Vendors
The vendor directory lists the third-party services your company relies on. For each vendor, you complete a risk assessment questionnaire that produces a risk level, and Oneleet records when the vendor was reviewed and by whom. Completed assessments feed your compliance monitors and controls, and vendors can appear as subprocessors on your Trust Center.
Open the directory from Organization > Vendors in the sidebar. Everyone in your workspace, including auditors, can view the directory and open assessments read-only; adding vendors, editing assessments, and removing vendors require the admin role.
Add vendors
Section titled “Add vendors”-
Go to Organization > Vendors and click Add vendors.
-
In the modal, click the Select or Add Vendors field. Check vendors from Oneleet’s catalog, or type a name that isn’t listed and choose the option to add it as a new custom vendor.
-
Click Add vendors.
If you add a single vendor, its assessment opens right away. Adding several returns you to the directory filtered to the Needs details group.
Vendors detected from your integrations
Section titled “Vendors detected from your integrations”Oneleet scans for vendors whenever you connect or reconnect an integration. Detected vendors carry a star icon in the dropdown, and the modal lists them below the field with a Choose All button so you can add them all at once.
Find vendors in the directory
Section titled “Find vendors in the directory”Vendors are grouped by assessment status: Needs details for vendors whose assessment isn’t finished, then High risk, Moderate risk, and Low risk. In the Services column, country flags mark the vendor’s processing locations and a PII tag means the vendor processes personally identifiable information.
Search matches vendor names, categories, and descriptions. The table sorts by Date added, newest first, by default. Click any row to open that vendor’s assessment.
While any vendor is unreviewed, a banner at the top of the page offers to complete the outstanding assessments. Its button opens the review queue, described below.
Complete a risk assessment
Section titled “Complete a risk assessment”Each vendor has its own assessment page, organized into sections listed in the left navigation: Vendor details, Data security (shown only when the vendor stores data), Reliability measures, and Risk level. Your answers save automatically as you type.
Assessments for catalog vendors come pre-filled from a template written by Oneleet’s compliance team. If your answers diverge from the template, a banner says so and offers Reset to template.
Expect questions about how much your business depends on the vendor, how it processes and stores data, and its security practices, including its most recent independent security assessment or penetration test.
An assessment counts as complete when every applicable question is answered and, for vendors that store data, the data inventory has at least one entry. The Needed for completion bar lists anything still missing; click an item to jump to that section.
Vendor details
Section titled “Vendor details”Assign a compliance owner from your workspace members. The owner oversees the vendor and receives risk-related notifications. If the right person isn’t on Oneleet yet, the Add now link takes you to the People page.
For custom vendors, you can set a Logo URL — a link to an image shown as the vendor’s logo in Oneleet and on your Trust Center. The link must start with http or https.
Data inventory
Section titled “Data inventory”If you answer yes to Does this vendor process or store data?, describe what data the vendor handles. Click + Add data entry to add each item with a description, a sensitivity level (Public, Internal, Confidential, or Secret), and tags.
Switching Does this vendor process or store data? to No while entries exist prompts you to confirm, because the entries are removed and can’t be recovered.
Vendors with data answers from before the inventory existed show a Set up your data inventory prompt with a button that carries the old answers over.
Risk level
Section titled “Risk level”The Risk level section shows a suggested risk level computed from your answers. Riskier answers raise the suggestion, and data inventory entries count too: the more sensitive the data, the higher the suggested level.
Click Override to set the level to High, Moderate, or Low instead. The label changes to show the level was overridden.
Evidence and notes
Section titled “Evidence and notes”Attach supporting material in the Evidence section: drop files to upload them, click Add link to attach a URL, or click Link evidence to attach evidence that already exists in your workspace. The Notes section accepts Markdown.
Finish the assessment
Section titled “Finish the assessment”Once the Needed for completion bar is empty, click Complete assessment. Oneleet records the review date and reviewer, shows them in the Reviewed column, and logs the review in your audit log. If the assessment later becomes incomplete, the review stamp is cleared until you complete it again.
Review vendors in bulk
Section titled “Review vendors in bulk”The review queue steps through your vendors one assessment at a time.
-
On the directory, click Start review (or Review vendors) in the banner.
-
Complete the current vendor’s assessment and click Continue. If you’re not ready to finish this vendor, click Skip — your answers are saved and the queue moves on.
The queue advances alphabetically through unreviewed vendors and returns you to the directory when none remain. A sidebar lists every vendor in the queue with a reviewed indicator, and you can click any of them to switch.
Questionnaire versions
Section titled “Questionnaire versions”A vendor’s assessment shows its current version in the Questionnaire version section. New custom vendors start on the latest version; vendors added earlier may still be on an older one.
Click Upgrade questionnaire version to move a vendor to a newer version. Compatible answers migrate automatically and a message reports how many carried over, but answers to some questions may be lost — the upgrade asks you to confirm first.
Vendors on your Trust Center
Section titled “Vendors on your Trust Center”The Trust Center derives a vendor’s public services list and PII flag from its data inventory — only entries flagged to appear on the Trust Center contribute to the services list.
Vendors still on the Legacy questionnaire instead include a Subprocessor Information section covering services provided, PII processing, processing locations, and the vendor’s URL. Filling it in lists the vendor as a subprocessor on your Trust Center.
Remove vendors
Section titled “Remove vendors”-
On the directory, select vendors with the row checkboxes.
-
Click Remove in the panel that appears.
-
Confirm in the removal dialog.
Removing a vendor permanently deletes its assessment data, evidence, and notes. You can add the vendor back at any time from the directory, but its assessment starts over. Removed vendors can be restored through the API; there is no restore option in the app.
Monitors and controls
Section titled “Monitors and controls”Every vendor you add becomes a monitored asset, and vendor management backs several controls.
Monitors fail for each vendor whose assessment isn’t complete, and for each data-storing vendor whose data inventory is empty; vendors that answered they store no data are exempt from the inventory check.