative coverage and enforcement actions matched back to the supplier record.

UK registry
Companies House

Filing status, officers and registered particulars from the statutory register.

Vulnerability feeds
CVE intelligence

Published vulnerabilities correlated to the technology a supplier is known to run.

Shodan InternetDB
Attack surface

Internet-exposed services and open ports on the supplier estate.

PhishTank
Phishing abuse

Supplier domains observed being used in phishing campaigns.

Mozilla Observatory
Web posture

Security headers and browser-facing configuration on supplier endpoints.

TLS check
Transport security

Certificate health and protocol support, checked on a schedule.

Growth and aboveAltisium carries the provider cost.
OpenSanctions
Full sanctions index

The commercial OpenSanctions dataset, broader than the self-hosted index.

Scale and aboveAltisium carries the provider cost.
urlscan Pro
URL detonation

What a suspect URL actually resolves to, rendered and recorded.

EnterprisePremium feeds.
LeakIX · IntelX
Breach and leak

Exposed data stores and credential material surfaced against supplier domains.

GreyNoise
Threat telemetry

Whether supplier infrastructure is observed in scanning or attack traffic.

Signal to action

What happens when something changes

14 SOURCESVendor recordATTRIBUTEDComposite scoreREASON RECORDEDNamed ownerROUTEDClosedON THE TRAIL
STEP 01
Detect

A source reports a change against a supplier entity or domain.

STEP 02
Attribute

The signal is matched to the vendor record it belongs to.

STEP 03
Score

The composite risk score moves, and the reason is recorded.

STEP 04
Route

The alert lands with the named owner for that supplier.

STEP 05
Close

The action is tracked to closure and stays on the audit trail.

Bring your own ratings. Connect a SecurityScorecard or BitSight key and the rating becomes another monitored signal on the vendor record, with movement tracked over time like any other source.

See what we would find on your suppliers.

Bring a short list and we will run the sources against it with you.