๐Ÿ”— ~9,000 schools were breached through one vendor โ€” none of them ran a vulnerable server. Vendor risk means owning the consequences of someone else's mistake. Three questions per vendor, honestly scored, is a working register. This tracker supports vendor-risk and GV.SC-style workflows โ€” it is not legal advice; contract terms need your attorney.

How to use this (3 steps)

  1. Duplicate this page into your workspace (top-right).
  2. One copy per client. Rename it: Vendors โ€” [Client].
  3. Add a row for every vendor that touches client data, then score brutally โ€” ๐ŸŸก means "from memory," and memory doesn't survive incidents.

Vendor Register

Contract-Clause Checklist (Q2 helper)

The afternoon drill


๐ŸŠ Vendor rows are one table. The whole posture is the product. AxiomLens runs the rest of the review โ€” 106 controls, computed coverage, evidence tied to controls, and the board report written locally. Nothing phones home after activation. It supports compliance documentation and audit-prep workflows (it's a tool, not a certification). See it run (2 min): youtu.be/namYnNbox4k ยท Store: thesecuritygator.gumroad.com ยท Free Tuesday issue: thesecuritygator.com

Siblings: Gatorbyte #001 โ€” the 10-missed-controls field guide ยท #002 โ€” the CSF Govern tracker ยท #003 โ€” the Evidence Register ยท #004 โ€” the Shadow AI Starter Kit ยท #005 โ€” the CaaS Pricing & Scoping Worksheet.