Vendor Analysis is an AI-generated briefing on a vendor, built from publicly available information about their domain. It is background research — useful before onboarding, or as context when reading a questionnaire — and it is generated fresh, not drawn from the vendor's own answers.
vendor:add), which is what the analysis service checksNavigation: Sidebar → Vendors → [select a vendor] → Vendor Analysis
The analysis starts as soon as the tab opens.
You see an AI Analysis in Progress card that steps through what it is doing:
Leave the tab open until it finishes.
The report opens with a note that the content was generated using ZIN and asks you to verify it independently before acting on it. Take that seriously — this is research material, not an audited finding.
The report is then organised into these sections. A section only appears if the AI found something for it, so a low-profile vendor may show fewer of them.
| Section | What it covers |
|---|---|
| Financial Stability | The vendor's financial standing |
| Business Continuity | Their resilience and continuity position |
| Incident History | Past incidents affecting the vendor |
| Cyber Attacks & Incidents | Individual incidents, each with a date, an Impact note and a View Source link to the original reporting |
| Data Privacy Compliance | Their data privacy and regulatory position |
| Third Party Dependencies | Who the vendor themselves depends on |
| Key Strengths | What the vendor does well |
| Key Risks | What to be cautious about |
| Market Position | Where they sit in their market |
| Security Posture | Their overall security maturity |
| Recommendations | Suggested next steps |
Use View Source on any incident to read the underlying report before you rely on it.
Anything you decide to track should be raised as a risk on the vendor's Manage Risk tab. Vendor Analysis is read-only; it does not create risks by itself.
The Vendor Analysis tab shows a "not authorised" screen → Vendor Analysis is not available on on-premises deployments.
The tab is blank, or the analysis never starts → The analysis runs against the vendor's primary domain. Open the Profile tab and check a domain is recorded; if it is missing, edit the vendor to add it.
The analysis is taking a long time → Generation is allowed several minutes before it times out. If nothing appears after that, reload the tab to run it again.
The report is very thin → The AI works from public information. Small or privately held vendors, and vendors with little web presence, genuinely produce less material.
Something in the report looks wrong → Follow the View Source link where one is given, and treat the disclaimer at the top of the report as the rule: verify independently before making a decision.
A colleague cannot open the tab → The analysis service checks the vendor add permission (vendor:add). Someone with view-only access to vendors will not be able to run it.
Need more help? Contact support@zeron.one