PartnerScope · Plans

Third-party AI risk — without the 40-page questionnaire

PartnerScope assesses your vendors across 13 dimensions — behavioural, financial, and AI-compliance — with automated tests, documentary review and AI red-teaming. Drop-in reports aligned with EU AI Act, GDPR, DORA and NIS2.

  • Scope and price confirmed before payment
  • EU-hosted · GDPR-compliant
  • Named analyst on every Pro report
Not ready to buy? Get a 60-second risk snapshot — 4 questions, no account.
Try it free →

Pricing

Three tiers. One methodology.

Starter is an external technical snapshot of a vendor domain. Pro and Enterprise apply the 13-dimension framework: documentary review, a named analyst, and — for Enterprise — ongoing monitoring after delivery.

Starter

€99
Single vendor · external technical snapshot · one-time

An external technical snapshot of one vendor domain — plus the questions to ask them next.

  • Automated checks on the vendor domain: DNS, TLS, HTTP security headers, Certificate Transparency log
  • Each check reported with time, object tested and its limits — a failed service is reported as "not checked", not as a finding
  • Open questions for the vendor, derived from what the checks could not see
  • No composite score and no proceed/decline verdict — those require Pro

We confirm scope within one business day and send a Stripe payment link.

Pro

€299
Single vendor · one AI product and use case · analyst-led

Serious vendor decisions — new contract, renewal, audit response.

  • Everything in Starter, plus:
  • Context brief agreed before payment: product, use case, data involved, criticality, decision deadline
  • Documentary review of what you and the vendor supply — DPA, ISO 27001 / SOC 2 scope, Model or System Card, SBOM, BCP / IR plan
  • Sanctions screening against EU, UN and OFAC consolidated lists; insolvency-register check; UBO from the commercial register where available
  • EU AI Act applicability — Annex III / GPAI — and obligations gap, with the basis for each conclusion stated
  • AI red-team probe (prompt injection · jailbreak · PII leakage) where the vendor exposes a testable endpoint — otherwise reported as not tested
  • Written recommendation: verified facts, open gaps and conditions of use — each finding with source, date and verification status
  • Named analyst; scope, price and delivery date confirmed before payment

Delivered as a signed PDF within 5 business days of scope confirmation. Anything outside the agreed scope is stated as not assessed.

Enterprise

€4 900
per quarter · 15-vendor minimum · scoped engagement

15+ vendors, regulated industries, a portfolio reviewed every quarter.

  • Everything in Pro, applied across your vendor portfolio
  • Quarterly re-review of every vendor in scope; changes since last review called out
  • Dedicated analyst and a quarterly executive briefing
  • Continuous monitoring, SSO and GRC integrations are scoped and priced per contract — not off the shelf
  • Additional vendors €199 / vendor / quarter

Scope, onboarding and integrations are agreed in the contract before any invoice.

Why PartnerScope

Built for the EU risk stack.

EU

Built for the EU stack.

EU AI Act, GDPR Art. 28, DORA Art. 28–30, NIS2. Every finding mapped to regulation and Annex.

Evidence you can audit.

Every finding states its source, date, what was tested and its verification status. Unknowns stay unknowns — they are never scored.

Independent and named.

Every Pro report is signed by a named analyst. 15-day vendor right-of-reply.

Free snapshot · 60 seconds · no account

Get a 60-second AI-risk snapshot

Answer 4 questions about a vendor you're evaluating. We score it against three AI-specific dimensions (data provenance, model transparency, regulatory readiness) and email you a preview alongside your upgrade path.

  1. 1
    Data Provenance
    The vendor can fully document training data sources for their AI models.
    1 — No lineage — cannot say where data came from. 5 — Complete lineage with licences and consent basis.
  2. 2
    Model Transparency
    The vendor publishes a Model Card or System Card for each model in production.
    1 — None published. 5 — Comprehensive, updated with every release.
  3. 3
    Model Versioning
    Model versions are tracked and clients are notified of material changes.
    1 — No versioning. 5 — SemVer + changelog + client notice.
  4. 4
    EU AI Act Readiness
    The vendor has completed EU AI Act Annex III self-assessment (and registered, if applicable).
    1 — Not started. 5 — Registered, documentation ready.
GDPR: EU-hosted, 90-day lead retention, privacy.

Frequently asked

Questions buyers ask before signing the PO

How is this different from our existing GRC tool?

We are a data source, not a replacement. Reports are delivered as PDF; structured JSON is available on request. Direct GRC integrations (ServiceNow, Archer, OneTrust, SAP Ariba) are scoped per Enterprise contract, not available off the shelf.

Do vendors have to pay?

No. The buyer pays; vendors are asked for documents and answers at no cost.

Who runs the red-team?

Our analyst, using a catalogue aligned to OWASP LLM Top 10 (2025), MITRE ATLAS and NIST AI RMF — and only where the vendor exposes a testable endpoint under agreed rules of engagement. Otherwise the report says "not tested".

GDPR / EU hosting?

Yes. Data is stored in Germany (Hetzner, Falkenstein). DPAs signed with every customer. Sub-processors are listed at partnerscope.eu/legal/sub-processors.

Refunds?

Nothing is charged before scope is confirmed. If we cannot deliver the agreed scope, undelivered work is refunded pro-rata.

Can we self-serve?

Not yet. Starter and Pro start with a short request form; we confirm scope within one business day and send a Stripe payment link. Enterprise requires a scoping call (portfolio sizing, SSO, integrations).

Ready to start?

Request a Starter snapshot — or talk to us about Pro and Enterprise.

Curious how we score vendors? See our assessment methodology →