BrainTrust · Vendor intelligence

Know who has access.
Know what to ask.

Independent, evidence-based security research on the vendors RIAs rely on. Find a provider, review what's sourced and what's still open, and leave with a documented, citable due-diligence record for your compliance file.

Data may be incomplete or out of date — confirm anything decision-critical directly with the vendor.
Your research desk

Vendor library

Screen the full catalog or focus on the records that need attention.

0 vendors in view

No vendors found

Try a broader search or clear your filters.

From search to evidence file

A defensible review, without the scavenger hunt.

01

Find the vendor

Search the catalog and see what client data the provider can reach.

02

Review the evidence

Read the plain-language assessment, then every sourced answer with its citation and capture date.

04

File the record

Turn on Selection mode and export the vendors you use as two deliverables for your compliance file: one printed PDF report and one Excel workbook.

About this resource

An independent, evidence-based reference on the cybersecurity and compliance posture of the vendors that financial firms — RIAs, broker-dealers, and funds — entrust with sensitive data. For each vendor we work through a fixed due-diligence questionnaire and publish what can be confirmed from public sources, with a link and capture date; anything we can't yet confirm is marked Unknown. Nothing is inferred, and every item is anchored to the regulation behind it — Reg S-P, Rule 206(4)-7, Rule 204-2, Reg S-ID. Vendors whose products embed AI get a supplemental review of how customer data is handled.

Want a hard copy? Download the Vendor Due Diligence Questionnaire (free BrainTrust sign-in required). Vendor missing? We prioritize research on request (≈30-day turnaround) — email vdd@mtradecraft.com. Have a vendor complete it themselves: forward the self-report form and their answers come back to us for review.

⚠️ Always a work in progress. A living resource — new vendors and re-reviews are added continuously, certifications lapse, and trust centers change. Public information only (no client data); not legal advice; not an endorsement. Verify anything decision-critical directly with the vendor.