OpenDD
HomeDue diligence › Free Third-Party & Vendor Due Diligence

Free third-party & vendor due diligence

Every vendor you onboard is a risk you inherit. OpenDD assesses a third party's security, privacy, data-governance and AI posture from its own published trust materials, screens it for adverse media and sanctions, and scores the gaps — for free.

Assess a vendor free →

A trust posture, scored

OpenDD discovers a company's trust pages, policies and disclosures and scores them against recognised expectations — SOC 2 and ISO 27001 for security, GDPR and CCPA for privacy — flagging where a control is present, partial or absent, plus objective signals measured directly (HTTPS, security headers, email authentication).

Beyond the questionnaire

A vendor questionnaire tells you what the vendor says; OpenDD checks what it actually publishes and what the public record shows. Pair the trust assessment with adverse media and sanctions screening for a complete third-party risk view.

Repeatable and free

Run it at onboarding and on renewal, and set up monitoring so you are alerted when a vendor's posture changes. See the third-party vendor due diligence guide for the full workflow.

Related

Third-party vendor due diligencePrivacy due diligence (GDPR/CCPA)SOC 2 vs ISO 27001
Run it free. Every vendor you onboard is a risk you inherit. Assess a vendor free →

Frequently asked questions

How do I do vendor due diligence for free?

Enter the vendor in OpenDD's trust modules (security, privacy, data governance, AI). It scores their posture from their own disclosures and screens adverse media and sanctions — no cost to start.

What frameworks does it reference?

SOC 2 and ISO 27001 for security, GDPR and CCPA for privacy, plus objective technical signals measured directly against the vendor's live site.

Can I monitor vendors over time?

Yes. Add a vendor to monitoring and OpenDD re-checks its posture on a schedule and alerts you to material changes.

Informational only, not legal advice. See our Terms, Privacy Policy and DPA.