Start free trial

The whole review, not another questionnaire.

Urengi replaces questionnaire-driven vendor assessments with continuous, evidence-based reviews that cover the full vendor lifecycle. We chase, collect, score, and monitor so your team can focus on actual risk.

Every risk, surfaced before it satisfies.

Urengi maps every vendor to live evidence certificates, pentest reports, and breach history so your team reviews facts, not promises.

01 — Evidence VaultEvery document, every certificate, one living archive.

Urengi continuously collects SOC 2 reports, ISO certificates, pentest summaries, and insurance policies from public registries and vendor portals. Documents are parsed, classified, and version-tracked automatically — no shared folders, no expiry surprises.

02 — Risk ScoringA score you can defend to the board.

Each vendor receives a composite risk score built from evidence freshness, finding severity, and your custom weighting rules. Scores update in real time as new evidence arrives — no quarterly recalculation, no stale data.

03 — Compliance MappingOne evidence set, every framework covered.

Map collected evidence against SOC 2, ISO 27001, GDPR Article 28, and NIST 800-53 controls simultaneously. Urengi highlights gaps per framework and generates audit-ready reports without duplicating review effort.

04 — Workflow EngineReviews that move without a project manager.

Define review workflows with conditional routing, SLA escalation, and auto-approval thresholds. Urengi assigns tasks to the right reviewer based on vendor tier and risk domain — procurement never has to chase security again.

05 — ReportingBoard decks that write themselves.

Every vendor lands in one of four tiers, from a rules engine you control. Each score shows which inputs moved it, so when an auditor asks why a vendor is Standard, the answer is on the screen. Rules are visible, editable, and versioned — no black-box AI rating.

The first week, three vendors uploaded their SOC 2 without anyone from my team sending an email. That was the moment.

Marc Delhaye, IT Operations, Fold Systems (B2B SaaS)
Marc Delhaye, IT Operations at Fold Systems

380 companies. 41,000 vendors monitored.

Secure your supply chain, realistically

Ditch the spreadsheets and the endless chase. Pick a tier that keeps your procurement moving without losing compliance.

Starter

Ideal for early stage companies sorting their first vendor compliance checks.

$249/mo


  • Up to 25 vendor reviews/year
  • Automated questionnaire generation
  • Basic evidence collection
  • Email support
  • 2 team seats

Growth

Most popular

For active security teams managing automated workflows and scoring pipelines.

$749/mo


  • Up to 100 vendor reviews/year
  • AI-powered risk scoring
  • Full evidence automation
  • Priority support
  • 10 team seats
  • Custom review templates
  • Slack integration

Enterprise

Tailored review volume, custom rulesets, and deep compliance auditing.

Custom


  • Unlimited vendor reviews
  • Dedicated success manager
  • SSO & SCIM provisioning
  • Custom SLAs
  • Unlimited seats
  • API access
  • Audit log & compliance reports

Supporting Capabilities

The operational infrastructure required to run vendor compliance at enterprise scale.

Audit export

Single-click PDF/CSV compile of every review and approval for external regulators.

  • PDF
  • CSV
  • Regulator-ready

API and webhooks

Programmable interfaces to trigger assessments from external CRM or ERP commands.

Continuous monitoring

Posture changes surface as alerts between reviews.

Vendor inventory tracking

A unified source of truth with explicit business owners and planned renewal timelines.

Custom questionnaires

Drop in existing legacy matrices and let Urengi translate them to automated request logs.

Full audit logging

Every action, review score change, and reminder dispatch is permanently logged.

Immutable records

Every entry is hash-chained and sealed to WORM storage for seven years.

Spend visibility via accounting sync

Integrates directly with ERP systems to alert when unauthorized transactions occur.

SSO & SCIM provisioning

SAML integration and automated user directory syncing for large security divisions.

Approval workflows with delegation

Direct routing paths to legal, finance, and security officers with out-of-office logic.