Skip to main content
The Vendor Directory is VISO TRUST’s catalog of known third-party organizations. It contains pre-populated company profiles that help VISO TRUST build more accurate instant assessments — faster and with less manual input.

What the Directory Contains

Each directory entry includes:
  • Company name, website, and primary domain(s)
  • Industry classification
  • Headquarters location and company size
  • Known compliance certifications (SOC 2, ISO 27001, etc.)
This information is used to pre-populate vendor profiles when you create a relationship and to seed instant assessments with publicly available intelligence.

Searching the Directory

The directory is accessible when you Add a Relationship. Type the vendor’s name into the search field and VISO TRUST will suggest matches from the directory. When you select a vendor from the directory:
  • Company details are automatically populated in the relationship
  • VISO TRUST can immediately offer to predict relationship context based on the vendor’s profile
  • Instant assessment runs with richer starting data than an unknown vendor

When a Vendor Isn’t in the Directory

If you search and don’t find the vendor, select Create new third-party organization at the bottom of the search results. Enter the vendor’s name and website URL.
Providing a website URL for vendors not in the directory is important. Without a URL, VISO TRUST has limited ability to conduct a public research assessment and the risk analysis will be less predictive.
Once you create a new vendor entry, VISO TRUST will begin building a profile for that organization using publicly available information.

Public Artifacts and Certifications

When VISO TRUST finds publicly available evidence for a vendor — security pages, compliance badges, trust portals, public audit summaries — it uses that evidence to derive initial control coverage:
  • Publicly available artifacts (full documents VISO TRUST can access): counted as present controls with full confidence
  • Compliance certifications (certification badges claimed on the vendor’s website): counted as partial coverage — lower assurance than a validated report
To get full credit and higher confidence, request the actual certification document (e.g., the SOC 2 report) from the vendor.
Organizations can control whether publicly claimed compliance certifications influence residual risk scoring. Go to Settings to manage this preference.