Third-party risk tools compete on dashboards. Noctovisor is the opposite: "It could have been an email!", so it is one. We read the public record daily: court filings, company registers, sanctions lists, the press. Every company is resolved to its legal entity, every finding verified against its source, and you get one email when a company crosses a line you set. Most days: nothing. Monday logs and monthly reports cover DORA, NIS2, Reg S-P, Part 500. Free 30-day watch, ten companies, no card.
I'm Piotr, founder of Noctovisor third-party risk monitoring service by email.
I worked in supplier risk assessments for years and it always bugged me that we reviewed suppliers once a year and the reviews were often just a big theater - declarative questionnaires that everyone hated. Then there's enterprise risk intelligence tools that pretty much drown you in information and force you to sift through their dashboards. For such an important matter (companies lose billions a year due to their third parties failing) it's not good enough.
So we built a service that reads global public sources: court filings, registers, sanctions lists, press, daily. Everything gets checked against the source, matched to a unique legal entity, then we log the identified risks but send email alerts only when your third party is on fire (sometimes literally). Most days we send nothing at all.
We also produce and send weekly and monthly reports that are built to answer the questions DORA, NIS2 and similar frameworks ask about third-party oversight, so you can hand them to an assessor as they are.
We launched today and I'd like to see how TPRM people use it, what works, and what you would never pay for. We have a free trial (no card, no personal data) so you can check the full product for yourself.
Questions very welcome, I'll be around all day.
Report
Hey Piotr, grats on the launch! How much of it is AI and which one do you use?
Report
Maker
@kamila_walaszkiewicz Thanks! A fair amount is agentic AI, all of it in the pipeline. We run different models on different stages: smaller ones for simple work like summaries and translation, the strongest ones for entity resolution and verification, where a second model's entire job is to disagree with the first before anything reaches our clients. There's also human oversight of course. Today no alerts go out without a person approving them first.
The whole thing is model agnostic, so we switch to the best available models as they change. Right now we use Gemini and Claude, with OpenAI as redundancy. All of it through APIs whose terms exclude training on our data, so nothing about your third parties feeds anyone's model. Plus every alert links to its public source, so you don't have to take an LLM's word for anything.
Hi Product Hunt 👋,
I'm Piotr, founder of Noctovisor third-party risk monitoring service by email.
I worked in supplier risk assessments for years and it always bugged me that we reviewed suppliers once a year and the reviews were often just a big theater - declarative questionnaires that everyone hated.
Then there's enterprise risk intelligence tools that pretty much drown you in information and force you to sift through their dashboards.
For such an important matter (companies lose billions a year due to their third parties failing) it's not good enough.
So we built a service that reads global public sources: court filings, registers, sanctions lists, press, daily. Everything gets checked against the source, matched to a unique legal entity, then we log the identified risks but send email alerts only when your third party is on fire (sometimes literally).
Most days we send nothing at all.
We also produce and send weekly and monthly reports that are built to answer the questions DORA, NIS2 and similar frameworks ask about third-party oversight, so you can hand them to an assessor as they are.
We launched today and I'd like to see how TPRM people use it, what works, and what you would never pay for. We have a free trial (no card, no personal data) so you can check the full product for yourself.
Questions very welcome, I'll be around all day.
Hey Piotr, grats on the launch! How much of it is AI and which one do you use?
@kamila_walaszkiewicz Thanks! A fair amount is agentic AI, all of it in the pipeline.
We run different models on different stages: smaller ones for simple work like summaries and translation, the strongest ones for entity resolution and verification, where a second model's entire job is to disagree with the first before anything reaches our clients. There's also human oversight of course. Today no alerts go out without a person approving them first.
The whole thing is model agnostic, so we switch to the best available models as they change. Right now we use Gemini and Claude, with OpenAI as redundancy.
All of it through APIs whose terms exclude training on our data, so nothing about your third parties feeds anyone's model.
Plus every alert links to its public source, so you don't have to take an LLM's word for anything.