Assess suppliers on real data
Automatic analysis of your suppliers' security maturity, based on publicly available signals, not questionnaires.
Automatic Supplier Detection
Tracer automatically detects suppliers from your product data and component lists, no manual table maintenance.
RFC 9116 · found
security.txt Detection
Tracer automatically checks whether your suppliers have published a security.txt according to RFC 9116, the first indicator of security maturity.
CVD Policy Detection
Does the supplier have a Coordinated Vulnerability Disclosure Policy? Tracer finds out and evaluates the quality.
CSAF Feed Detection
Tracer detects whether suppliers publish CSAF advisories, machine-readable security notices according to international standards.
PSIRT
productcert@siemens.com
PSIRT Analysis
Does the supplier have a Product Security Incident Response Team? Tracer analyzes the publicly available information.
Properties
Maturity Level (0-5)
The maturity level shows at a glance how far a supplier is in their security maturity, from "no signals" to "best practice".
How it works
Three steps to the full picture.
01
Suppliers are detected
Tracer pulls your suppliers from your product data. You can add more at any time.
supported by Scanner
02
Tracer checks what is actually there
security.txt, CVD policy, CSAF feed, PSIRT: Tracer checks what the supplier has really published. No questionnaire, no self assessment.
03
You see who you can trust
A score from 0 to 100 and a maturity level from 0 to 5, per supplier. If something changes you notice right away.
The difference
Wait eight weeks for answers.
Or simply look it up.
Send out a questionnaire with 47 questions, follow up, wait. Back comes three times yes and a checkmark. Nobody ever checked whether the security.txt really exists.
Tracer looks at what the supplier has actually published and turns it into a score from 0 to 100. If the security.txt disappears again, you see it right away.
