Deciding whether a new technology vendor is worth onboarding, and keeping the ones you already work with on track, are two different jobs — Granur treats them that way. A weighted evaluation and mandatory gates keep a first-timer honest; health scorecards, obligations, certifications, and a portfolio view by spend and risk keep the rest of your vendor base accounted for — every vendor in one searchable directory, not a spreadsheet someone updates when they remember to.
Not a folder of contracts — the vendor itself, as its own record. Every relationship your org has is searchable and filterable by capability, segment, and health, with every contract tied to that vendor rolled up underneath it.
Click into any vendor and see its full history in one place — every contract, every health check, every certification — instead of piecing it together from separate records.
A brand-new vendor and a routine renewal are not the same risk. Granur treats them differently by design — a first-time vendor gets a weighted evaluation across eight dimensions (strategic fit, capability, architecture, data, security, performance, commercial, and vendor model), plus mandatory pass/fail gates and a strategic-risk read on ecosystem fit and exit cost, the moment it's flagged "new" at intake; a renewal doesn't, because that relationship has already been vetted.
Evaluation scorecard, Vendor Risk Assessment, and privacy / AI diligence all apply — the relationship is unproven, so the gates run in full.
No evaluation scorecard and no re-run of diligence already on file. The focus shifts to negotiation — terms, pricing, and renewal timing.
Weighted rubric for onboarding a new vendor — separate from the VRA / compliance gates.
Every vendor placed by spend against risk on a single map — so the ones worth prioritizing surface on their own, instead of waiting to be found in a one-vendor-at-a-time lookup. Spend uses the same normalization as the Spend page; risk reuses each vendor's highest per-contract risk score from the risk badge.
Vendors land in one of four quadrants — strategic, bottleneck, leverage, or routine — so a portfolio review starts with "who needs attention" instead of a spreadsheet of every vendor in alphabetical order.
A segmentation map tells you where to look. These are what you're actually looking at once you get there.
A weighted KPI rubric — quality, delivery, cost, service, innovation, communication — run periodically per vendor, with an auto-suggested health rating and an action-item list, so "how's this vendor doing" has an actual record behind it.
The actual deliverables a vendor relationship promises — a report due quarterly, a right to audit, a volume commitment — tracked against an owner and a due date, separately from when any one contract with that vendor expires.
COI, SOC 2, ISO 27001, W-9, and anything else a vendor needs on file — tracked with expiry dates and an automatic amber-then-red warning as a certification approaches or passes expiration.
A five-step checklist — access revoked, data returned, final invoice, knowledge transfer, contracts closed — so winding down a vendor relationship is a record, not a memory.
Vendor management is half the picture. See the dashboard where every contract is tracked, stage by stage
Granur is early — we're straightforward about what's built today rather than borrowing badges we haven't earned.
Every contract, user, and event is scoped to your organization — no cross-tenant access.
Passwords are hashed, never stored in plain text; sessions are signed and short-lived.
Every stage move, approval, and settings change is logged automatically — visible on the Timeline, and exportable as a CSV or PDF for a security reviewer.
Your vendor data lives in your own database — Granur doesn't share it across organizations.
Pick a plan, upload a handful of agreements, and watch the evaluation scorecard and health tracking fill in.