Now Available

Provenance AI

Every answer you need (and every vendor's true risk posture) is already written down, in a document you own or one they sent you. Provenance AI finds it, fills it in or verifies it, and shows its source.

A ThreatWorx GRC & TPRM Solution

0%
Answers Backed
by Source Evidence
Framework Crosswalk
The Problem

Proof requests keep multiplying.
Your evidence doesn't.

Security questionnaires, regulator assessments, audit fieldwork, supplier diligence, insurance renewals: all drawing on the same underlying controls. Today each one is answered from scratch.

Before · Manual

Analysts hunt across documents, answer by answer

Days to weeks of turnaround, with human error.

After · Provenance AI

Every answer drafted from approved evidence

Source-linked and audit-ready, in minutes.

How It Works

Three steps, start to finished document

Select Workflow
Framework Crosswalk
Inbound Autofill
Audit Binder
RFI Responder
More workflows…
Step 1

Choose the workflow

Pick the request type, then upload the blank questionnaire, checklist or RFI.

SOC 2 Type 2 Report35%
Covers Section 2 Q7, Section 3 Q10–Q13, and more.
ISO 27001 Certificate5%
Covers Section 2 Q6.
Information Security Policy20%
Covers Section 3 & Section 4.
Step 2

Connect the evidence

Attach SOC 2, ISO certificates, policies and prior assessments already on file.

Completed_Questionnaire.pdf
Step 3

Generate & review

A complete, source-linked document, ready for reviewer sign-off.

The Difference

It tells you what's covered, and what's still missing

Before a single question is answered, Provenance AI scans your connected evidence and reports, section by section, how much it can already fill, then names the exact documents that close the rest.

40%
answered automatically from two documents already on file
60%
resolved by four named policies, no open-ended search
Coverage panel: 8 suggested documents
✓ Already Uploaded (2)
SOC2 Type2 Report35%
Covers Section 2 Q7, Section 3 Q10–Q13, Section 4 Q14–Q16.
ISO 27001 Certificate5%
Covers Section 2 Q6.
Pending (6)
Information Security Policy20%
Covers Section 3 Q10, Q12, Q13, Section 4 Q15, and Section 9 Q30.
Data Protection Policy12%
Covers Section 2 Q8 and Section 4 Q14, Q17.
Third-Party Risk

Vendor answers, verified against their own evidence

Score-card tools guess vendor risk posture from the outside. ThreatWorx verifies it from the inside: checking the security questionnaire answers your vendors and partners give you against the SBOMs, certifications and evidence documents they actually supplied.

Every vendor and partner questionnaire response is checked line by line against the evidence attached to it, so a claim only counts once their own document backs it up.

Onboard vendors and partners once, track their risk posture continuously, and share platform access so they can keep their own evidence current, with no yearly re-collection drive.

Every finding lands in the same inventory as your own hosts, cloud accounts and code: one severity model, not a side spreadsheet per vendor.

The inside view pairs with the outside one: point ThreatWorx EASM at a vendor's own domain to check what they expose externally, before you ever ask them a question.

Vendor & partner ledger: answers vs. evidence
✓ Verified (2)
Core Payments VendorLow
Questionnaire checked against SOC 2 and SBOM on file.
Cloud Storage PartnerMedium
Questionnaire checked; 1 SBOM finding above KEV threshold.
Pending (2)
Regional ResellerRequested
Questionnaire sent, evidence not yet uploaded.
Staffing AgencyRequested
Questionnaire sent, evidence not yet uploaded.
Workflows

One engine, everywhere proof is requested

Framework Crosswalk

Maps existing controls onto NIST 800-53, HIPAA Security Rule and ISO 27001/13485.

Regulatory Mapping

Inbound Autofill

Customer, partner and payer security questionnaires drafted from your own evidence library.

Third-Party Reviews

Audit Binder

SOC 2, HITRUST and industry audit evidence assembled into a citation-ready binder.

Audit Evidence

RFI Responder

Outbound RFIs to upstream suppliers, with responses reconciled against the same model.

Supplier Diligence

Binder Ready

Cyber insurance applications completed from the same evidence, every renewal.

Insurance Renewals

Inside-Out Verify

Checks vendor and partner questionnaire answers against the SBOMs, certifications and evidence documents they actually supplied, so risk posture is verified, not just scored from outside.

Vendor & Partner Risk

SBOM Support

Ingests CycloneDX and SPDX SBOMs from vendors and partners, or generates them yourself with the open twigs CLI, and keeps every one current automatically.

SBOM Operations
SBOM Support

Operationalizing SBOMs, from ingest to automation

CycloneDX and SPDX in, however your vendors already produce them, or generate one yourself with the open twigs CLI.

01 · Ingest

Source SBOMs

Source and upload SBOMs from vendors and partners, in CycloneDX or SPDX, however they already produce them.

02 · Assess

Verify inside-out

Every component is checked for true inside-out risk: known vulnerabilities, license exposure, and abandoned or typosquat packages.

03 · Automate

Keep it current

Collaborate with vendors on automated SBOM generation and upload using the open twigs CLI, so the ledger never goes stale.

CycloneDX SPDX SBOM Generation SBOM Ingest Vendor Management
See full third-party risk & SBOM details →
What Changes

Less typing, fewer errors, faster turnaround

Weeks→Min
Turnaround per request
100%
Answers backed by source evidence
Zero
Manual transcription errors
1 click
From evidence to completed file

Analysts shift from re-typing to reviewing: one person clears the backlog that used to take a team weeks.

Provenance AI

Answer once. Reuse everywhere. Every response traced back to the document it came from.

Framework Crosswalk Inbound Autofill Audit Binder RFI Responder Binder Ready Inside-Out Verify SBOM Support