Support

FAQ

Everything you need to know about TERTIQ, supplier risk assessments, security evidence and billing.

TERTIQ is a third-party cybersecurity risk management platform that helps organizations assess suppliers, collect security evidence, identify control gaps, track remediation and maintain an auditable supplier-risk program from one workspace.

TERTIQ is designed for organizations managing third-party and supplier cybersecurity risk, including internal security teams, compliance teams, vCISOs, MSPs and consultants working with regulated or security-conscious businesses.

TERTIQ uses a deterministic seven-factor inherent-risk model covering operational criticality, data sensitivity, system access, business dependency, substitutability, subprocessors and regulatory or geographic exposure. The resulting score determines the supplier's risk level and recommended assessment depth.

Suppliers are assigned an assessment tier based on their inherent risk. Assessments use structured YES, PARTIAL, NO and N/A responses across areas such as governance, identity and access, data protection, vulnerability management, incident response, business continuity and supply-chain security.

TERTIQ includes supplier-security controls and workflows designed to be NIS2-aligned and useful for third-party risk management. TERTIQ does not claim to guarantee NIS2 compliance, certification or legal conformity. Organizations remain responsible for determining their own regulatory obligations.

No. TERTIQ's core supplier-risk scoring is deterministic and explainable. Scores are derived from defined risk factors, assessment responses, evidence and findings rather than opaque AI-generated risk scores.

Teams can attach supporting evidence to supplier assessments, including security reports, policies, certifications and other documents used to validate supplier controls. Evidence is stored privately and remains associated with the relevant supplier and assessment records.

Assessment and evidence gaps can generate Findings. Findings can then be assigned remediation actions, owners, deadlines and progress states, giving teams a structured path from identifying risk to resolving it.

Yes. TERTIQ includes risk reporting, CSV exports and an executive Board Summary designed to give stakeholders a concise view of supplier risk, findings, remediation and overall third-party risk posture.

Starter. Supports up to 20 suppliers and 5 active team members while providing the core TERTIQ workflow.

Business. Supports up to 100 suppliers, unlimited team members and the complete TERTIQ workflow with expanded reporting and capacity.

Yes. Paid customers can manage their subscription through TERTIQ's Billing & Plan area and the Stripe-hosted customer portal. Cancellation is configured to take effect at the end of the paid billing period.

No. TERTIQ does not have a free commercial plan. The public Live Demo can be explored without modifying real data, while Starter and Business are paid subscription plans.

Yes. The public Live Demo contains realistic sample suppliers, assessments, evidence, findings, remediation and reviews so prospects can explore the workflow without creating or modifying production data.

Yes. TERTIQ is organization-scoped. Supplier, assessment, evidence and related risk records are associated with the authenticated workspace, and authorization checks are enforced server-side.

Consultant / Custom is intended for organizations or consultancies that require capacity or deployment needs beyond the standard Starter and Business plans. It is handled through direct contact rather than automated Stripe checkout.

Still have questions?

Explore the live demo or contact us to see how TERTIQ can fit your supplier-risk workflow.