Skip to content

Panorays

Third-party cyber risk management platform combining continuous external attack-surface scanning with context-based, AI-assisted vendor questionnaires.

Visit Website ↗
68/100Incremental Innovator

Overview

Panorays was founded in Israel in 2016 by Matan Or-El, Meir Antar, and Demi Ben-Ari and is now headquartered in New York, with continued Israeli R&D presence. It automates third-party security risk assessment by combining continuous external attack-surface scanning of a vendor’s infrastructure with internal-style questionnaires and certification review, producing what it calls ‘Risk DNA’ ratings that factor in business criticality and data-access levels rather than a one-size-fits-all score.

Its AI features focus on auto-completing vendor questionnaires from prior responses and scanning submitted documentation for compliance verification, aiming to compress the weeks-long back-and-forth of manual vendor due diligence. Panorays has raised roughly $100 million total, including a $42 million Series B in September 2021, and was recognized in Forrester’s Q2 2026 Wave for Cybersecurity Risk Ratings, though no major funding round has been reported since 2021, and detailed current customer counts are not publicly disclosed.

Innovation Matrix Assessment

Innovation Velocity 7/10

Added AI-driven questionnaire auto-completion and real-time breach-probability prediction on top of its original scanning-plus-questionnaire model.

Operational Value 7/10

Combining automated external scanning with questionnaire and certification review directly reduces the manual back-and-forth typical of vendor due diligence.

Market Momentum 6/10

Recent Forrester Wave recognition is a positive signal, but no funding round has been reported since a 2021 Series B, suggesting momentum has slowed relative to peers.

Category Disruption 7/10

Context-based, continuously updated 'Risk DNA' ratings that reflect business criticality are a genuinely different approach from static, point-in-time vendor questionnaires.

Real-World Efficacy 6/10

Described as serving 'hundreds of enterprise customers' in financial services and technology, but no independent efficacy statistics were found.

Enduring Relevance 8/10

Third-party and supply-chain risk is an increasingly regulated area (DORA's ICT third-party risk requirements, for example), keeping continuous vendor-risk monitoring highly relevant.

Why CISOs Should Care

It replaces static, annual vendor questionnaires with continuously updated risk visibility tied to actual business criticality, helping CISOs prioritize which vendor relationships need attention now rather than at renewal time.

What Makes It Different

Combines automated external scanning with contextual, business-criticality-weighted scoring rather than a generic security rating, differentiating it from pure ratings services like BitSight.

The Matrix Verdict

68/100 — INCREMENTAL INNOVATOR

A genuinely innovative mid-tier entry: its context-based, continuous approach to third-party risk is a real structural improvement over static questionnaires, but slowing funding momentum and thin independent efficacy evidence keep it out of the top tier.

Editorial Note: Claims vs. Verified Findings

Funding totals vary slightly across PitchBook, Crunchbase, and Tracxn; specific customer counts and the 'Risk DNA' methodology description come from the company's own site and were not independently corroborated.

Sources