Panorays

Primary category: vendor-risk. Also listed in third-party-ai-apps.

One-liner — Third-party cyber risk management that combines outside-in attack-surface ratings with inside-out security questionnaires in one workflow — and now uses an LLM to autofill both sides of the questionnaire exchange.

What it does — Two halves. Outside-in: automated external attack-surface assessment of a supplier’s internet-facing footprint, producing a rating — the same basic technique as bitsight, securityscorecard and black-kite. Inside-out: the security questionnaire workflow — issuing, chasing, scoring and reconciling supplier responses, which is processunity and whistic territory. Panorays’ argument is that neither half is sufficient alone: a rating tells you nothing about a supplier’s internal controls, and a questionnaire is self-reported. It contextualises both against how the supplier is actually used (what data they hold, what access they have), and layers regulatory mapping — DORA, NIS2, GDPR — over the assessment.

The 2026 product direction is AI-assisted throughput. Smart Match extracts answers from a supplier’s uploaded certifications, attestations and prior documentation to autofill questionnaires — attacking the real bottleneck in TPRM, which is the human hours spent on questionnaire round-trips rather than the assessment logic.

Naming / provenance — Founded 2016; Israeli R&D with a New York commercial HQ. Single brand, no renames.

Ownership & viabilityindependent, VC-backed. Roughly $62–67M raised (sources disagree on the total; the $42M Series B led by Greenfield Partners in September 2021 is firm). Investor list includes Oak HC/FT and StepStone plus notable security angels. No round found since 2021 and no acquisition as of 2026-08-26 — the same five-year funding gap that applies to several vendors in this category. Named a Leader in the Forrester Wave for Cybersecurity Risk Rating Platforms, Q2 2026, which is meaningful third-party validation of product, not of balance sheet.

Positioning & differentiators

  • Both halves in one tool. The ratings vendors (bitsight, securityscorecard) and the questionnaire vendors (processunity, whistic, venminder) have been converging on each other for years; Panorays was built at the intersection.
  • Regulatory mapping for DORA and NIS2. Directly relevant to any manager with EU-regulated entities or EU counterparties — DORA’s ICT third-party register is exactly this workload.
  • AI-assisted questionnaire processing is where Forrester scored it highest. For a small compliance team, throughput is the binding constraint, so this is the differentiator most likely to matter in practice.
  • Extends to AI vendors. The natural path for assessing the AI features your existing SaaS suppliers have quietly switched on — see third-party-ai-apps. Whether Panorays ships a specific AI-vendor assessment template is unverified below.

Who should choose them / anti-fit — Fits a firm running a real TPRM programme over dozens-to-hundreds of suppliers, especially with DORA/NIS2 exposure, and a small team that needs the questionnaire cycle automated. The typical alternative-investment profile — heavy vendor concentration in fund admin, prime brokerage, market data, and now AI SaaS — matches well. Anti-fit: a firm that only wants a cheap outside-in score to satisfy a checkbox (a ratings-only vendor is cheaper), or one whose GRC suite (hyperproof, onetrust, archer) already carries an adequate TPRM module.

Known weaknesses / gotchas — Funding age versus a consolidating category. The published research it markets (the CISO survey) is vendor-sponsored — useful directionally, not as evidence. Outside-in rating accuracy suffers the same well-known limitations as every vendor in this space: attribution of internet assets to the right corporate entity is error-prone, and disputes with rated suppliers are routine.

Deployment & data handling — SaaS. Where assessment data resides, EU residency options, and retention terms are unverified — a live question for a DORA-driven purchase.

Integrations & partnerships — GRC and ticketing integrations claimed; specific connector list unverified.

Compliance & FS tractionUnverified. DORA/NIS2 mapping implies financial-services intent, but no named FS customers were confirmed. Certifications held not confirmed.

Commercial — Not public. Subscription, typically scaled by number of suppliers monitored.

Open questions

  • Reconcile total funding (~$62M vs ~$67M) and confirm whether anything has been raised since 2021.
  • EU data residency — necessary to answer before a DORA-driven purchase.
  • Certifications held; named financial-services customers.
  • Does Panorays ship a purpose-built AI-vendor assessment template, or is AI risk handled through generic questionnaire customisation?
  • Practical accuracy of the outside-in ratings versus bitsight/black-kite on the same supplier set.

Sources

History

  • [2026-08-26] Page created via wiki-create + researched same day. Sourced from the 2026-08-25 competitor scan (Tier A, score 8) — surfaced as a peer by OneTrust.