Vendor Due Diligence
Know a vendor's public posture in 30 seconds.
Passive checks only: public headers, pages, signals — one Battle Card, read before you sign.
7 signal classes0 intrusive requests
+ CONSOLE / 01 TARGET
STANDBY
LAST SCAN ——:——:——
Type a vendor name — or speak it if you're on a device with a mic. Then press stop.
Transient processing · 24h cache · audio never retained.
PIPELINE / 05 STAGES
no target
stages 02–03 share one passive request · /api/scout
01Resolve
Pending
—
02Fetch / Headers
Pending
—
03Crawl
Pending
—
04Analyze
Pending
—
05Battle Card
Pending
—
CARD / 01 REPORT
—
—
Cached
—
—
Talon Scout Score
higher = stronger public posture
Findings
Tech Stack
Exposure
Vendor Risk
Actions
Passive analysis only. No exploitation. No penetration testing.
Need the deep four-domain audit? Talon Audit goes deeper — with authorization, where it belongs.
Talon Audit →
Demo Card Mode
Offline / cached — no backend required
Cached = real scan snapshots. Synthetic = generated layout demo, no real vendor.
What a buyer should ask before signing
VENDOR RISK / 02 QUESTIONSThe summary answers
Public posture vs. procurement checklist — written for the signer.
Typical open questions
- Current SOC 2 report or equivalent — who audits it?
- Where is data hosted, and who are the subprocessors?
- What is the breach-notification SLA, in writing?
- Which cookie flags and headers can you verify today?
How Talon Scout works
REF / 04 STAGESOne passive pass, one analysis pass, one card.
01
Speak it
Voice via your device mic (optional), or type the domain.
02
Scout it
One passive fetch of public signals.
03
Analyze it
DeepSeek scores the card, schema-validated.
04
Battle Card
Score, findings, actions — exportable markdown.
Honest partner line: Speech: device mic (Web Speech) · Pages: Firecrawl (Apify fallback) ·
Analysis: DeepSeek · Cache: Workers KV, 24h. Everything else: one Cloudflare
Worker and this page.