Black Kite Third-Party Cyber Risk
- 1Runs onWeb
- 2Assessment methodhybrid
- 3Continuous monitoringYes
- 4Questionnaire libraryYes
- 5Framework mappingYes
- 6Evidence collectionYes
- 7Workflow automationYes

Overview
Black Kite Third-Party Cyber Risk is a web platform for monitoring and assessing cyber risk across vendor portfolios and extended supply chains. It provides visibility from first-party posture through fifth-party exposure, flags suppliers, software products, and geographies as possible single points of failure, and maps downstream exposure. Black Kite Monitor continuously tracks vendor portfolios, while FocusTags connect breaches, active exploits, CVEs, and dark-web exposures to vendors. The Ransomware Susceptibility Index provides a predictive, vendor-specific signal. Black Kite Assess parses policies and compliance documents, mapping evidence to more than 25 global frameworks or a custom framework; its shared workspace supports gap sharing, remediation requests, and follow-up with vendors. The platform grounds findings in open, auditable standards, and Open FAIR-based analysis translates cyber posture into dollar-denominated exposure. It supports hybrid assessments, questionnaire libraries, framework mapping, evidence collection, and workflow automation. Official integrations include ServiceNow, Aravo, OneTrust, Splunk, Jira, Power BI, Slack, Zapier, Microsoft Teams, and others. Pricing is on request.
Who it is for
It suits organizations that monitor vendor portfolios and need visibility into downstream supply-chain exposure. Teams assessing policies against frameworks or coordinating vendor remediation may use its listed Assess capabilities.
What is good
- Visibility extends through fifth-party exposure.
- Monitor provides continuous vendor portfolio monitoring.
- Assess maps evidence to global or custom frameworks.
- Open FAIR-based analysis expresses exposure in dollars.
- Standard and Enterprise plans list unlimited users.
What to know first
- Pricing is available only on request.
- The listed platform is web only.
- Production customer data is stored and processed in US-based GCP regions.
Verdict
Black Kite combines continuous monitoring, supply-chain exposure mapping, and document-based assessments with vendor collaboration. Pricing requires a request, and production data residency is limited to US-based Google Cloud Platform regions.
Black Kite Third-Party Cyber Risk plans and pricing
All plansCompared on third-party risk management software
- Assessment method
- hybridblackkite.com
- Continuous monitoring
- Yesblackkite.com
- Questionnaire library
- Yesblackkite.com
- Framework mapping
- Yesblackkite.com
- Evidence collection
- Yesblackkite.com
- Workflow automation
- Yesblackkite.com
Facts
- Extended supply-chain visibility
- Black Kite provides real-time visibility from first-party posture through fifth-party exposure across the extended supply chain.blackkite.com · 1 Oct 2026
- Concentration risk
- The platform identifies suppliers, software products and geographies that represent single points of failure.blackkite.com · 1 Oct 2026
- Cascading risk
- Black Kite maps third-, fourth- and fifth-party exposure to show how downstream impact can travel through the supply chain.blackkite.com · 1 Oct 2026
- Open standards
- Black Kite grounds findings in open, auditable standards for traceable and explainable risk decisions.blackkite.com · 1 Oct 2026
- Financial quantification
- Open FAIR-based analysis translates vendor and supply-chain cyber posture into dollar-denominated exposure.blackkite.com · 1 Oct 2026
- Threat intelligence
- FocusTags map breaches, active exploits, CVEs and dark-web exposures directly to vendors in a portfolio.blackkite.com · 1 Oct 2026
- Ransomware prediction
- The Ransomware Susceptibility Index is a predictive vendor-specific signal for ransomware susceptibility.blackkite.com · 1 Oct 2026
- AI assessments
- Black Kite Assess parses policies and compliance documents and maps evidence to more than 25 global frameworks or a custom framework.blackkite.com · 1 Oct 2026
- Vendor collaboration
- Assess provides a shared workspace to share gaps, request remediation and track follow-up with vendors.blackkite.com · 1 Oct 2026
- Integrations
- Official integrations include ServiceNow TPRM and ITSM, Aravo, LogicGate Risk Cloud, OneTrust, Archer, Splunk, Jira, Power BI, Slack, Zapier, Microsoft Teams and an MCP Server.blackkite.com · 1 Oct 2026
- SOC 2
- Black Kite completed a SOC 2 Type 2 examination covering security, availability, confidentiality, processing integrity and privacy criteria.blackkite.com · 1 Oct 2026
- GovRAMP
- Black Kite announced GovRAMP Authorization for its Third-Party Cyber Risk Intelligence platform in July 2026.blackkite.com · 1 Oct 2026
- Data residency
- Production customer data is stored and processed exclusively in US-based Google Cloud Platform regions.blackkite.com · 1 Oct 2026
Company
- Headquarters
- Boston, Massachusetts, United Statesblackkite.com · 28 Sept 2026
Best Black Kite Third-Party Cyber Risk alternatives
See all 20Where it ranks on Specifiction
Is Black Kite Third-Party Cyber Risk yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- blackkite.com/platform· checked 1 Oct 2026
- blackkite.com/platform/monitor· checked 1 Oct 2026
- blackkite.com/platform/assess· checked 1 Oct 2026
- blackkite.com/platform/integrations· checked 1 Oct 2026
- blackkite.com/press-releases/black-kite-achieves-soc-· checked 1 Oct 2026
- blackkite.com/press-releases/black-kite-achieves-govr· checked 1 Oct 2026
- blackkite.com/privacy-policy· checked 1 Oct 2026
- blackkite.com· checked 28 Sept 2026
- blackkite.com/blog/no-hidden-costs-how-black-kite-red· checked 1 Oct 2026


