Latka logo

Top 22 Vendor Security and Privacy Assessment Software Companies (August 2026)

As of August 2026, Latka tracks 22 vendor security and privacy assessment software companies. They have combined revenues of $909.1M and employ 4.7K people. They have raised $1.4B and serve 1M customers combined.

Every company below sells vendor security and privacy assessment software to other businesses and is ranked by its most recent annual revenue. Revenue, funding, headcount and customer figures come from CEO interviews on the Latka podcast, public company filings, and Latka estimates where a company has not disclosed a number.

What Vendor Security and Privacy Assessment Software Companies do

Vendor Security and Privacy Assessment Software enables organizations to evaluate and manage the security and privacy risks associated with their third-party vendors. These tools assist in identifying, assessing, and continuously monitoring vendors to ensure they meet required security standards and compliance regulations. Typical use cases include conducting security assessments, managing vendor communications regarding security practices, and facilitating compliance with data protection laws. The primary features of this software often include vendor risk scoring, automated workflows for assessments, reporting functions, and integration capabilities with existing security systems. Common users of this software are risk management teams, compliance officers, procurement departments, and IT security professionals who need to maintain a secure supply chain and safeguard sensitive data shared with third-party vendors.

Companies
22
Revenue
$909.1M
Funding
$1.4B
Employees
4.7K

Filters

Sorting: Highest -> Lowest

Filters

Top Vendor Security and Privacy Assessment Software Companies by revenue

Showing 10 of 22 companies ranked by annual revenue.

1OneTrust logo
OneTrust

Atlanta, Georgia, United States

a comprehensive platform for privacy, security, and trust management

Revenue
$550M
Customers
14K
Year founded
2016
Funding
$1.1B
Team size
2.4K
Growth
10%
2BitSight logo
BitSight

Boston, Massachusetts, United States

Developer of cyber security software application. The company provides a security rating platform, which analyzes external data on security behaviors in order to allow organizations to manage third party risk, benchmark performance, and assess and negotiate cyber insurance premiums.

Revenue
$200M
Year founded
2011
Funding
$150.6M
Team size
743
Growth
19.05%
3Sprinto logo
Sprinto

San Francisco, California, United States

Automating Information Security Compliances & Privacy Laws for fast growing SaaS companies. Use Sprinto to obtain information security compliance, close enterprise deals faster, and pass vendor security assessments easily.

Revenue
$38M
Year founded
2020
Team size
345
4UpGuard logo
UpGuard

Mountain View, California, United States

Provider of a digital resilience platform designed to validate compliance and security. The company's platform combines asset discovery, security ratings and vendor questionnaires for the only complete cyber risk programming, enabling clients to get assured cyber security.

Revenue
$20.7M
Customers
1M
Year founded
2012
Funding
$53.4M
Team size
267
5Risk Ledger logo
Risk Ledger

London, Greater London, United Kingdom

Risk Ledger was founded in 2018 with a mission to shift the way organisations approach cybersecurity and information management in the supply chain. It provides an innovative cybersecurity platform that empowers enterprises to manage vendor relationships and assess risks more effectively.

Revenue
$13.8M
Year founded
2018
Team size
77
6Panorays logo
Panorays

New York, New York, United States

Panorays is a leading provider of third-party cyber risk management solutions, helping businesses optimize their defenses for each unique third-party relationship. Trusted by the most complex supply chains in the world, Panorays provides businesses the tools to stay ahead of any emerging third-party threats and provides actionable remediations.

Revenue
$13.1M
Year founded
2016
Team size
119
7Whistic logo
Whistic

Pleasant Grove, Utah, United States

Whistic is a vendor security network for users to assess, publish, and share vendor security information.

Revenue
$11.5M
Year founded
2015
Funding
$71M
Team size
73
8SafeBase logo
SafeBase

United States

SafeBase accelerates enterprise deals for B2B SaaS companies by streamlining security assessments.

Revenue
$10.3M
Customers
4
Year founded
2020
Funding
$20.1M
Team size
92
9Source Defense logo
Source Defense

Rosh Ha'Ayin, Israel

Developer of a cloud based Web application designed to help site owners to monitor third party vendors' behavior on their site. The company's cloud based Web application specializes in removing the security considerations from third party integrations, saving countless man-hours spent on tests and integrations, allowing sites to focus on generating revenues and new opportunities while keeping the site visitors safe and the site in high performance, enabling site owners to set and enforce permissions, receive real time alerts and monitor third party vendors' behavior on their site.

Revenue
$8.8M
Year founded
2014
Funding
$20.5M
Team size
46
106clicks logo
6clicks

Melbourne, Victoria, Australia

Transform your approach to cyber risk and compliance with 6clicks, a leading AI-powered Governance, Risk & Compliance (GRC) platform. Designed for service providers, enterprises and governments, 6clicks streamlines building resilient cyber programs that go beyond tick-box compliance. Our unique Hub & Spoke deployment model and powerful AI engine connect distributed teams, systems, and data, providing comprehensive oversight and control. With 6clicks, you can: ➡️ Balance control and autonomy with our Hub & Spoke deployment model, ideal for managing distributed GRC programs across various divisions, functions, geographies, or projects. ➡️ Utilize Hailey, our AI engine, to automate security compliance, IT risk management, vendor management, incident response and more. ➡️ Leverage our transparent licensing model with unlimited users and access to all our modules and the most in-demand security frameworks, like ISO27001, NIST, SOC 2, Cyber Essentials, CMMC, and DORA. ➡️ Access our vast Content Library, including turn-key security frameworks and regulations, audit and assessment templates, control sets and policies, and risk and issue libraries. We also offer advisors and managed service providers a white-labelled, turn-key GRC platform designed to increase client retention, unlock new revenue streams and streamline and scale service delivery.

Revenue
$8.3M
Year founded
2019
Funding
$10M
Team size
75

Frequently asked questions about Vendor Security and Privacy Assessment Software Companies

How many vendor security and privacy assessment software companies are there?

Latka tracks 22 vendor security and privacy assessment software companies with reported revenue. Together they generate $909.1M in annual revenue and employ 4.7K people.

Which vendor security and privacy assessment software company is the largest?

OneTrust is the largest, with $550M in annual revenue, founded in 2016.

How much revenue does a typical vendor security and privacy assessment software company make?

The average vendor security and privacy assessment software company in this list makes $41.3M a year, across 22 companies with reported revenue. They serve 1M customers combined.

Who are the leading Vendor Security and Privacy Assessment software vendors?

Ranked by annual revenue, the leaders are OneTrust, BitSight, Sprinto, UpGuard and Risk Ledger.

How much funding have vendor security and privacy assessment software companies raised?

The 22 vendor security and privacy assessment software companies tracked here have raised $1.4B in disclosed funding between them.

Related Security Software categories

Inclusion Criteria

- Must provide tools for assessing the security posture of vendors - Should include features for tracking compliance with relevant regulations and standards - Must support automated workflows for vendor risk assessments - Should enable continuous monitoring and reassessment of vendor security - Must facilitate vendor communication about security practices and requirements - Not just a simple questionnaire or form; must also offer risk scoring and reporting functionalities - Should integrate with existing enterprise security solutions