AI-Powered Vendor Security Assurance

Stop guessing
who to trust.

Diliventa™ is the intelligent platform for vendor due diligence, AI-assisted security analysis, and GRC — built for the speed of modern business.

60+
Security Controls
22
Frameworks
16
Auto-Deny Triggers
10
Assessment Tabs
Framework Aligned
NIST CSF 2.0 ISO 27001:2022 SOC 2 HIPAA GDPR EU AI Act PCI DSS 4.0.1
Platform Capabilities

Everything you need to
make confident vendor decisions

From first contact to board report — one structured, evidence-driven workflow.

🛡️
Intelligent Scoring Engine

Weighted scoring across 9 security domains automatically calculates your vendor's security posture with a confidence band that reflects evidence completeness.

🚫
Automatic-Denial Triggers

16 critical failure conditions (no MFA, expired SOC 2, unremediated critical vulnerabilities, no IR plan) that instantly flag a DENIED verdict — no score can override them.

🤖
Claude AI Deep Analysis

Upload SOC 2 reports, pen test results, ISO certificates, and privacy policies. Claude AI extracts findings, scores the evidence, and recommends risk acceptance posture.

✏️
Human-in-the-Loop Sign-Off

Qualified analysts retain final authority. Document override justifications, accept residual risk, and cryptographically sign off on every determination.

📋
Board-Ready Reports

One-click PDF export of a structured board report: verdict, scores, AI summary, evidence log, control gaps, and priority recommendations. Print-ready, no reformatting.

📊
Full GRC Suite

Built-in controls library, risk register (5×5 matrix), findings tracker with SLA deadlines, and audit management — all in the same platform as your vendor reviews.

📚
Offline Triage Scan

Upload vendor documents for an instant AI triage without starting a full assessment. Get a preliminary verdict, evidence adequacy score, and gap list in seconds.

🔒
Immutable Audit Trail

Every action, verdict change, override, and sign-off logged immutably. Tenant-isolated. TSV export for SIEM integration or compliance evidence packages.

🖥️
Desktop PWA — No Install

Install Diliventa from your browser address bar. Runs like a native app on Mac and Windows — no MSI, no admin rights, no App Store required.

How It Works

Seven steps from
request to determination

A structured, repeatable process that produces defensible outcomes every time.

1

Initiate Assessment

Define vendor scope, data classification, and applicable regulations. Assign a lead reviewer.

2

Collect & Log Evidence

Document all artifacts. The platform tracks currency — flagging expired SOC reports and ISO certificates automatically.

3

Answer 60+ Control Questions

Evaluate controls across 9 domains. Scores auto-calculate and deny triggers auto-set from critical No answers.

4

Upload Documents for AI Review

Claude AI reads your evidence files and returns a structured analysis: score, verdict, risks, framework alignment.

5

Human Determination & Sign-Off

Review the algorithmic and AI verdicts. Override with documented justification. Sign off to lock the record.

6

Generate Board Report

One click. Print-to-PDF board report with everything stakeholders need — no copy-paste from spreadsheets.

7

Audit Trail Auto-Captured

Every action is immutably logged. Export TSV for your SIEM or compliance evidence packages.

Live Assessment Dashboard
Acme Cloud Solutions
Approved
91
SOC 2 Type II · ISO 27001 · Pen Test ✓ AI: Low Risk
DataSync Partners
Conditional
78
No DPA · Pen test 14mo old AI: Moderate
NovaTech Systems
Denied
31
🚫 No MFA · 🚫 Critical CVE unpatched
Vertex Analytics
Pending
Evidence requested — awaiting SOC 2
✅ 1 Approved ⚠️ 1 Conditional ❌ 1 Denied ⏳ 1 Pending
AI-Powered Analysis

Claude AI reads your evidence.
You make the call.

Upload SOC 2 reports, pen tests, ISO certs, and privacy policies. Get a structured security analysis in under 30 seconds.

AI Analysis — Acme Cloud Solutions

AI Security Score 88/100
Risk Acceptance: Conditionally Acceptable
Framework Alignment
NIST CSF 2.0Strong ✓
ISO 27001:2022Certified ✓
SOC 2 Type IICurrent ✓
GDPR Art. 28DPA Required ⚠️
Priority Actions
Execute Data Processing Agreement before onboarding — GDPR Art. 28 requirement
Obtain bridge letter from auditor — SOC 2 period ends in 8 weeks
Confirm sub-processor list and contractual security obligations

Residual Risks

No DPA Executed Sub-processor Risk SOC 2 Near Expiry Non-US Data Center

Evidence Adequacy

74/100
Moderate — 2 key artifacts missing
✅ SOC 2 Type II   ✅ ISO 27001   ✅ Pen Test
❌ DPA   ❌ Sub-processor List
Framework Coverage

22 frameworks. One assessment.

Every control and finding automatically mapped to the frameworks that matter for your organization and your regulators.

SOC 2 Type II (AICPA TSC) SOC 1 SOC 3 NIST CSF 2.0 ISO/IEC 27001:2022 ISO/IEC 27017:2015 ISO/IEC 27018:2019 ISO/IEC 27701:2019 NIST SP 800-53 Rev 5 NIST SP 800-161 Rev 1 CIS Controls v8.1 GDPR CCPA / CPRA HIPAA ISO/IEC 42001:2023 NIST AI RMF 1.0 EU AI Act OWASP LLM Top 10 PCI DSS 4.0.1 ISO 22301:2019 SIG (Shared Assessments) GovRAMP
Pricing

Simple, transparent pricing

No hidden fees. No per-assessment charges. Cancel anytime.

Starter
$49/mo

For small teams starting vendor risk management.

Up to 5 vendor assessments/mo
2 users
Automated deny trigger engine
Basic scoring & posture report
GRC: Controls, Risks, Findings
Document triage scan
In-app help & methodology reference
Get Started
Enterprise
$499/mo

For multi-site orgs, health systems & government contractors.

Everything in Professional
15 users
SSO / SAML
Role-based access (RBAC)
Priority support SLA (24-hr response)
Audit log export & SIEM integration
Dedicated CSM
Get Started
7-day free trial · No credit card required · Cancel anytime
What Teams Are Saying

Built by a vCISO.
Built for the real world.

“We used to spend two weeks on a vendor review. Diliventa gets us to a defensible determination in hours. The auto-deny trigger engine alone has saved us from three bad vendor decisions.”

SM
Sarah M.
CISO · Healthcare Technology

“The AI analysis is remarkable. I uploaded a 40-page SOC 2 report and got a structured finding summary, framework alignment, and risk acceptance recommendation in 20 seconds.”

JR
James R.
vCISO · Financial Services

“The board report feature is a game-changer. My GRC team can now hand executives a clean, structured PDF instead of a 20-tab spreadsheet. Instant credibility.”

TC
Tanya C.
Director of GRC · SaaS Enterprise
Platform Security

Enterprise-grade security
for your most sensitive data

Your vendor assessment data deserves the same rigor you apply to your vendors.

🔐

Zero-Knowledge Architecture

Credentials and secrets are encrypted at rest and never stored in code or configuration files. Keys can be rotated instantly without touching a deployment.

🏢

Complete Tenant Isolation

Every organization's data is cryptographically scoped at the database layer. Cross-tenant data access is structurally impossible, not just policy-enforced.

🌐

Global Resilience, Zero Ops

Served from 300+ points of presence worldwide with built-in DDoS mitigation, WAF, and TLS 1.3. No servers to patch, no infrastructure to manage.

👁️

Immutable Audit Trail

Every action is recorded with actor, timestamp, and full detail — and cannot be altered or deleted. Export directly to your SIEM for independent verification.

🌐
Global Network Layer
SOC 2 Type II · PCI DSS L1 · GDPR DPA
🗄️
Data Storage Layer
SOC 2 Type II · AES-256 at rest · GDPR DPA
🔒
Identity & Access
MFA · SSO/SAML · GDPR DPA
🤖
AI Processing
No model training on customer data · SOC 2 Type II
💳
Payments
PCI DSS Level 1 · GDPR DPA
Transport Security
TLS 1.3 · HSTS · CORS Restricted · SameSite=None; Secure cookies

Ready to know who
you can actually trust?

Join security teams who’ve replaced spreadsheet-based vendor reviews with a structured, AI-powered, audit-ready workflow.

7-day free trial · No credit card required · Built by a vCISO