Supplier exposure

How do you see third-party risk across every client you manage?

Outerwall finds each client’s suppliers from public sources, including the ones your client never listed, and ranks them by blast radius: how much damage a failure there would do. Because it maps every client you manage, it shows which suppliers they share. When one is breached, every affected client is flagged within hours.

Find them

The suppliers your clients forgot are the ones that hurt most.

Supplier monitoring is usually a separate product, priced per vendor your client remembers to add. The identity provider and the agent on every laptop are the ones they forget. Outerwall finds them from the outside.

01

DNS names the obvious ones.

Mail and sender records, verification tokens, CNAMEs and the sign-in realm show who runs a client’s mail, identity, hosting and software. All of it public.

02

Job ads and case studies name the rest.

“Experience with our payroll platform required.” A vendor’s case study that names your client as a customer. Each supplier goes to your client to confirm, with where we found it.

03

Ranked by blast radius.

How much damage a failure there would do. Catastrophic: the identity provider, and an endpoint agent that updates itself on every laptop. Severe: processors of regulated data. High: hosting. Moderate: peripheral software.

04

Seen across every client you manage.

Say you look after 40 clients. 14 of them use the same payroll provider, and 31 the same identity provider. No spreadsheet shows you that.

05

When a supplier is breached, you know within hours.

The payroll provider files a breach notice. All 14 clients are flagged in one view, with the evidence, within 6 hours. You raise it with all of them the same morning.

When one is breached

One breach notice, every affected client, the same morning.

Outerwall keeps watching after onboarding. When a supplier is breached, every client that depends on it is flagged in one view, ranked, and sent to your PSA with the evidence.

From a supplier breach to your clients: the payroll provider files a breach notice; Outerwall matches it to the 14 of your 40 clients that use it; ranks it severe because it holds regulated staff data; opens one ticket per client in your PSA from a single view; and you tell every affected client the same morning.

From breach notice to your clients · illustration

Fast-moving changes, in under 6 hours

A supplier’s breach, outage or insolvency. A new flaw on CISA’s known-exploited list that matches software a client runs. Staff credentials in a breach or infostealer log. A lookalike domain. A ransomware group naming a client.

Daily changes, within 24 hours

New subdomains and addresses, DNS and email records. A change triggers a recheck of only the asset that changed.

Alert times are targets for the first partner release. See the roadmap.

Blast radius

How we rank a supplier

Each supplier gets a blast radius class from what it does for your client. The class decides where its alerts rank.

ClassTypical suppliersWhy it ranks there
CatastrophicThe identity provider. An endpoint agent that updates itself on every laptop.A failure there reaches every user or every device.
SeverePayroll, loan and tax platforms that process regulated data.A breach there exposes data your client is accountable for.
HighHosting and cloud providers.A failure there can take your client’s systems offline.
ModeratePeripheral software, such as e-signature and CRM.Less data, and a narrower route to it.

Observed, never tested

Suppliers are observed from public sources only. We never test a supplier without that supplier’s own signed consent.

How we keep it safeHow it works

See which suppliers your clients share.

Design partners start with their own estate, then add clients as each release lands.