Skip to content

Vendors

The vendor directory lists the third-party services your company relies on. For each vendor, you complete a risk assessment questionnaire that produces a risk level, and Oneleet records when the vendor was reviewed and by whom. Completed assessments feed your compliance monitors and controls, and vendors can appear as subprocessors on your Trust Center.

Open the directory from Organization > Vendors in the sidebar. Everyone in your workspace, including auditors, can view the directory and open assessments read-only; adding vendors, editing assessments, and removing vendors require the admin role.

  1. Go to Organization > Vendors and click Add vendors.

  2. In the modal, click the Select or Add Vendors field. Check vendors from Oneleet’s catalog, or type a name that isn’t listed and choose the option to add it as a new custom vendor.

  3. Click Add vendors.

If you add a single vendor, its assessment opens right away. Adding several returns you to the directory filtered to the Needs details group.

When you connect an integration, Oneleet adds the corresponding vendor to the directory. The vendor sits in the Needs details group until you complete its risk assessment. If you previously removed the vendor from the directory, connecting the integration won’t add it back.

Vendors discovered through your integrations also appear below the search field in the Add vendors modal, marked with a star icon. Add the ones you want, or click Choose All to add all detected vendors.

Vendors are grouped by assessment status: Needs details for vendors whose assessment isn’t finished, then High risk, Moderate risk, and Low risk. In the Services column, country flags mark the vendor’s processing locations and a PII tag means the vendor processes personally identifiable information.

Search matches vendor names, categories, and descriptions. The table sorts by Date added, newest first, by default. Click any row to open that vendor’s assessment.

Each vendor has its own assessment page, with sections listed in the left navigation. Some sections appear conditionally in response to your answers. Answers save automatically as you type.

Assessments for catalog vendors come pre-filled from a template written by Oneleet’s compliance team. If your answers diverge from the template, a banner says so and offers Reset to template.

Expect questions about how much your business depends on the vendor, how it processes and stores data, and its security practices, including its most recent independent security assessment or penetration test.

An assessment counts as complete when every applicable question is answered and, for vendors that store data, the data inventory has at least one entry. The Needed for completion bar lists anything still missing; click an item to jump to that section.

Assign a compliance owner from your workspace members. The owner oversees the vendor and receives risk-related notifications. If the right person isn’t on Oneleet yet, the Add now link takes you to the People page.

For custom vendors, you can set a Logo URL — a link to an image shown as the vendor’s logo in Oneleet and on your Trust Center. The link must start with http or https.

If you answer yes to Does this vendor process or store data?, describe what data the vendor handles. Click + Add data entry to add each item with a description, a sensitivity level (Public, Internal, Confidential, or Secret), and tags.

Switching Does this vendor process or store data? to No while entries exist prompts you to confirm, because the entries are removed and can’t be recovered.

Vendors with data answers from before the inventory existed show a Set up your data inventory prompt with a button that carries the old answers over.

The Risk level section shows a suggested risk level computed from your answers. Riskier answers and more sensitive data inventory entries raise the suggested risk level.

If needed, you can click Override to set the level to High, Moderate, or Low, replacing the suggested level.

Attach supporting material in the Evidence section: drop files to upload them, click Add link to attach a URL, or click Link evidence to attach evidence that already exists in your workspace. The Notes section accepts Markdown.

Once the Needed for completion bar is empty, click Complete assessment. Oneleet records the review date and reviewer, shows them in the Reviewed column, and logs the review in your audit log. If the assessment later becomes incomplete, the review stamp is cleared until you complete it again.

While any vendor is unreviewed, a banner at the top of the directory offers to review them. Click Start review (or Review vendors) in the banner to open the review queue, which steps through your vendors one assessment at a time. Complete the current vendor’s assessment and click Continue, or click Skip to save your answers and move on without finishing this vendor.

The queue advances alphabetically through unreviewed vendors and returns you to the directory when none remain. A sidebar lists every vendor in the queue with a reviewed indicator, and you can click any of them to switch.

A vendor’s assessment shows its current version in the Questionnaire version section. New custom vendors start on the latest version; vendors added earlier may still be on an older one.

Click Upgrade questionnaire version to move a vendor to a newer version. Compatible answers carry over automatically, and a message reports how many did. Answers to some questions may be lost, so the upgrade asks you to confirm first.

The Trust Center derives a vendor’s public services list and PII flag from its data inventory — only entries flagged to appear on the Trust Center contribute to the services list.

Vendors still on the legacy questionnaire instead include a Subprocessor Information section covering services provided, PII processing, processing locations, and the vendor’s URL. Filling it in lists the vendor as a subprocessor on your Trust Center.

  1. On the directory, select vendors with the row checkboxes.

  2. Click Remove in the panel that appears.

  3. Confirm in the removal dialog.

Removing a vendor doesn’t delete its assessment. If you add the vendor back through Add vendors, it returns with its risk level, services, processing locations, and notes still intact.

Every vendor you add becomes a monitored asset, and vendor management backs several controls.

Monitors fail for each vendor whose assessment isn’t complete, and for each data-storing vendor whose data inventory is empty; vendors that answered they store no data are exempt from the inventory check.