
Panorays
Third-party cyber risk and attack surface management, powered by native AI
By Panorays · HQ New York, United States · 4.0/5 Value-Position score (estimate)
Positioning guardrails
Best for
- Security and risk teams that must tier, assess and continuously monitor hundreds or thousands of third parties.
- CISOs who want externally verifiable cyber posture ratings merged with questionnaire-based controls in one risk rating.
- Organizations with supply-chain compliance drivers such as DORA or SIG reporting.
- Teams that need automated remediation tasks and in-platform collaboration with their vendors.
Ideal size: Dedicated security/risk team of 5+ people · Scale-up or enterprise running a formal third-party risk program
Not for
- Small companies with a handful of vendors and no formal third-party risk program.
- Buyers who want published self-serve pricing and online signup rather than a custom quote.
- Vendors looking for cheap tooling to answer their customers' security questionnaires.
- Companies seeking a full internal GRC or IT compliance suite rather than third-party cyber risk.
Value metrics scorecard
Time-to-Value
About 2-4 weeks
~30 days to first production value
Total Cost of Ownership
$50,000/yr
Starts at $15,000 · Quote-based annual subscription; bundles built from inventory, assessment and monitoring evaluation types tailored to the customer's risk strategy.
Implementation Friction
3/5
Engineering + admin effort required
Value-Position score
out of 5 · model estimate
Full cost breakdown
Mandatory implementation fee
None
Seat tiers
No published seat tiers; scope is set by number of third parties and evaluation types
Add-on costs
- DORA support (register of information export, DORA questionnaire templates, pre-evaluation review) is an add-on on assessment and monitoring plans
Company & support
Who is behind Panorays, and how your team gets help once it is live.
Company
- Founded
- 2016 · 10 yrs in business
- Headquarters
- New York, United States
How you get support
- PhoneNot listed
- EmailPlan not stated
- Live chatNot listed
- Support portal / ticketsNot listed
- Community forumNot listed
- Help centre / docsNot listed
- Dedicated account managerNot listed
- In person / on-siteNot listed
- Hours
- Not recorded
- Response time
- Not stated
Support contact [email protected] is published on the security page. No plan tiers, support hours or response-time SLA are stated.
“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.
Market position
Where Panorays sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.
Quadrant view
Typical annual cost × Time-to-value
The lines cross at the median of the solutions shown, so about half sit on each side of each line.
Companies on the chart 6 / 10
- Panorays
- Black Kite
- Napier AI
- Chainalysis
- Cypago
- AgentSync
Add or change companies
Up to 10 companies including Panorays. Listed closest first.
Stack fit signal
Compatibility with standard B2B ecosystems.
No supported MCP path today, so it cannot be driven from an AI client.
AI & MCP readiness
What Panorays ships in AI, and what it asks of your ecosystem.
AI features shipped
Vendor describes native AI for risk ratings, AI-powered questionnaires, nth-party discovery and AI classification of cyber news under continuous monitoring. It states its AI management system is certified to ISO/IEC 42001. Model sourcing, customer-data training and AI-specific action logging are not described.
Your data & models
- Trains on your data
- Not recorded — ask the vendor
- Runs on
- Not recorded
- AI pricing
- Not recorded
In your ecosystem
- AI connection
- Not supported
- Model key
- Not recorded
- AI usage audit
- Not recorded
Compliance attestations
* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.
Bottom line
Panorays is a third-party cyber risk management platform that merges AI-powered questionnaires, external attack surface assessment, inherent risk and continuous monitoring into a single vendor risk rating. It maps third- to nth-party dependencies, automates remediation tasks and hosts vendor collaboration in-platform. Framework support includes DORA and SIG. Pricing is quote-based, scoped to assessment types and vendor volume. The company states SOC 2 Type II, ISO/IEC 27001:2022 and ISO/IEC 42001:2023 certification.
Frequently asked questions
How is Panorays priced?
Panorays does not publish list prices. Pricing is quote-based and depends on your risk strategy, the number of third parties and which evaluation types you need (inventory, assessment, monitoring). DORA support is sold as an add-on on assessment and monitoring plans, and you build a bundle by mixing evaluation types.
What certifications and security controls does Panorays hold?
The vendor states it is certified to SOC 2 Type II, ISO/IEC 27001:2022 and ISO/IEC 42001:2023 (AI management systems). Data is hosted on Google Cloud Platform, encrypted at rest and in transit, and access is controlled with SSO/SAML 2.0, MFA and role-based access control. Annual third-party penetration tests are performed.
How long does it take to get value?
Panorays does not publish an implementation timeline. Onboarding is guided by the vendor and the platform supports bulk upload and API upload of supplier inventories, plus portfolios and tags for tiering. Panorays claims an 80% reduction in vendor onboarding time and 98% third-party response rates.
Does Panorays use AI, and how is it governed?
Yes. Panorays describes native AI for risk ratings, AI-powered questionnaires, discovery of third-, fourth- and nth-party relationships, and AI classification of daily cyber news. It says it is the first TPCRM platform operating under a formal AI governance framework certified to ISO/IEC 42001. The vendor does not state which model providers it uses or whether customer data trains models.
Which regulations and frameworks does Panorays support?
The platform supports DORA with a register of information export, DORA questionnaire templates and pre-evaluation review, and it supports SIG questionnaire templates and uploads. Approval management and automated reevaluation help demonstrate continuous compliance, and auto-discovery surfaces self-attested vendor certifications such as SOC 2 and FedRAMP.
How do I get support?
Panorays publishes a support email address, [email protected], for customer questions, and a dedicated [email protected] address for vulnerability reports. No support plan tiers, support hours or response-time SLA are published, so those terms need to be confirmed during contracting.