Full Vendor Lifecycle Management

Most TPRM programs scatter the vendor lifecycle across onboarding forms, questionnaire tools, scanning consoles, and calendar reminders. Fair TPRM handles every phase in one system — from intake to annual review, tracked, automated, and audited.

The Vendor Journey — All in One Place

Six phases, one platform. No context switching between tools, no manual hand-offs, no vendors slipping through the cracks.

1

Onboarding

Structured intake form captures vendor metadata, data security questions, and FAIR analysis inputs. Autosave via AJAX prevents data loss. Stakeholders are assigned as owners, reviewers, or observers.

2

Security Assessment

Template-driven questionnaires are sent to vendors via secure UUID links — no account required. ISO 27001 and Tier 2 templates included out of the box. All file uploads are encrypted at rest.

3

FAIR Analysis

Risk analysts run the built-in calculator, implementing the FAIR™ risk taxonomy developed by the FAIR Institute, to produce ALE figures. Assessment submission auto-creates a draft FAIR analysis, pre-populating data from the vendor's security responses.

4

Continuous Monitoring

Once approved, vendors enter tier-based SRS monitoring via built-in API integrations with UpGuard and Shodan. Scores are tracked over time. Score drops and overdue rescores surface in the Cyber Todo dashboard.

5

Annual Review

Reviews are scheduled one year from vendor approval. Email reminders fire at 30 days, on due date, and every 7 days when overdue. Stakeholders complete a structured review form.

6

Ongoing Governance

The Cyber Todo dashboard aggregates action items: expiring certificates, overdue rescores, score drops, unapproved vendors, and custom tasks into one prioritized view.

Structured Vendor Onboarding

No separate intake tool required. The onboarding form is the entry point for every vendor relationship, and data entered here flows directly into FAIR analysis, SRS monitoring, and assessment workflows — because it's all one system.

  • Vendor metadata: name, domain, type, industry, contact info
  • Data security: PII/PHI exchange, cross-border transfers, remote access
  • FAIR inputs: record counts, business impact, daily operational costs
  • Stakeholder assignment with owner, stakeholder, and reviewer roles
  • Status workflow: Draft → Submitted → In Review → Approved → Active
  • CSV bulk import with duplicate detection
Form Fields 50+ columns
Autosave Every keystroke
Bulk Import CSV
Permission-Aware Per-role visibility
Stakeholder Roles 3 types

Template-Driven Assessments

No third-party questionnaire tool needed. Vendors complete security assessments through built-in public-facing forms accessed via unique UUID links. Submissions auto-create draft FAIR analyses and trigger SRS scoring — all within the same platform.

  • ISO 27001:2022 comprehensive ISMS questionnaire
  • Tier 2 streamlined assessment for lower-risk vendors
  • Custom templates with sections, question types, and file uploads
  • Autosave on every response to prevent data loss
  • All uploaded files encrypted with AES-256-CBC at rest, TLS 1.3 in transit
  • ISO certificate upload option to skip detailed questionnaire
Access Method UUID Link
Built-in Templates 2 default
Question Types 6 types
File Encryption AES-256-CBC
CSRF Protection Token rotation

Automated Annual Reviews

No calendar reminders or separate ticketing system needed. Fair TPRM schedules reviews automatically one year from vendor approval, with a built-in three-tier email reminder system that prevents anything from falling through the cracks.

  • Automatic scheduling one year from vendor approval
  • Email reminders at 30 days, on due date, and weekly when overdue
  • Structured completion form for stakeholders
  • Scope change tracking and updated contact information
  • Complete review history per vendor
  • SMTP delivery with configurable email settings
30-Day Reminder Automated
Due Date Reminder Automated
Overdue Reminders Every 7 days
Review History Full archive
Cron Managed With locking

Enterprise Security & Compliance

Every feature is built with security-first design principles, protecting data with the strongest encryption available today.

🔒

SAML 2.0 SSO

Enterprise IdP support for Okta, Microsoft Entra ID, and other SAML providers. Group mapping syncs IdP groups to local ACL roles automatically on login.

📱

TOTP Two-Factor Auth

RFC 6238 time-based one-time passwords compatible with Google Authenticator and Authy. QR code enrollment makes setup simple for end users.

📋

Complete Audit Trail

Every action is logged with user ID, action type, affected record, old/new values, IP address, and user agent. Full accountability for compliance audits.

👥

User Impersonation

Super admins can "View As" another user for troubleshooting. Original session is preserved, amber banner is displayed, and all actions are audit logged.

Data Protection — At Rest and In Transit

Fair TPRM applies the highest level of encryption at every layer. Sensitive data is encrypted at rest using AES-256-CBC, while all data in transit is secured with TLS 1.3 supporting post-quantum resistant key exchange and the latest cipher suites and algorithms. Your vendor risk data is protected against both today's threats and tomorrow's quantum computing capabilities.

  • AES-256-CBC encryption for all sensitive database fields
  • 40+ individually encrypted fields for FAIR and vendor data
  • All uploaded assessment files encrypted at rest
  • TLS 1.3 enforced for all data in transit
  • Post-quantum resistant key exchange (ML-KEM / Kyber)
  • Modern cipher suites: ChaCha20-Poly1305, AES-256-GCM
  • Argon2id password hashing (memory-hard, GPU-resistant)
  • HSTS, CSP, and full security header suite
Encryption at Rest AES-256-CBC
Transport Security TLS 1.3
Key Exchange Post-Quantum (ML-KEM)
Cipher Suites ChaCha20 / AES-GCM
Password Hashing Argon2id
Quantum Resistant Yes

Deploy Your Way

Host Fair TPRM on-premises in your own data center for full control, or let us host and manage the platform for you.

On-Premises

Deploy Fair TPRM in your own data center or private cloud. Your data never leaves your infrastructure, giving you complete control over security, compliance, and network policies. Ships with Docker Compose for instant deployment or installs on any Apache + PHP 8.3 server.

Managed Hosting

Let Fair TPRM handle the infrastructure. We host, maintain, and update the platform so your team can focus on managing vendor risk instead of managing servers. Includes monitoring, backups, and guaranteed uptime.

On-Prem Deployment

For organizations that require data sovereignty or have strict compliance requirements, Fair TPRM deploys entirely within your own infrastructure. No external dependencies, no data leaving your network — just a self-contained platform under your full control.

  • Docker Compose: PHP 8.3 + Apache + MariaDB
  • MySQL/MariaDB or SQLite database options
  • 6-step setup wizard with no coding required
  • Theme customization: colors, logos, fonts
  • Database backup and restore from admin panel
  • SQL migration system with preview and rollback
# Docker Compose Stack
services:
  tprm-web:
    image: php:8.3-apache
    ports: ["8080:80"]

  tprm-db:
    image: mariadb:10
    volumes: [data:/var/lib/mysql]

Managed Hosting by Fair TPRM

Not every organization wants to manage infrastructure. With managed hosting, Fair TPRM runs the platform for you — deployed, monitored, backed up, and updated — so your team stays focused on vendor risk, not server administration.

  • Fully managed infrastructure with guaranteed uptime
  • Automatic updates and security patches
  • Daily encrypted backups with point-in-time recovery
  • TLS 1.3 with post-quantum resistant cipher suites
  • Dedicated instance — no shared tenancy
  • Same platform, same features — zero compromise
Infrastructure Fully Managed
Updates Automatic
Backups Daily Encrypted
Tenancy Dedicated Instance
Transport Security TLS 1.3 + PQ
Feature Parity 100%

One Platform. Your Infrastructure or Ours.

Deploy on-premises for full data sovereignty or let us host it for you. Either way, you get the same unified platform with zero compromises.

Back to Home FAIR Analysis Security Monitoring