Open Source · Version 2.5.3

Third-Party Risk,
Quantified in Dollars

Fair TPRM combines FAIR risk methodology with continuous security monitoring to transform vendor risk from guesswork into data-driven financial decisions.

Explore FAIR Analysis See Monitoring Features
40+
Granular Permissions
2
SRS Integrations
31
Database Tables
AES-256
Encryption at Rest

What Makes Fair TPRM Different

Purpose-built for organizations that need to connect vendor security posture to financial impact.

$

Financial Risk Quantification

FAIR methodology converts vendor risk into Annualized Loss Expectancy (ALE) with recommended cyber insurance coverage, giving leadership numbers they can act on.

Dual SRS Monitoring

Continuous external scanning via UpGuard and Shodan provides real-time security visibility across website, network, email, TLS, and vulnerability categories.

Full Vendor Lifecycle

From onboarding through procurement, security assessment, continuous scoring, and annual reviews — every phase is tracked and automated.

Enterprise Access Control

SAML 2.0 SSO, TOTP two-factor authentication, role-based permissions, and complete audit logging meet the strictest compliance requirements.

Cyber Todo Dashboard

Consolidated action items from expiring certificates, overdue rescores, score drops, annual reviews, and unapproved vendors in one prioritized view.

Bank-Grade Security

AES-256-CBC encryption at rest, Argon2id password hashing, CSRF protection, security headers, and encrypted file uploads for assessment documents.

Platform Overview

A modern PHP 8.3 application backed by MariaDB with Docker-ready deployment.

Built for Enterprise Scale

Fair TPRM is architected with service layers, singleton patterns, and permission-aware queries to support organizations managing hundreds of vendor relationships.

  • PHP 8.3 with strict typing and modern patterns
  • MariaDB/MySQL or SQLite database support
  • Docker Compose deployment in minutes
  • 6-step setup wizard — no coding required
  • Theme customization with brand colors and logos
  • 14 SQL migrations with rollback tracking
PHP Version 8.3
Service Classes 8
API Endpoints 16
ACL Permissions 40+
Assessment Templates 2 Default
Encrypted Fields 40+

Default Role-Based Access

Four built-in groups cover common organizational structures out of the box.

Group Access Level Typical Users
Administrator Full System Access IT Security leadership, system admins
Cyber TPRM All TPRM Operations Security analysts, risk managers
Procurement Vendor & Analysis Access Procurement team, vendor managers
Stakeholder Own/Assigned Vendors Business unit owners, project leads

Ready to Quantify Your Vendor Risk?

Explore the core capabilities that make Fair TPRM the data-driven approach to third-party risk management.

FAIR Analysis Security Monitoring Vendor Lifecycle