Findings (CloudVRM)
CloudVRM automates real-time third-party cloud risk auditing, connecting directly to vendor AWS/Azure/GCP environments for continuous compliance data.
Visit Website ↗ + Add to CompareOverview
Findings offers CloudVRM, a vendor risk management platform that connects directly and securely to a vendor’s cloud environment via encrypted APIs, pulling configuration data on a continuous basis rather than relying on the periodic questionnaires and point-in-time attestations typical of legacy third-party risk management. The platform automatically scans for more than 150 risk indicators — including misconfigurations, compliance drift, and vulnerabilities — and maps findings against more than 15 frameworks including DORA, NIST, and HIPAA to generate audit-ready reports.
Findings markets CloudVRM as adopted by global banks, Ministries of Defence, and critical infrastructure providers, with published customer references from organizations including SDN, FIBI, MalamTeam, and Engine. The company has also extended its coverage to track AI-generated code and productivity-tool exposure risk in vendor environments through its AiVRM offering, addressing a gap most traditional VRM programs don’t yet cover.
Third-party and vendor risk management is a well-established category with entrenched competitors like BitSight, Panorays, and UpGuard. Findings’ differentiation is direct, continuous cloud-API connectivity rather than survey-based assessment, which is a genuine improvement in data freshness, though independent, detailed founding and funding information for the company was not available in the sources reviewed.
Innovation Matrix Assessment
Extended from cloud configuration monitoring into AI-code and productivity-tool risk tracking as vendor risk profiles shifted.
Continuous, API-based vendor risk data is materially more useful to risk teams than static, periodic questionnaires.
Named customer references (SDN, FIBI, MalamTeam, Engine) are a positive signal, but broader funding and scale data are undisclosed.
Real-time cloud-API connectivity is a genuine step beyond survey-based VRM, in a category with several established, well-funded competitors.
Named customer testimonials lend some credibility, though independent, quantified efficacy data was not found.
Third-party and AI-supply-chain risk visibility will keep growing in importance as vendor ecosystems and AI tool usage expand.
Why CISOs Should Care
Replaces slow, static vendor risk questionnaires with continuous, API-based visibility into vendor cloud security posture.
What Makes It Different
Direct, encrypted API connections into vendor cloud environments (AWS/Azure/GCP) for real-time risk data, rather than periodic self-attestation surveys.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A useful, technically sound approach to continuous vendor risk monitoring; a Meaningful Innovator, though funding and scale transparency are limited.
Editorial Note: Claims vs. Verified Findings
Customer names are drawn from published testimonials on the company's own site; founding year, HQ, and funding were not independently confirmed.
Sources
Alternatives to Findings (CloudVRM)
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…