Vendor Security Alliance
- Company typePrivate
- Founded2016
- HeadquartersMenlo Park, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
Vendor Security Alliance firmographics
Firmographics- Name
- Vendor Security Alliance
- Legal name
- Vendor Security Alliance
- Website
- https://vendorsecurityalliance.org
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
Vendor Security Alliance industry classification
Industry- Product category
- Third-Party Risk Management
- SIC
- Services-Membership Organizations (8600), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Third-Party Monitoring, Vendor Risk & Control Testing for Market Infrastructure (FSAFAKAO)
- akta.pro secondary industry
- Vendor & Contract Management (Software/Cloud) (BPAEAOAD)
Keywords
Where Vendor Security Alliance is headquartered
LocationHeadquarters
- HQ city
- Menlo Park
- HQ country
- United States
- HQ region
- North America
Markets served
Vendor Security Alliance business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Membership Fees: Companies pay membership fees to join the VSA coalition and gain access to auditor networks, questionnaire platforms, and audit report sharing capabilities.
- Audit Services: Starting at $1300 USD per audit, members can leverage the network of third-party auditors for risk-based vendor assessments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Unit Pricing | Pay-as-you-go | Audit Services - Starting at $1300 USD per audit |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
Vendor Security Alliance product offering
Product offeringCore offering
Vendor Security Alliance is a non-profit coalition that provides standardized vendor security assessment questionnaires (VSA-Full and VSA-Core) and a network of third-party auditors to conduct risk-based vendor assessments for member companies. Members gain access to the questionnaires, auditor network, and online platforms (Whistic and OneTrust) to outsource vendor due diligence and receive executive summary audit reports.
Product overview
The Vendor Security Alliance offers a coalition-based vendor security assessment program consisting of two free questionnaires (VSA-Full for comprehensive security and VSA-Core for critical security plus privacy/CCPA/GDPR). The organization provides an end-to-end VSA Audit Service where third-party auditors verify questionnaire responses and deliver executive summary reports. VSA members receive exclusive access to the Whistic platform for questionnaire completion and audit report management. The VSA is organized as a non-profit organization with membership starting at $1300 USD per audit.
Differentiator
Problem solved
Functional benefit
Products and services
- VSA-Full Questionnaire A standardized vendor security questionnaire that focuses deeply on vendor security practices. Used by thousands of companies globally and updated annually. Available as a free download from the VSA website.
- VSA-Core Questionnaire A streamlined questionnaire comprising the most critical questions on vendor security plus privacy coverage for US Privacy (data breach notification requirements plus CCPA) and EU Privacy (GDPR). First available October 24th, 2019.
- VSA Audit Service An end-to-end audit service for member companies that outsources vendor due diligence to the VSA. Vendors complete the selected questionnaire online, results are audited by an experienced auditor with answers verified by follow-up interview, and members receive an executive summary report plus the completed questionnaire.
- Whistic Platform Access Exclusive access to the Whistic platform as part of VSA membership. Vendors complete questionnaires in an intuitive online interface, add teammates, assign questions, set internal due dates, collaborate, manage responses over time, and share completed questionnaires with other companies.
Quantifiable outcome
- More vendor audits significantly lowers existing vendor risk
- +1 more outcomes
Companies that use Vendor Security Alliance
Customer profileNamed customers6 records
Segments2 records
Ideal customer profiles1 record
Vendor Security Alliance technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
Feature4 records
Vendor Security Alliance partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered flagship and core.
- VSA Founding CompaniesflagshipThe VSA was formed by founding companies committed to improving Internet security. Founding members include Docker, Dropbox, Airbnb, Coinbase, TaskUs, and Adobe. The coalition was organized as a non-profit organization.
- WhisticcoreWhistic is the online platform partner for the VSA Full Security Assessment program. Members get exclusive access to Whistic as part of VSA membership and can access VSA audit reports in the same place they manage their entire vendor risk management program.
- OneTrust (Vendorpedia)coreOneTrust is the online platform partner for the new combined Security Assessment & Privacy program: VSA Core. Provides the online interface for the VSA Core questionnaire covering both security and privacy assessments.
Scale indicators2 records
Recent moves6 records
Expansion highlights4 records
Vendor Security Alliance competitors and assessment
Company assessmentDirect peers
- SecurityScorecard: Leading commercial vendor risk management platform offering security ratings, automated questionnaires, and risk monitoring. Directly competes with VSA's third-party risk assessment offering for enterprise buyer mindshare and budget.
- Bitsight: Enterprise vendor risk and security ratings provider offering continuous monitoring and third-party risk analytics. Competes with VSA by providing an alternative, data-driven assessment methodology to enterprises evaluating vendor security.
- UpGuard: Vendor risk management and attack surface monitoring platform with automated questionnaires and security ratings. Closely comparable in offering vendor due diligence questionnaires plus continuous monitoring, overlapping with VSA's questionnaire-plus-audit model.
- CyberGRX: Third-party cyber risk management platform offering a shared assessment exchange model that directly parallels VSA's coalition-based approach of letting enterprises share and reuse vendor risk data.
- Whistic: Proactive vendor security and third-party risk management platform; serves as VSA's distribution partner for VSA-Full but also offers its own assessment exchange, creating partial overlap in vendor due diligence workflows.
- ProcessUnity: Third-party risk management platform with vendor onboarding, assessments, and ongoing monitoring. Competes for the same buyer (TPRM teams) and overlaps with VSA's questionnaire-and-audit workflow.
- Venminder: Third-party risk management solution providing vendor assessments, risk monitoring, and due diligence documentation. Comparable in serving mid-market and regulated enterprises that need standardized vendor risk processes.
Broad incumbents
- OneTrust: Broad trust intelligence platform covering privacy, security, and third-party risk. Functions as VSA's distribution partner for VSA-Core while also offering native vendor risk capabilities that overlap with VSA's content.
- ServiceNow GRC (Vendor Risk Management): Enterprise GRC suite with integrated vendor risk management workflows used by large regulated enterprises. Competes for TPRM budget at the high end of the market where VSA's coalition approach is also pitched.
- RSA Archer: Enterprise governance, risk, and compliance platform with vendor risk management modules. Targets the same regulated buyer as VSA but as part of a much broader GRC portfolio.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Vendor Security Alliance social profiles
Digital presenceVendor Security Alliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
Vendor Security Alliance leadership team
Management profileNumber of profiles
Profiles3 records
Vendor Security Alliance funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Vendor Security Alliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Vendor Security Alliance
What does Vendor Security Alliance do?
Vendor Security Alliance is a non-profit coalition that provides standardized vendor security assessment questionnaires (VSA-Full and VSA-Core) and a network of third-party auditors to conduct risk-based vendor assessments for member companies. Members gain access to the questionnaires, auditor network, and online platforms (Whistic and OneTrust) to outsource vendor due diligence and receive executive summary audit reports.
Is Vendor Security Alliance a public or private company?
Vendor Security Alliance is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Vendor Security Alliance founded?
Vendor Security Alliance was founded in 2016. It employs 1 to 10 people.
Where is Vendor Security Alliance based?
Vendor Security Alliance is headquartered in Menlo Park, United States, in the North America region.
How does Vendor Security Alliance make money?
Two revenue lines are on record. Membership Fees are the primary driver. The others are audit Services.
Who are Vendor Security Alliance's main competitors?
Direct peers on record are SecurityScorecard, Bitsight, UpGuard, CyberGRX, Whistic, ProcessUnity and Venminder. Broad incumbents are OneTrust, ServiceNow GRC (Vendor Risk Management) and RSA Archer.
Does Vendor Security Alliance have an API?
No public API is recorded for Vendor Security Alliance.
What industry is Vendor Security Alliance in?
Vendor Security Alliance's product category is Third-Party Risk Management. Its primary akta.pro industry code is FSAFAKAO, Third-Party Monitoring, Vendor Risk & Control Testing for Market Infrastructure, with a secondary code of BPAEAOAD, Vendor & Contract Management (Software/Cloud). Its SIC code is 8600.