ChainShield
How It Works
From onboarding to continuous monitoring
Risk Scoring
7-domain composite risk model
Compliance Mapping
CPS 230, ISM, SOCI & more
AI-Powered Analysis
AI agents analyse every finding
Product & Tech Inventory
Technology discovery and EOL tracking
For Small Business
Vendor risk in 15 minutes, no GRC team needed
For Mid-Market
CPS 230, ISM, SOCI compliance at a fraction of enterprise cost
For Enterprise
Multi-framework, multi-stakeholder SCRM at scale
For MSPs
Deliver SCRM as a managed service
Pricing
What is SCRM?
Learn about supply chain risk management
Help Centre
Guides, FAQs, and documentation
Security
How we protect your data
Sign InGet started
Menu
Platform
How It Works
From onboarding to continuous monitoring
Risk Scoring
7-domain composite risk model
Compliance Mapping
CPS 230, ISM, SOCI & more
AI-Powered Analysis
AI agents analyse every finding
Product & Tech Inventory
Technology discovery and EOL tracking
Solutions
For Small Business
Vendor risk in 15 minutes, no GRC team needed
For Mid-Market
CPS 230, ISM, SOCI compliance at a fraction of enterprise cost
For Enterprise
Multi-framework, multi-stakeholder SCRM at scale
For MSPs
Deliver SCRM as a managed service
Pricing
Resources
What is SCRM?
Learn about supply chain risk management
Help Centre
Guides, FAQs, and documentation
Security
How we protect your data
Sign InGet started

Built for Australian Regulatory Compliance

Shield Your Organisation from Supply Chain Risk

AI-powered vendor risk management that continuously monitors your third-party ecosystem. Automated discovery, real-time risk scoring, and Australian regulatory compliance — without the enterprise price tag.

Start free — first risk score in 15 minutes See How It Works
Sample Vendor Risk ProfileIllustrative data
Cyber 40%Ops 20%Compliance 15%Privacy 10%Financial 5%Reputation 5%Geopolitical 5%
35+Intelligence sources
12AU frameworks
5Standards
MinutesTo first score

Understanding Vendor & Supply Chain Risk

What is Supply Chain Risk Management?

Supply Chain Risk Management (SCRM) — also called Vendor Risk Management (VRM) or Third-Party Risk Management (TPRM) — is the discipline of identifying, assessing, and continuously monitoring the risk your vendors introduce. Every cloud provider and SaaS platform you rely on extends your attack surface: their breach becomes your breach.

Australian regulators now expect formal vendor oversight. Since 1 July 2025, APRA's CPS 230 requires regulated entities to manage material service provider risk — including a provider register submitted to APRA annually — alongside CPS 234, the ISM, the SOCI Act, the Privacy Act, and the Cyber Security Act 2024. The bar has shifted from point-in-time questionnaires to continuous, verified assurance.

48%

of breaches now involve a third party — up 60% in a single year

Verizon 2026 DBIR
US$4.91M

average cost of a breach that starts in the supply chain

IBM Cost of a Data Breach 2025
267 days

to contain a supply-chain breach — the slowest of any attack vector

IBM Cost of a Data Breach 2025
Every 6 min

a cybercrime is reported in Australia

ASD Annual Cyber Threat Report 2024–25

The “one-to-many” effect

A single supplier compromise gives attackers a trusted path into every downstream customer at once — Unit 42's 2026 incident response data calls it a one-to-many opportunity, and the ASD warns it is often an organisation's weakest link. Australia has already seen it play out:

  • Qantas (2025): 5.7 million customer records exposed — the attackers never touched Qantas systems. They compromised a third-party call-centre platform. (Skift)

  • LexisNexis (2026): A single supplier cloud breach exposed data linked to 21,000+ customer accounts, touching law firms, courts, and government agencies. (The Register)

  • Defence supply chain (2025): Ransomware attacks on Australian defence contractors exfiltrated files referencing frigate and submarine programs — via suppliers, not Defence. (Insurance Business)

Supply Chain Risk Management for Your Organisation

Select your profile to see how ChainShield solves supply chain risk for you.

Small Business

Owner / IT Manager

Regulators and clients are asking about your vendors.

ChainShield automates discovery, scoring, and reporting so you can demonstrate vendor oversight in minutes, not months — no GRC team required.

Start free — 15 minutes to your first risk score

The Vendor Lifecycle

Manage the whole vendor lifecycle

Every vendor moves through the same stages — identify, assess, contract, monitor, offboard. ChainShield automates the work at each one, from the initial risk assessment before you commit to the audit trail that outlives the relationship.

Identify & profile

Prospect

What happens — Add a vendor by name and domain — singly or bulk-imported — and tier it: business criticality, data sensitivity, regulatory scope. External discovery starts screening immediately, before you commit.

What you see — A new register entry with risk-context tags that decide which controls apply — and the first signals arriving while the vendor is still a prospect.

Initial risk assessment

Onboarding

What happens — The inherent-risk baseline: an automated external scan across all 7 risk domains plus a framework questionnaire the vendor completes through the portal — no account required, no 200-row spreadsheet to chase.

What you see — An initial composite risk score and evidence-linked findings — enough to proceed, require remediation and contract controls first, or walk away before onboarding completes.

Monitor continuously

Active

What happens — Risk is not static — cadenced rescans, questionnaires through the vendor portal, and your own org-private self-assessment keep the baseline honest.

What you see — A live composite risk score, real-time alerts when posture changes, and a full finding history.

Re-assess & contract

Review / Renewal due

What happens — Contract and SLA expiry tracked automatically; remediation requirements and accepted-risk decisions recorded against findings; the CPS 230 material-service-provider register stays current.

What you see — Renewal-due flags and every risk decision with the reasoning behind it.

Offboard

Offboarding

What happens — The vendor enters the exclusion workflow — access and monitoring wind down in a controlled sequence.

What you see — An offboarding status on the vendor record; every step is timestamped.

Decommissioned

Offboarded / Archived

What happens — The relationship ends. Nothing about it is deleted.

What you see — A read-only archived record with the full audit trail, ready if an auditor asks.

Every scan behind the Active stage runs through 30 pipeline components — including 7 domain AI agents — with an independent AI reviewer on a separate model and ChainShield analyst approval before any finding publishes. Findings map to 30 active controls across the 7-domain risk taxonomy.

Trust & Oversight

Tenant-scoped by design. Auditable by default.

ChainShield is designed with security, privacy, and human oversight at its core.

Human in the Loop

AI assists — humans decide. Critical and high-severity AI findings are never auto-published: each passes a two-tier review gate, including an independent AI reviewer running on a separate model, then ChainShield analyst approval before your organisation sees it. Your team can review, edit, or override any AI-generated narrative or assessment.

Responsible AI by Design

All external data is sanitised before AI processing to defend against prompt injection and data poisoning. Specialised agents operate in isolated contexts with least-privilege tool access. Every AI action is logged with full audit trail and source attribution. AI outputs are validated against expected schemas before storage.

Enterprise-Grade Security

AES-256 encryption at rest, TLS 1.2+ in transit, application-layer AES-256-GCM for stored third-party API keys. Row-level security for tenant isolation. Granular role-based access — from read-only auditors to MSP administrators. Full audit logging. ChainShield discovers and stores information about vendors from public sources (domains, certificates, CVEs, published vulnerabilities, ABR records, news coverage). Because this information comes from the public internet and is identical regardless of who is looking at the vendor, a single vendor record can be referenced by many customer organisations. ChainShield does not segregate public vendor facts by tenant.

Open Source Intelligence Only

We only collect publicly available data. No penetration testing, no intrusive scanning, no vendor contact without your explicit direction. Our AI agents analyse OSINT and vendor data only — questionnaire answers, vendor correspondence, stored contact records, account data, and your organisation's context never enter an AI prompt. ChainShield analyst review notes steer the agents — never attributed to your organisation.

Full audit trail
AI agent finding
Independent AI reviewer (separate model)
ChainShield analyst approval
Published

Platform

Everything You Need for Supply Chain Risk

Five questions every buyer asks — answered by one platform.

How do you find risk?

Continuously discover your vendors' digital footprint and the technology running on it — no manual data entry, ever.

  • Automated DNS enumeration, subdomain discovery, and per-host service scanning across your entire vendor portfolio
  • CVE detection with exploit-prediction scoring, plus end-of-life detection for unsupported software
  • SSL/TLS certificate analysis, email security (DMARC/SPF/DKIM), and technology fingerprinting from service banners

How do you score it?

Seven domain-aligned AI agents plus dedicated utility agents investigate every vendor; findings map to a 7-domain risk taxonomy across 30 active controls, with organisation-configurable weights.

  • Independent review gate — a separate AI reviewer model cross-checks every finding, and critical findings always require human analyst approval before publication
  • Agents analyse OSINT and vendor data only — questionnaire answers, vendor correspondence, stored contact records, account data, and your organisation's context never enter an AI prompt
  • Confidence tracking and regulatory auto-uplift when frameworks like CPS 230 or SOCI are in scope
7 domains · 30 active controls

How do we stay compliant?

Findings map directly to CPS 230, CPS 234, the ISM, SOCI Act, and the Privacy Act — plus hosting-location and geopolitical exposure tracking.

  • Automated compliance mapping to specific regulatory control IDs, with audit-ready evidence artefacts
  • CPS 230 material service provider identification and SOCI Act critical-infrastructure classification
  • Three-tier hosting model (AU Hosted / Foreign Non-Risk / Foreign Risk) with high-risk jurisdiction alerting

How do you work with vendors?

Two complementary assessment flows — vendor-facing questionnaires through a self-service portal, and an org-private self-assessment your vendors never see.

  • Framework questionnaire templates (ISM, CPS 234, SOC 2) with a guided vendor portal wizard — no vendor account required
  • Org-private scoring across capability, reliability, financial stability, and compliance — vendors are never notified
  • Vendor certification registry (ISO 27001, SOC 2, IRAP, FedRAMP) with evidence upload and full audit trail

How do we act on it?

Push findings into your existing workflow, track remediation to verification, and see concentration risk across shared fourth-party dependencies.

  • One-click Jira Cloud and ServiceNow integration with severity-mapped priority
  • Auto-verify remediation — the next scan confirms a fix and closes the finding automatically
  • Fourth-party concentration analysis highlights single points of failure across your portfolio

Built for Australian Compliance

Every finding is automatically mapped to the regulatory obligations and voluntary standards it affects — from CPS 230 to DFAT sanctions screening — so audit-ready reports take minutes, not weeks.

Australian Regulatory & Government Frameworks

CPS 230
APRA Operational Risk
CPS 234
APRA Information Security
ASD ISM
Information Security Manual
Essential Eight
ASD Maturity Model
SOCI Act
Critical Infrastructure
Privacy Act
Australian Privacy Principles
NDB
Notifiable Data Breaches
Cyber Security Act
2024 Reporting Obligations
DFAT
Sanctions Screening
PSPF
Protective Security Policy
ASIC Cyber
Cyber Resilience
ASIC IS 231
Market Participants

Industry & Voluntary Standards

ISO 27001
Information Security
NIST CSF
Cybersecurity Framework
PCI DSS 4.0
Payment Card Industry
SOC 2
Service Organisation Controls
VAISS
Voluntary AI Safety Standard

Fits into your existing stack

REST API
Jira & ServiceNow
SIEM (Splunk, Sentinel, Elastic)
Webhooks
Slack, Teams & Email
SAML SSO (MSP tenants)

SAML SSO is available for MSP tenants today; per-organisation SSO is in active development.

Pricing

Simple, Transparent Pricing

Start free. Upgrade as you grow. No lock-in contracts.

Free

$0/forever

Try ChainShield with basic monitoring — no credit card required

  • Up to 2 vendors
  • 14-day Starter trial on signup
  • Basic risk scoring
Start free — first risk score in 15 minutes

Starter

$490/month

For small teams starting their SCRM programme

  • 10 vendors included
  • $49 per extra vendor
  • Full risk scoring
  • Monthly reports
Get Started
Most Popular

Essentials

$975/month

For growing teams with a regulated vendor portfolio

  • 25 vendors included
  • $39 per extra vendor
  • Monthly board reports
  • Slack + Teams integrations
Get Started

Pro

$1,450/month

For regulated organisations and MSPs at scale

  • 50 vendors included
  • $29 per extra vendor
  • SSO (SAML/OIDC)
  • API access
  • Priority support
Get Started

Enterprise

Custom

Full coverage for large organisations

  • 50+ vendors, custom scale
  • Negotiated contract terms
  • Dedicated success manager
  • Compliance assistance (SOC2, ISO 27001)
Contact Sales

All prices in AUD, ex GST. See the full plan comparison for annual discounts, overage rates, and feature details.

See your vendors' real risk posture in the next 15 minutes

Add a vendor by domain, and ChainShield starts discovering, scoring, and mapping it to your regulatory obligations — automatically.

Start free — first risk score in 15 minutes Sign In to Existing Account
ChainShield

AI-powered supply chain risk management for Australian enterprises and MSPs.

A product of Simplecore Pty Ltd, trading as ChainShield. Australian-owned and Australian-hosted.

Product

  • Features
  • Pricing
  • Compliance
  • For MSPs

Resources

  • What is SCRM?
  • Help Centre
  • Status

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Security
  • Accessibility

Contact

  • hello@chainshield.com.au
  • Simplecore Pty Ltd
  • PO Box 273, Lawnton QLD 4501
  • ACN 641 930 627 · ABN 39 641 930 627
© 2026 Simplecore Pty Ltd · ACN 641 930 627 · ABN 39 641 930 627. ChainShield is a product of Simplecore Pty Ltd. All rights reserved.