Find the vendor
Search the catalog and see what client data the provider can reach.
Independent, evidence-based security research on the vendors RIAs rely on. Find a provider, review what's sourced and what's still open, and leave with a documented, citable due-diligence record for your compliance file.
Screen the full catalog or focus on the records that need attention.
Try a broader search or clear your filters.
Search the catalog and see what client data the provider can reach.
Read the plain-language assessment, then every sourced answer with its citation and capture date.
Use the open questions as a vendor follow-up list — or send the vendor our self-report form.
Turn on Selection mode and export the vendors you use as two deliverables for your compliance file: one printed PDF report and one Excel workbook.
An independent, evidence-based reference on the cybersecurity and compliance posture of the vendors that financial firms — RIAs, broker-dealers, and funds — entrust with sensitive data. For each vendor we work through a fixed due-diligence questionnaire and publish what can be confirmed from public sources, with a link and capture date; anything we can't yet confirm is marked Unknown. Nothing is inferred, and every item is anchored to the regulation behind it — Reg S-P, Rule 206(4)-7, Rule 204-2, Reg S-ID. Vendors whose products embed AI get a supplemental review of how customer data is handled.
Want a hard copy? Download the Vendor Due Diligence Questionnaire (free BrainTrust sign-in required). Vendor missing? We prioritize research on request (≈30-day turnaround) — email vdd@mtradecraft.com. Have a vendor complete it themselves: forward the self-report form and their answers come back to us for review.