Skip to main content

Trust Chain

A guide to managing third-party risk in Strike Graph

Written by Laurel True-McCarthy

Getting Started with Trust Chain

Trust Chain is Strike Graph's third-party risk management (TPRM) solution. Instead of sending vendors questionnaires to self-attest, you assign them evidence requests and they upload supporting documentation directly. Verify AI then assesses each submission against your defined criteria.

You can invite up to 5 vendors for free.

Step 1: Add a Vendor

  1. In the left navigation, click the Trust Chain tab.

  2. Click the Vendors tab.

  3. Click Add New Vendor.

  4. Enter the vendor's company name, contact name, and contact email address.

Vendors are not notified when they're added. They won't receive anything until you assign them evidence requests and send an invitation.

Alternatively, you can bulk import vendors by preparing a spreadsheet with three columns — Vendor Name, Contact Name, and Email Address — and clicking Upload Vendor List.

Step 2: Build Your Evidence Request Library

Your Evidence Request Library is where you define what you're asking vendors to prove. Each request includes a name, a description, and an optional expiration date. The description is the exact criteria Verify AI will use to evaluate submitted evidence, so write it clearly and with measurable outcomes.

To get started quickly, download one of our pre-built starter sets and upload it via the Bulk Create button in your Request Library. You can edit, delete, or add requests at any time.

To create a request manually, click Create Evidence Request, enter a name and description, and save.

Example of a well-written request:

"Upload your most recent penetration test report, conducted within the last year, with no medium or high vulnerabilities found. The report must name an appropriately accredited auditor."

Step 3: Assign Requests to Vendors

  1. Go to the Vendors tab and select one or more vendors.

  2. Click Assign Evidence Items.

  3. In the modal, select the requests you want to assign (or toggle all on).

  4. Click Submit.

You can assign all requests to all vendors at once, or hand-pick specific requests per vendor.

Step 4: Send Invitations

  1. Click the kebab menu (⋮) next to a vendor's name.

  2. Click Invite.

This sends the vendor an email from hello@strikegraph.com with instructions to log in and complete their requests. We recommend also sending them a heads-up from your own email address so they know to expect it.

Step 5: Monitor Progress

Check your Trust Chain dashboard periodically to track vendor progress. The dashboard shows each vendor's assessment status, the number of requests assigned, the number satisfied, and any items that need attention.


Managing Evidence Requests

Editing a Request

  1. Find the request in your Request Library.

  2. Click the kebab menu (⋮) next to it and select Edit.

  3. Update the name, description, or expiration date and save.

Changes to a request's description will affect how Verify AI evaluates future submissions for that request.

Deleting a Request

Deleting a request from your library removes it from the assignable list and unassigns it from any vendors it was previously assigned to.

If you only want to remove a request from a specific vendor (without deleting it from your library):

  1. Go to the Vendors tab and click into the vendor's detail page.

  2. Find the request you want to remove.

  3. Click the kebab menu (⋮) next to it and select Unassign.

Assigning Evidence Requests

You can assign requests in bulk (all requests to all vendors at once) or individually per vendor. To assign requests, select one or more vendors from the Vendors tab, click Assign Evidence Items, and choose the requests from the modal.


Understanding Vendor Assessment Statuses

Your Trust Chain dashboard displays a status for each vendor that reflects where they are in the assessment process.

Status

What It Means

Satisfied

The vendor has uploaded evidence for all requests, and each has either passed Verify AI's review or been manually marked as reviewed and accepted by your team.

Needs Review

One or more of the vendor's submissions has been flagged by Verify AI for your manual review.

In Progress

The vendor is actively uploading evidence. No submissions have been flagged yet.

Invited

The vendor has been invited but hasn't started uploading evidence.

Ready to Invite

The vendor has been added to the system but hasn't been invited yet.

You can also set a manual Vendor Status on each vendor's detail page (e.g., Approved, Under Review, Onboarding, Declined) to communicate their standing to your team.


Reviewing Vendor Evidence Submissions

How Verify AI Evaluates Evidence

When a vendor uploads a document, Verify AI automatically assesses it against the description in the corresponding evidence request. Each submission receives one of two statuses:

  • Passed — The document meets all criteria in the request description.

  • Needs Attention — The document did not fully meet the criteria. A description of the discrepancy is provided.

Note: If a vendor has marked their evidence as sensitive, the Verify AI assessment description will be hidden. You'll see a message indicating the evidence is restricted. You can still leave a comment for the vendor if you have questions.

Reviewing a Flagged Submission

  1. Navigate to the vendor's detail page.

  2. Click into the evidence request marked Needs Attention.

  3. Review the Verify AI status and the description of the discrepancy.

  4. Take one of the following actions:

    • Accept the submission — If you determine the evidence is sufficient, open the kebab menu within the Verify AI panel and select Mark as Reviewed.

    • Request access to the document — In the Attachments section, click Request Access on the document card. The vendor will receive an email. You'll be notified when access is granted or denied.

    • Leave a comment — Click the Comment tab within the evidence request and write your note. Use the @ symbol to tag the vendor contact so they receive a notification.

Requesting Access to Vendor Documents

By default, you do not have access to the documents a vendor uploads. To request access:

  1. Navigate to the evidence request.

  2. Scroll to the Attachments section.

  3. Click Request Access on the relevant document card.

The request button will become inactive while you wait. If access is granted, you'll receive an email and can return to preview or download the document. If access is denied, the button becomes active again. Documents you have access to will no longer show the Request Access button.


Working with Unresponsive Vendors

Vendors receive a weekly system-generated reminder email between the time they're invited and their assessment due date — until they log in for the first time.

If a vendor remains unresponsive, we recommend following up with them directly.

If the vendor provides a Trust Center or publicly available documentation, you can upload evidence to their requests yourself:

  1. Go to the vendor's detail page.

  2. Click into the relevant evidence request.

  3. Click Add Attachments and upload the file.

Verify AI will assess the document immediately. Note that vendors can see anything you upload on their behalf.

If a request doesn't exist yet for the document you want to upload, create it in your Request Library, assign it to the vendor, then upload the attachment.

Did this answer your question?