You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A complete third-party vendor security risk-assessment framework — questionnaire, live scoring engine, and worked vendor assessments with approve/conditions/reject recommendations. Two-axis inherent×control residual-risk model mapped to NIST 800-161, ISO 27001 & SOC 2.
Open-source AI agent for vendor privacy risk assessment. Scores vendors across 8 GDPR/CCPA dimensions using a published, enforcement-grounded rubric. Works with Claude, GPT-4o, Gemini, Mistral, or fully local with Ollama. Free forever.
A comprehensive third-party risk management framework for a global media streaming platform. Focuses on vendor classification, content security, intellectual property protection, and compliance monitoring, delivering risk maps, due diligence checklists, and strategic recommendations
Claude plugin for Bitsight Security Ratings — a zero-dependency MCP server wrapping the Bitsight REST API as 15 read-only tools, plus 16 skills that turn ratings into board packs, vendor decisions, remediation roadmaps, audit evidence and Indian regulatory incident notifications.
Análise tática de TPRM e GRC em licitações públicas, cruzando a Lei 14.133/21 com o framework NIST SP 800-161. Projeto prático gerado com IA (NotebookLM) | Desafio DIO.
Multi-agent third-party risk review on Google Gemini 2.5 Flash — vendor onboarding & M&A due-diligence in under 90 seconds. lablab.ai Transforming Enterprise Through AI submission (Track 2).
Open-source security questionnaire & RFP auto-responder. Drafts answers grounded in your own security profile and flags gaps instead of inventing certifications. BYOK with the Anthropic Claude API - no data stored server-side.
IT Compliance Framework for Manufacturing: GDPR/CCPA, Annual IT & OT Audit, TPRM (Third-Party Risk Management) — templates, checklists, and methodology
Documenting my transition from academia/DevOps into GRC — risk assessment, TPRM, and ISO frameworks, building toward Enterprise Risk Management in Germany.
Central index for my US-grade GRC, Security Assurance, and TPRM portfolios. Features audit-ready documentation, cross-framework mappings, and evidence-driven vendor risk management.