Panorays
Primary category: vendor-risk. Also listed in third-party-ai-apps.
One-liner — Third-party cyber risk management that combines outside-in attack-surface ratings with inside-out security questionnaires in one workflow — and now uses an LLM to autofill both sides of the questionnaire exchange.
What it does — Two halves. Outside-in: automated external attack-surface assessment of a supplier’s internet-facing footprint, producing a rating — the same basic technique as bitsight, securityscorecard and black-kite. Inside-out: the security questionnaire workflow — issuing, chasing, scoring and reconciling supplier responses, which is processunity and whistic territory. Panorays’ argument is that neither half is sufficient alone: a rating tells you nothing about a supplier’s internal controls, and a questionnaire is self-reported. It contextualises both against how the supplier is actually used (what data they hold, what access they have), and layers regulatory mapping — DORA, NIS2, GDPR — over the assessment.
The 2026 product direction is AI-assisted throughput. Smart Match extracts answers from a supplier’s uploaded certifications, attestations and prior documentation to autofill questionnaires — attacking the real bottleneck in TPRM, which is the human hours spent on questionnaire round-trips rather than the assessment logic.
Naming / provenance — Founded 2016; Israeli R&D with a New York commercial HQ. Single brand, no renames.
Ownership & viability — independent, VC-backed. Roughly $62–67M raised (sources disagree on the total; the $42M Series B led by Greenfield Partners in September 2021 is firm). Investor list includes Oak HC/FT and StepStone plus notable security angels. No round found since 2021 and no acquisition as of 2026-08-26 — the same five-year funding gap that applies to several vendors in this category. Named a Leader in the Forrester Wave for Cybersecurity Risk Rating Platforms, Q2 2026, which is meaningful third-party validation of product, not of balance sheet.
Positioning & differentiators —
- Both halves in one tool. The ratings vendors (bitsight, securityscorecard) and the questionnaire vendors (processunity, whistic, venminder) have been converging on each other for years; Panorays was built at the intersection.
- Regulatory mapping for DORA and NIS2. Directly relevant to any manager with EU-regulated entities or EU counterparties — DORA’s ICT third-party register is exactly this workload.
- AI-assisted questionnaire processing is where Forrester scored it highest. For a small compliance team, throughput is the binding constraint, so this is the differentiator most likely to matter in practice.
- Extends to AI vendors. The natural path for assessing the AI features your existing SaaS suppliers have quietly switched on — see third-party-ai-apps. Whether Panorays ships a specific AI-vendor assessment template is unverified below.
Who should choose them / anti-fit — Fits a firm running a real TPRM programme over dozens-to-hundreds of suppliers, especially with DORA/NIS2 exposure, and a small team that needs the questionnaire cycle automated. The typical alternative-investment profile — heavy vendor concentration in fund admin, prime brokerage, market data, and now AI SaaS — matches well. Anti-fit: a firm that only wants a cheap outside-in score to satisfy a checkbox (a ratings-only vendor is cheaper), or one whose GRC suite (hyperproof, onetrust, archer) already carries an adequate TPRM module.
Known weaknesses / gotchas — Funding age versus a consolidating category. The published research it markets (the CISO survey) is vendor-sponsored — useful directionally, not as evidence. Outside-in rating accuracy suffers the same well-known limitations as every vendor in this space: attribution of internet assets to the right corporate entity is error-prone, and disputes with rated suppliers are routine.
Deployment & data handling — SaaS. Where assessment data resides, EU residency options, and retention terms are unverified — a live question for a DORA-driven purchase.
Integrations & partnerships — GRC and ticketing integrations claimed; specific connector list unverified.
Compliance & FS traction — Unverified. DORA/NIS2 mapping implies financial-services intent, but no named FS customers were confirmed. Certifications held not confirmed.
Commercial — Not public. Subscription, typically scaled by number of suppliers monitored.
Open questions
- Reconcile total funding (~$62M vs ~$67M) and confirm whether anything has been raised since 2021.
- EU data residency — necessary to answer before a DORA-driven purchase.
- Certifications held; named financial-services customers.
- Does Panorays ship a purpose-built AI-vendor assessment template, or is AI risk handled through generic questionnaire customisation?
- Practical accuracy of the outside-in ratings versus bitsight/black-kite on the same supplier set.
Sources
- Panorays Recognized as a Leader in The Forrester Wave, Q2 2026 (Panorays) — fetched 2026-08-26 — supports: Forrester Leader placement, scored criteria; confidence: medium (vendor summary of a paid analyst report)
- Panorays Closes $42 Million Series B (Panorays) — fetched 2026-08-26 — supports: Series B size, lead, investor list; confidence: high (primary)
- 2026 Study from Panorays: 85% of CISOs Can’t See Third-Party Threats (CIO) — fetched 2026-08-26 — supports: AI-in-TPRM adoption trend; confidence: medium (vendor-sponsored research)
- Cached:
raw/sources/2026-08-26--panorays--funding-and-forrester-2026.md
History
- [2026-08-26] Page created via wiki-create + researched same day. Sourced from the 2026-08-25 competitor scan (Tier A, score 8) — surfaced as a peer by OneTrust.