Built for Australian Regulatory Compliance
AI-powered vendor risk management that continuously monitors your third-party ecosystem. Automated discovery, real-time risk scoring, and Australian regulatory compliance — without the enterprise price tag.
Understanding Vendor & Supply Chain Risk
Supply Chain Risk Management (SCRM) — also called Vendor Risk Management (VRM) or Third-Party Risk Management (TPRM) — is the discipline of identifying, assessing, and continuously monitoring the risk your vendors introduce. Every cloud provider and SaaS platform you rely on extends your attack surface: their breach becomes your breach.
Australian regulators now expect formal vendor oversight. Since 1 July 2025, APRA's CPS 230 requires regulated entities to manage material service provider risk — including a provider register submitted to APRA annually — alongside CPS 234, the ISM, the SOCI Act, the Privacy Act, and the Cyber Security Act 2024. The bar has shifted from point-in-time questionnaires to continuous, verified assurance.
to contain a supply-chain breach — the slowest of any attack vector
IBM Cost of a Data Breach 2025A single supplier compromise gives attackers a trusted path into every downstream customer at once — Unit 42's 2026 incident response data calls it a one-to-many opportunity, and the ASD warns it is often an organisation's weakest link. Australia has already seen it play out:
Qantas (2025): 5.7 million customer records exposed — the attackers never touched Qantas systems. They compromised a third-party call-centre platform. (Skift)
LexisNexis (2026): A single supplier cloud breach exposed data linked to 21,000+ customer accounts, touching law firms, courts, and government agencies. (The Register)
Defence supply chain (2025): Ransomware attacks on Australian defence contractors exfiltrated files referencing frigate and submarine programs — via suppliers, not Defence. (Insurance Business)
Select your profile to see how ChainShield solves supply chain risk for you.
Owner / IT Manager
Regulators and clients are asking about your vendors.
ChainShield automates discovery, scoring, and reporting so you can demonstrate vendor oversight in minutes, not months — no GRC team required.
Start free — 15 minutes to your first risk scoreThe Vendor Lifecycle
Every vendor moves through the same stages — identify, assess, contract, monitor, offboard. ChainShield automates the work at each one, from the initial risk assessment before you commit to the audit trail that outlives the relationship.
Identify & profile
What happens — Add a vendor by name and domain — singly or bulk-imported — and tier it: business criticality, data sensitivity, regulatory scope. External discovery starts screening immediately, before you commit.
What you see — A new register entry with risk-context tags that decide which controls apply — and the first signals arriving while the vendor is still a prospect.
Initial risk assessment
What happens — The inherent-risk baseline: an automated external scan across all 7 risk domains plus a framework questionnaire the vendor completes through the portal — no account required, no 200-row spreadsheet to chase.
What you see — An initial composite risk score and evidence-linked findings — enough to proceed, require remediation and contract controls first, or walk away before onboarding completes.
Monitor continuously
What happens — Risk is not static — cadenced rescans, questionnaires through the vendor portal, and your own org-private self-assessment keep the baseline honest.
What you see — A live composite risk score, real-time alerts when posture changes, and a full finding history.
Re-assess & contract
What happens — Contract and SLA expiry tracked automatically; remediation requirements and accepted-risk decisions recorded against findings; the CPS 230 material-service-provider register stays current.
What you see — Renewal-due flags and every risk decision with the reasoning behind it.
Offboard
What happens — The vendor enters the exclusion workflow — access and monitoring wind down in a controlled sequence.
What you see — An offboarding status on the vendor record; every step is timestamped.
Decommissioned
What happens — The relationship ends. Nothing about it is deleted.
What you see — A read-only archived record with the full audit trail, ready if an auditor asks.
Every scan behind the Active stage runs through 30 pipeline components — including 7 domain AI agents — with an independent AI reviewer on a separate model and ChainShield analyst approval before any finding publishes. Findings map to 30 active controls across the 7-domain risk taxonomy.
Trust & Oversight
ChainShield is designed with security, privacy, and human oversight at its core.
AI assists — humans decide. Critical and high-severity AI findings are never auto-published: each passes a two-tier review gate, including an independent AI reviewer running on a separate model, then ChainShield analyst approval before your organisation sees it. Your team can review, edit, or override any AI-generated narrative or assessment.
All external data is sanitised before AI processing to defend against prompt injection and data poisoning. Specialised agents operate in isolated contexts with least-privilege tool access. Every AI action is logged with full audit trail and source attribution. AI outputs are validated against expected schemas before storage.
AES-256 encryption at rest, TLS 1.2+ in transit, application-layer AES-256-GCM for stored third-party API keys. Row-level security for tenant isolation. Granular role-based access — from read-only auditors to MSP administrators. Full audit logging. ChainShield discovers and stores information about vendors from public sources (domains, certificates, CVEs, published vulnerabilities, ABR records, news coverage). Because this information comes from the public internet and is identical regardless of who is looking at the vendor, a single vendor record can be referenced by many customer organisations. ChainShield does not segregate public vendor facts by tenant.
We only collect publicly available data. No penetration testing, no intrusive scanning, no vendor contact without your explicit direction. Our AI agents analyse OSINT and vendor data only — questionnaire answers, vendor correspondence, stored contact records, account data, and your organisation's context never enter an AI prompt. ChainShield analyst review notes steer the agents — never attributed to your organisation.
Platform
Five questions every buyer asks — answered by one platform.
Continuously discover your vendors' digital footprint and the technology running on it — no manual data entry, ever.
Seven domain-aligned AI agents plus dedicated utility agents investigate every vendor; findings map to a 7-domain risk taxonomy across 30 active controls, with organisation-configurable weights.
Findings map directly to CPS 230, CPS 234, the ISM, SOCI Act, and the Privacy Act — plus hosting-location and geopolitical exposure tracking.
Two complementary assessment flows — vendor-facing questionnaires through a self-service portal, and an org-private self-assessment your vendors never see.
Push findings into your existing workflow, track remediation to verification, and see concentration risk across shared fourth-party dependencies.
Every finding is automatically mapped to the regulatory obligations and voluntary standards it affects — from CPS 230 to DFAT sanctions screening — so audit-ready reports take minutes, not weeks.
Fits into your existing stack
SAML SSO is available for MSP tenants today; per-organisation SSO is in active development.
Pricing
Start free. Upgrade as you grow. No lock-in contracts.
Try ChainShield with basic monitoring — no credit card required
For small teams starting their SCRM programme
For growing teams with a regulated vendor portfolio
For regulated organisations and MSPs at scale
Full coverage for large organisations
All prices in AUD, ex GST. See the full plan comparison for annual discounts, overage rates, and feature details.
Add a vendor by domain, and ChainShield starts discovering, scoring, and mapping it to your regulatory obligations — automatically.