ThreatWatch is a web platform for continuously monitoring vendors as third-party risks. It tracks breaches, dark-web exposure, attack-surface vulnerabilities, and compliance gaps, then assigns each vendor an A-to-F grade using threat intelligence, security scans, questionnaire responses, and certifications. A passive outside-in scan is available without signup or a credit card and returns a grade in about 30 seconds. Its catalogue contains 280,770 companies searchable by name, domain, or alias. Staff devices are checked hourly for exposure, and leaked credentials are re-checked daily. Vulnerability matching is part of every plan, but ThreatWatch confirms a vulnerability only when it can read the exact software version. Alerts can be sent to services including Slack, Microsoft Teams, Jira, ServiceNow, PagerDuty, email, and webhooks. Professional and higher plans include AI Co-Pilot and Ask AI, with human approval required for proposed changes. A free plan is available; paid plan pricing is on request.
Who it is for
ThreatWatch suits organisations that need to monitor vendor security and compliance across a portfolio. Its free plan covers an organisation’s own vendors, while paid plans list options for larger and multi-entity programmes.
What is good
- Free passive scan needs no signup or card.
- Catalogue contains 280,770 searchable companies.
- Vulnerability matching is included on every plan.
- Alerts can reach collaboration and service-management tools.
- Compliance AI supports listed and custom frameworks.
What to know first
- Free plan has no breach or dark-web intelligence.
- Free plan has no API, SSO, or AI agents.
- Vulnerabilities are confirmed only with an exact software version.
- Imported vendors wait for the plan’s first scheduled scan.
Verdict
ThreatWatch combines vendor monitoring, risk grading, and alert delivery, with scan cadence and capabilities varying by plan. The free scan offers a quick starting grade, while paid pricing requires an enquiry.
ThreatWatch plans and pricing
All plansCompared on security ratings software
- Free plan
- Yes
- Vendor monitoring
- Yes
- Attack surface coverage
- full attack surface
- Change alerts
- Yes
- API access
- Yes
- Risk frameworks
- ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, NIST CSF 2.0, NIST 800-53, CSA CCM, DORA, NIS2, ISO 42001, EU AI Act, EU Cyber Resilience Act


