Supply Chain Risk Management
When your supplier is breached, you find out first.
Your suppliers become part of your risk surface the moment they ship you code. Correlens watches them across threat-intel sources, scores the noise, and correlates a breach to the exact components and programs it puts at risk.
| Supplier | Tier | CIA status | CVD policy | Support until | Signals |
|---|---|---|---|---|---|
| Silicon vendor · gateway MCU | Tier 2 | signed | coordinated | 2032-06 | 1 active |
| Telematics stack provider | Tier 1 | signed | coordinated | 2031-01 | clear |
| IVI middleware vendor | Tier 1 | in negotiation | mailbox only | 2029-09 | 2 watch |
| OSS crypto library | OSS | n/a | public CVD | community | clear |
tiering per ISO/SAE 21434 · interface status and CVD policy per supplier · signals from live monitoring
Suppliers mapped to your programsCurated supplier records with tier, role and the components they ship, aligned to ISO/SAE 21434 tiering.
Watched across every sourceBreach claims, leak markets, adverse news and dark-web listings, all in one feed.
Scored, not cried wolfThe AI weighs the claim and the actor’s history into a confidence, so a boast is not an incident.
Correlated to your exposureWhich of your components, nodes and programs a supplier touches, ranked by risk.
Breach to impact
From a claim on a forum to the parts on your line.
A breach claim is only useful once it is resolved against what that supplier actually ships you. The correlation runs across your register and your SBOMs, and what cannot be verified is said so.
- Confidence first. The actor's history and the claim's specifics set the score; a boast is not an incident.
- Exposure resolved. Shared components, the nodes they sit on and the programs at risk, ranked.
- Interface-aware. Cybersecurity Interface Agreement status and CVD policy tell you how the supplier will respond.
Your supplier register and your SBOMs stay inside the platform. Monitoring reads public and dark-web sources; nothing about your programs is shared back out.
Supplier breach signalsample data
Actor advertises build credentials allegedly stolen from a Tier-1 middleware vendor
Confidence: 0.62 · MEDIUMCorrelated to your programs
ivi-media-core 4.2 · IVI Head Unit2 programs
nav-render 2.9 · IVI Head Unit1 program
ota-agent 1.7 · Telematics3 programs