ThreatWatch
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- Web

Summary
ThreatWatch is a web-based third-party risk intelligence platform for continuous vendor monitoring. It tracks breaches, dark-web exposure, attack-surface vulnerabilities and compliance gaps, then gives each vendor an A-to-F grade based on threat intelligence, security scanning, questionnaire responses and certifications. Its free outside-in scan is passive, requires no signup or credit card, and returns a grade in about 30 seconds. A catalogue of 280,770 companies can be searched by name, domain or alias. The platform re-checks vendor staff devices hourly and leaked credentials daily. Vulnerabilities are matched only when the exact software version can be read, and vulnerability matching is included on every plan. Alerts can be delivered to Slack, Microsoft Teams, Jira, ServiceNow, PagerDuty, email, the app or a generic webhook. Compliance AI covers PCI-DSS, ISO 27001, SOC 2, HIPAA, GDPR and NIST CSF questionnaires, as well as custom frameworks. AI Co-Pilot and Ask AI begin at Professional, and proposed changes need human approval. A free plan is listed; prices for paid plans are on request.
Who it is for
ThreatWatch is suited to organizations that need to monitor vendor exposure and compliance status. Its free scan offers a way to inspect a vendor grade without creating an account, while larger portfolios may need paid-plan features.
What is good
- Free passive scan needs no signup or card.
- Vendor catalogue has 280,770 searchable companies.
- Alerts support email, app and several integrations.
- Vulnerability matching is included on every plan.
- Compliance AI supports named frameworks and custom ones.
What to know first
- Free plan has no breach or dark-web intelligence.
- Free plan excludes API access and SSO.
- Imported vendors wait for their scheduled first scan.
- Paid plan prices are available on request.
Verdict
ThreatWatch combines vendor grading with exposure monitoring, alerts and compliance questionnaires. The free plan is limited in intelligence and access features, so check the plan details against the monitoring cadence and capabilities your programme needs.
ThreatWatch plans and pricing
All plansCompared on security ratings software
- Free plan
- Yesthreat.watch
- Vendor monitoring
- Yesthreat.watch
- Attack surface coverage
- full attack surfacethreat.watch
- Change alerts
- Yesthreat.watch
- API access
- Yesthreat.watch
- Risk frameworks
- ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, NIST CSF 2.0, NIST 800-53, CSA CCM, DORA, NIS2, ISO 42001, EU AI Act, EU Cyber Resilience Actthreat.watch
Facts
- Product
- ThreatWatch is a third-party risk intelligence platform for continuously monitoring vendors.threat.watch · 1 Oct 2026
- Monitoring
- It monitors vendor breaches, dark-web exposure, attack-surface vulnerabilities, and compliance gaps.threat.watch · 1 Oct 2026
- Risk grade
- Each vendor receives an A-to-F grade built from threat intelligence, security scanning, questionnaire responses, and certifications.threat.watch · 1 Oct 2026
- Passive scanning
- The free scan is outside-in and passive, requires no signup or credit card, and returns a grade in about 30 seconds.threat.watch · 1 Oct 2026
- Vendor catalogue
- The platform includes a catalogue of 280,770 companies searchable by name, domain, or alias.threat.watch · 1 Oct 2026
- Dark-web cadence
- Vendor staff devices are re-checked hourly and leaked credentials are re-checked daily.threat.watch · 1 Oct 2026
- Vulnerability matching
- ThreatWatch confirms vendor vulnerabilities only when it can read the exact software version, and vulnerability matching is included on every plan.threat.watch · 1 Oct 2026
- Integrations
- Outbound alerts can be delivered to Slack, Microsoft Teams, Jira, ServiceNow, PagerDuty, email, the app, or a generic webhook.threat.watch · 1 Oct 2026
- AI approval
- The AI Co-Pilot and Ask AI are available from Professional and above, and proposed changes require human approval.threat.watch · 1 Oct 2026
- Compliance frameworks
- Compliance AI supports PCI-DSS, ISO 27001, SOC 2, HIPAA, GDPR, and NIST CSF questionnaires, plus custom frameworks.threat.watch · 1 Oct 2026
- Security controls
- Traffic uses TLS with one year of preloaded HSTS, while secrets such as API keys, SSO secrets, and integration credentials are encrypted at field level at rest.threat.watch · 1 Oct 2026
- Vendor access
- Vendors use a one-time code sent to their email rather than creating an account or password.threat.watch · 1 Oct 2026
- Import limitation
- Imported vendors are not scanned when the file is uploaded; they wait for the first scan in the plan schedule.threat.watch · 1 Oct 2026
Best ThreatWatch alternatives
See all 12Where it ranks on Everything Xiaomi
Is ThreatWatch yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- threat.watch· checked 1 Oct 2026
- threat.watch/product· checked 1 Oct 2026
- threat.watch/use-cases/onboarding· checked 1 Oct 2026
- threat.watch/platform/intelligence· checked 1 Oct 2026
- threat.watch/platform/vulnerabilities· checked 1 Oct 2026
- threat.watch/faq· checked 1 Oct 2026
- threat.watch/platform/agents· checked 1 Oct 2026
- threat.watch/platform/vendor-portal· checked 1 Oct 2026
- threat.watch/platform/portfolio· checked 1 Oct 2026



