Third-party AI risk — without the 40-page questionnaire
PartnerScope assesses your vendors across 13 dimensions — behavioural, financial, and
AI-compliance — with automated tests, documentary review and AI red-teaming. Drop-in
reports aligned with EU AI Act, GDPR, DORA and NIS2.
Starter is an external technical snapshot of a vendor domain. Pro and Enterprise apply the
13-dimension framework: documentary review, a named analyst, and — for Enterprise — ongoing
monitoring after delivery.
Starter
€99
Single vendor · external technical snapshot · one-time
An external technical snapshot of one vendor domain — plus the questions to ask them next.
Automated checks on the vendor domain: DNS, TLS, HTTP security headers, Certificate Transparency log
Each check reported with time, object tested and its limits — a failed service is reported as "not checked", not as a finding
Open questions for the vendor, derived from what the checks could not see
No composite score and no proceed/decline verdict — those require Pro
Scope, onboarding and integrations are agreed in the contract before any invoice.
Why PartnerScope
Built for the EU risk stack.
EU
Built for the EU stack.
EU AI Act, GDPR Art. 28, DORA Art. 28–30, NIS2. Every finding mapped to regulation and
Annex.
✓
Evidence you can audit.
Every finding states its source, date, what was tested and its verification status.
Unknowns stay unknowns — they are never scored.
★
Independent and named.
Every Pro report is signed by a named analyst. 15-day vendor right-of-reply.
Free snapshot · 60 seconds · no account
Get a 60-second AI-risk snapshot
Answer 4 questions about a vendor you're evaluating. We score it against three AI-specific
dimensions (data provenance, model transparency, regulatory readiness) and email you a
preview alongside your upgrade path.
We are a data source, not a replacement. Reports are delivered as PDF; structured JSON is available on request. Direct GRC integrations (ServiceNow, Archer, OneTrust, SAP Ariba) are scoped per Enterprise contract, not available off the shelf.
Do vendors have to pay?
No. The buyer pays; vendors are asked for documents and answers at no cost.
Who runs the red-team?
Our analyst, using a catalogue aligned to OWASP LLM Top 10 (2025), MITRE ATLAS and NIST AI RMF — and only where the vendor exposes a testable endpoint under agreed rules of engagement. Otherwise the report says "not tested".
GDPR / EU hosting?
Yes. Data is stored in Germany (Hetzner, Falkenstein). DPAs signed with every customer. Sub-processors are listed at partnerscope.eu/legal/sub-processors.
Refunds?
Nothing is charged before scope is confirmed. If we cannot deliver the agreed scope, undelivered work is refunded pro-rata.
Can we self-serve?
Not yet. Starter and Pro start with a short request form; we confirm scope within one business day and send a Stripe payment link. Enterprise requires a scoping call (portfolio sizing, SSO, integrations).
Ready to start?
Request a Starter snapshot — or talk to us about Pro and Enterprise.