The Platform
Built for the gap between what vendors say and what is actually happening
Magnitude ingests signals from security advisories, breach disclosures, and regulatory filings continuously, matching each one against your vendor roster so your team sees emerging risk as it develops, not months after it crystallized.
Core Capabilities
What Magnitude does every day
Three interconnected capabilities that replace the point-in-time questionnaire with a continuously-updated risk picture.
Signal Ingestion
Magnitude reads from CVE databases, vendor security bulletins, CERT advisories, breach disclosure registries, and regulatory enforcement feeds every day. New sources are added as the threat landscape changes.
Vendor Matching
Each incoming signal is matched against your vendor roster using entity resolution that handles name variants, subsidiaries, and acquired companies. A signal about a vendor's subsidiary shows up against the parent relationship in your portfolio.
Prioritized Alerting
Not every signal warrants the same response. Magnitude scores signals by severity, vendor access tier, and your team's defined risk thresholds, then routes alerts to the right people with enough context to act without additional research.
Data Sources
Where Magnitude reads the signal
Coverage across the three domains where vendor risk materializes before it becomes an incident your team hears about from a customer.
Security Advisories and CVE Databases
NVD, MITRE CVE, vendor-specific security bulletins, and CERT advisories are ingested daily. Each CVE is matched to affected vendors in your portfolio using product mapping built from your vendor onboarding data.
Breach Disclosures and Credential Exposure
HHS breach portal, state attorney general breach databases, SEC 8-K cybersecurity disclosures, and correlated dark-web credential exposure indicators. Coverage is updated continuously as disclosures are filed.
Regulatory and Enforcement Actions
CFPB consent orders, FTC enforcement actions, OCC enforcement documents, and state-level regulatory filings that reflect compliance posture changes at vendors you rely on. Especially relevant for financial services and healthcare supply chains.
Operational and Financial Signals
Leadership changes, workforce reduction announcements, major customer losses, and publicly-reported financial distress that correlate with elevated vendor risk in the subsequent 90 to 120 days.
Team Workflow
Designed to fit into how security teams already work
Magnitude connects to the tools your team already uses for incident response and vendor management, so alerts reach the right people without creating a new workflow they have to learn.
Slack and Teams Alerts
Risk alerts post to the channels your team already monitors, with severity labels, vendor context, and a direct link to the full signal detail in Magnitude.
Jira and ServiceNow Tickets
High-severity alerts can automatically create tickets in your existing tracking system, pre-populated with vendor name, alert type, supporting evidence, and suggested next actions.
GRC Platform Export
Export vendor risk summaries to your existing GRC platform in formats compatible with major third-party risk management workflows, including standardized risk fields for audit documentation.
Security Posture
How we handle the data you bring to Magnitude
Your vendor roster is sensitive. We treat it accordingly, with controls appropriate for enterprise security operations.
Encryption in Transit and at Rest
All data transmitted to and from Magnitude is encrypted using TLS 1.3. Vendor roster data and signal matches are encrypted at rest using AES-256. Encryption keys are tenant-isolated.
Role-Based Access Control
Seat-level permissions let you control who can view vendor data, configure alert thresholds, and export risk reports. Audit logs track all access and configuration changes.
SOC 2 Type II in Progress
We are in the Type II observation period with a regional public accounting firm. Type I report available under NDA for enterprise evaluations. Full Type II report expected before end of 2026.
US-Region Data Residency
All customer data is stored and processed in AWS US-East and US-West regions. No customer data is transferred to or processed in non-US infrastructure. Residency commitments are available as a contractual addendum.
See the platform against your actual vendor portfolio
Request access and we will set up a live pilot with your vendor roster in under a week, no migration required.