Vendor Security Review by Qeluntra

Done for you · fixed price · report in 5 business days

Vendor security reviews, done for you

Name the vendor. We collect their evidence, read their SOC 2 report, check how they handle your data and AI, and send you a risk-rated report with the exact follow-ups to ask for. No software to set up.

  • Fixed price per vendor, from $499
  • Covers AI and data handling: model providers, training on your data, sub-processors
  • Report ready for your auditors, security questionnaire answers and customer due diligence

See prices What's in the report

1

Order and name the vendor

Pay securely with Stripe and tell us the vendor, its website and what data or systems it will touch.

2

We gather the evidence

We send the vendor a short security questionnaire and collect their SOC 2 / ISO 27001 reports, trust centre, policies and public security record.

3

You get a decision-ready report

Risk rating, findings by control area, gaps in the SOC 2 report, contract clauses to add and a yes / yes-with-conditions / no recommendation.

Fixed prices, per vendor

One-time payment. No subscription. Volume pricing for 5+ vendors below.

Essentials

$499 / vendor

Low-risk vendors and SaaS tools with limited data access.

  • Security questionnaire sent to the vendor and chased
  • Certifications and trust centre checked
  • Public breach and security record check
  • Risk rating with top findings
  • PDF report in 5 business days
Order Essentials

Recommended

Professional

$1,250 / vendor

Vendors that store or process your customer data.

  • Everything in Essentials
  • Full SOC 2 report review: scope, exceptions, carve-outs and complementary user entity controls you must operate
  • AI and data review: model providers, training on your data, retention, sub-processors
  • Contract and DPA red flags with suggested clauses
  • One round of follow-up questions with the vendor
  • Report in 5 business days
Order Professional

Critical vendor

$2,500 / vendor

Core infrastructure, payments, AI platforms and anything production-critical.

  • Everything in Professional
  • Live call with the vendor's security team
  • Deeper review of access, incident response, business continuity and fourth parties
  • Two follow-up rounds and a remediation plan to agree with the vendor
  • Executive summary for your board or customers
  • Report in 7 business days
Order Critical review

Reviewing 5 or more vendors?

Bundles save up to 20%, and if you review vendors every month, Qeluntra's supplier risk platform runs questionnaires, scoring and re-reviews for your whole vendor list. Email Farhan@qeluntra.com with your vendor count for a quote.

What's in the report

  1. Decision: approve, approve with conditions, or do not approve, with the reasons.
  2. Risk rating: inherent risk (what the vendor touches) and residual risk (after their controls).
  3. Findings by control area: governance, access and identity, encryption, logging and monitoring, vulnerability management, incident response, business continuity, sub-processors, and AI and data use.
  4. SOC 2 report analysis (Professional and above): is the report current, does its scope cover the service you buy, which exceptions matter, and which controls you are expected to run.
  5. Follow-ups and contract asks: the exact questions and clauses to send the vendor.
  6. Evidence log: everything we reviewed, dated, so your auditor can see the work.

Why reviews now include AI

Most vendors have added AI features in the last two years. That raises questions a traditional security questionnaire does not ask: is your data used to train models, which model providers receive it, how long prompts and outputs are kept, and whether AI agents inside the product can take actions in your systems. Every review we do from Professional upwards answers these questions.

Do it yourself instead

If you'd rather run reviews in-house, use our free vendor risk questionnaire and track results in Qeluntra.

Frequently asked questions

How long does a review take?

Essentials and Professional reports arrive within 5 business days, Critical vendor reports within 7 business days, counted from when the vendor's evidence arrives. We chase the vendor for you.

What if the vendor won't respond?

We review the public evidence (trust centre, certifications, policies, security incidents) and record non-response as a finding, so you still get a report you can act on.

Is this an audit or a certification?

No. It's an independent risk review that supports your own third-party risk decision. It isn't an audit, attestation or legal advice, and it doesn't certify the vendor.

Will you sign an NDA?

Yes. We sign your NDA or the vendor's before receiving any confidential report, and we only use the evidence for your review.

What if I need to cancel?

Full refund if we haven't started the review. Once work has begun, we refund the unused portion.

Order a review

Choose a plan above. After payment you'll be asked for the vendor's name and website, and we'll confirm by email within one business day.

Questions first? Email Farhan@qeluntra.com.