Everything you need to stay answer-ready

PrivyLedger is a vendor risk and sub-processor register — inventory, scores, contracts, AI exposure, DSAR deadlines, and exports. It is not enterprise GRC, a website scanner, or a consumer privacy app.

Living vendor inventory

Every SaaS product, processor, and AI tool in one workspace — category, region, data types, and an internal owner. Quick-add from a catalog or import a CSV so you are not starting from a blank sheet.

How to build a vendor risk register

Automatic risk scores

A 0–100 score with itemized reasons: missing DPA, trains on customer data, sensitive categories, risky regions, no owner. Built so an ops lead can explain the number on a call — not a black-box “cyber rating.”

Compare with spreadsheets and GRC

DPA & contract hygiene

Statuses for missing, requested, signed, and expiring agreements. Download a dated request letter from the vendor record instead of rewriting Article 28 emails from scratch.

DPA tracking guide

AI vendor register

First-class tracking for LLM APIs, copilots, and shadow tools: exposure bands, training-on-data flags, and a 90-day re-review cadence. Export an AI evidence pack when the questionnaire asks.

What is an AI vendor register?

DSAR deadline board

Access and erasure requests with due dates next to the vendor list that tells you who actually holds that person’s data. A clock, not a case-management suite.

DSAR deadline checklist

Questionnaire pack

Paste-ready answers for “list your sub-processors,” AI use, and data maps. Export markdown, SIG-Lite style, CAIQ style, CSV, or JSON — then review before you send.

Answering security questionnaires