Vendict
Israeli GRC startup using generative AI to automate security questionnaire responses and third-party vendor risk assessments for enterprise sales and procurement teams.
Visit Website ↗ + Add to CompareOverview
Vendict is a Tel Aviv-area (Ramat Gan) startup founded in 2020 that uses generative AI to automate two related, historically manual GRC workflows: responding to inbound security questionnaires from prospects and customers, and managing third-party/vendor risk assessments on the buy side. The company emerged from stealth in 2023 with $9.5 million in seed funding and has since raised a total of roughly $31.5 million, including a $10 million Series A in August 2025.
On the sell side, Vendict’s platform ingests a vendor’s own security documentation (SOC 2 reports, policies, prior questionnaire answers) and uses that knowledge base to auto-draft responses to incoming security questionnaires, cutting a process that traditionally takes days or weeks of manual cross-referencing down to hours. On the buy side, its newer Managed Third-Party Risk Management offering uses AI agents to chase vendors for outstanding documentation, extract relevant security and privacy details from what’s submitted, check those details against the buyer’s own control requirements, and surface risk findings for the reviewing team.
The company’s relevance sits squarely in the GRC/vendor-risk space, where security questionnaire fatigue is a well-known, widely complained-about pain point on both sides of enterprise sales cycles. Vendict is available on AWS Marketplace, which suggests some enterprise procurement traction, though independent, named case studies quantifying time or cost savings were not found in current public reporting; the specific efficiency claims come from the company itself.
Innovation Matrix Assessment
Vendict expanded from questionnaire-response automation into a full Managed Third-Party Risk Management product with AI agents within about two years of exiting stealth, a fast expansion of scope for a small team.
At roughly 39 employees and five years old, Vendict has moved past pure early-stage but has not yet demonstrated the operational scale of established GRC platforms.
A $10 million Series A in August 2025 brought total funding to roughly $31.5 million across four rounds, and an AWS Marketplace listing suggests real enterprise procurement traction alongside the funding trajectory.
Applying generative AI to both sides of the vendor-questionnaire workflow (answering and assessing) is a genuine efficiency play against a well-known, widely disliked manual GRC bottleneck, though competitors are pursuing similar AI-questionnaire approaches.
Time-savings and accuracy claims (questionnaires cut from weeks to hours) are vendor-stated; no independent case study, named customer outcome, or third-party benchmark of Vendict's output accuracy was found in public reporting.
Security questionnaire fatigue and third-party risk backlogs are a near-universal enterprise GRC pain point, giving Vendict's product a broad, well-understood buyer need on both the sales and procurement sides.
Why CISOs Should Care
For CISOs whose GRC or sales-engineering teams are drowning in inbound security questionnaires, or whose procurement team can't keep pace with vendor risk reviews, Vendict targets a concrete, quantifiable time sink with AI automation on both sides of the process.
What Makes It Different
Vendict addresses both the sell-side (answering questionnaires) and buy-side (assessing vendors) of the same workflow with one platform, rather than the more common single-sided questionnaire-automation approach.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A well-funded, fast-moving GRC automation vendor addressing a genuine and widely felt pain point, though its specific efficiency and accuracy claims still rest on vendor-supplied figures rather than independent validation.
Editorial Note: Claims vs. Verified Findings
Funding figures ($9.5M seed, $31.5M total, $10M Series A in August 2025) are independently reported by trade press (Calcalist, VentureBeat) and funding databases. Specific efficiency claims (questionnaires shortened from weeks to hours, hundreds of hours saved monthly) are vendor-stated and were not independently verified via named customer case studies.
Sources
Alternatives to Vendict
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…