"Birtu is derived from the Aramaic word birta — meaning fortress. That is what we build around your vendor relationships."

Features

Every tool your team needs to manage vendor risk.

Six integrated modules covering the full TPRM lifecycle — from vendor discovery to incident resolution.

Vendor Registry

A single source of truth for every third-party relationship your agency manages. Import from CSV or build manually. Risk-tier each vendor and track their compliance posture over time.

Risk tiering — Critical, High, Medium, Low

Bulk CSV import for existing vendor lists

Vendor profiles with contact and contract details

Search, filter, and sort across full portfolio

Vendor Risk Tier
Acme Data Solutions Critical
CloudBridge Inc. High
NetSec Partners LLC High
Statewide Print Co. Low
Ohio IT Services Medium
Assessment — Acme Data Solutions
NIST 800-53 — AC-1
Does vendor maintain a formal access control policy?
Compliant
NIST 800-53 — AU-2
Does vendor perform event logging on all systems?
Partial
CMMC — MP.3.122
Sanitize or destroy system media before disposal?
Non-Compliant

Risk Assessments

Structured assessment workflows built around NIST 800-53, CMMC, and StateRAMP. Assign assessments to vendors, track completion status, collect evidence, and generate scores — all in one place.

Framework-mapped questionnaires ready to use

Compliant / Partial / Non-Compliant scoring

Evidence upload and retention per control

Assessment history tracked per vendor

Incident Management

Log vendor-linked security incidents with severity classification, SLA deadlines, ownership assignment, and full status tracking. Open → In Progress → Resolved → Closed. Nothing stalls unmanaged.

Alerts System

Severity-based alerts tied to vendor events — risk score changes, certification expiry, overdue assessments. Configurable thresholds. Your team stays ahead of risk instead of chasing it.

Document Management

Centralized repository for compliance documents, SOC 2 reports, CMMC certificates, and contracts — all linked to the relevant vendor. Expiry tracking and version history included.

Reporting & Dashboards

Executive dashboards showing portfolio risk distribution, assessment completion rates, and incident trends. Export PDF reports for leadership reviews, auditors, and oversight committees.

Compliance Coverage

Built around the frameworks that matter to government.

Every assessment in Birtu maps to real compliance requirements — so the evidence you collect serves double duty: risk management and audit readiness.

NIST SP 800-53

Security and Privacy Controls for Information Systems. The federal standard baseline for third-party risk assessment. Birtu maps vendor questionnaires to control families including AC, AU, CA, CM, and SC.

Used by all federal agencies and most state governments

CMMC

Cybersecurity Maturity Model Certification. Required for DoD contractors and increasingly adopted by state-level defence and critical infrastructure programmes. Birtu covers Levels 1 through 3 assessment domains.

Mandatory for DoD supply chain

StateRAMP

The state-government equivalent of FedRAMP. StateRAMP authorization is becoming a procurement requirement for SaaS vendors selling to state agencies. Birtu helps agencies track which vendors have authorized status.

Adopted by 20+ US states and growing
Architecture

Multi-tenant. Isolated. Secure by design.

Every agency on Birtu operates in a fully isolated data environment. No cross-tenant data access is possible at the database level. Row-level security enforced on every query.

PostgreSQL with row-level security

Every database query is scoped to the authenticated tenant. Isolation is enforced at the data layer, not just the application layer.

Role-based access control

Three roles with strict permission boundaries. Super Admin, Agency Admin, and Analyst — each scoped to exactly what they need.

Vetted onboarding flow

All new agency accounts go through a Corvenium approval gate before access is granted. No self-serve open signup.

Audit trail on all actions

Every create, update, and delete is logged with timestamp and user identity. Full activity history for compliance reviews.

Technology Stack
Frontend React 18 + TypeScript
Styling Tailwind CSS + shadcn
Database Supabase PostgreSQL
Auth Supabase Auth + RLS
State TanStack Query
Build Vite
Ready to Start

See Birtu running against your actual vendor landscape.

A 30-minute demo. No pitch deck. We walk through your real vendors, your real compliance requirements, and show you exactly how Birtu handles them.