PuReAIpureAi
Free scan

Solutions

Your suppliers' exposure is your exposure

Most regulated incidents now arrive through a third party. PuReAI scores every supplier from the outside on the same model it uses for you, so a portfolio review is a data exercise rather than a document exercise.

What it replaces

The annual questionnaire stays. It stops being the only evidence.

WorkflowModules usedWhat you get
Onboarding a supplierDomain, IP, Certificate, TechnologyAn external estate map and a first Risk Score before the contract is signed.
Continuous monitoringVulnerability, Misconfiguration, Leaked DataDated findings and score movement between reviews, not only at renewal.
Concentration analysisSupply ChainShared infrastructure and shared technology across your supplier portfolio.
Actor exposureNews / Threats, threat graphWhich suppliers run technology targeted by groups currently active in your sector.
Regulatory reportingAll modulesExportable, dated evidence per supplier for the ICT register and supervisory questions.

Where it fits in the regulation

DORA requires financial entities to maintain a register of ICT third-party arrangements and to assess concentration risk. NIS2 requires essential and important entities to take proportionate supply chain security measures. Both expect ongoing evidence.

The requirement-level mapping is on the DORA and NIS2 page. If the platform itself has to run inside your environment, see deployment.

Questions we get asked

How is this different from a questionnaire platform?

A questionnaire records what a supplier says about itself once a year. PuReAI observes what the supplier exposes to the internet, continuously, and keeps the evidence behind every finding.

Do suppliers have to agree to be scanned?

PuReAI only collects publicly available data. Nothing is installed at the supplier and no access to their systems is requested. Many customers still tell suppliers, because the findings are more useful when they are shared.

Can a supplier dispute a finding?

Yes. Disputes go through an analyst review of the raw evidence, and when a collection rule is wrong it is fixed for every customer, not only the one who raised it.

Start with one supplier domain