Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogContact
Test access Book a demo
Integrated risk & third-party risk management

SynapseRM / TPRM

Twelve modules on one data model. A risk enters from a project, an audit or a supplier assessment, and the platform carries it through treatment, formal acceptance and closure — with every change recorded.

Book a demo Request test access

Twelve modules, one data model

KNOW THE ESTATE
CLOSE THE LOOP
SUPPLIERS & CONTROL
360°
Dashboard
360° CISO view across all risk domains
ASSESS
Risk Assessment
Guided, automated per-project assessment
THIRD-PARTY
TPRM
Supplier workflow with tiering and threat mapping
ASSESS
BIA
Asset criticality based on C·I·A·T
PORTAL
Third-Party Portal
Dedicated secure access for your suppliers
TRACK
Audit Reco.
Audit findings tracked through to closure
INVENTORY
Asset Referential
Lightweight CMDB with lifecycle and EOL
REGISTER
Risk Registry
Full lifecycle, identified to accepted or closed
TRACK
Exception Registry
Formal acceptance with expiry tracking
REPORTING
Reporting
Reports scheduled or generated on demand
HIGHLIGHTS
To-Do / My Tasks
Personal assignments, deadlines and alerts
GOVERN
Access
RBAC, MFA and read-only auditor role
Automated risk assessment

Answer the requirement, get the risk

A 5×5 matrix populated live as findings are scored, finding-level analysis from control gap to rated severity, and a per-project PDF report in one click.

Several assessment frameworks supported out of the box
One consistent scale across every analyst and project
Your own scales, fields and workflows if you prefer
Project risk assessment with 5 by 5 matrix
Risk registry with history
Risk registry

Full lifecycle, fully traceable

IDENTIFIED TREATED MITIGATED ACCEPTED / CLOSED
Inherent → residual
The level at identification and today, with the path between them.
Owner and next review
A named owner and a next-status date that drives alerts.
Immutable history
Who changed what and when, exportable as evidence.
Connected registers
Assets, exceptions and audit findings reference the same risk.
Third-party risk management

The risk you inherit from your suppliers

01
Onboarding & tiering
Profile, classification and inherent criticality
02
Automated assessment
Tailored questionnaires, reminders and evidence requests
03
Scoring & gap analysis
Dependency, access, cyber maturity and trust scored into a zone
04
Continuous oversight
Approve, remediate or reassess as the risk evolves
TRUST ZONE
Within appetite, periodic review
WATCH ZONE
Enhanced due diligence and follow-up
DANGER ZONE
Immediate remediation or escalation
Third-party overview with risk zones
Vendor risk scoring

Every register, connected

ASSET REFERENTIAL
Lightweight CMDB
Identity, technical detail, warranty and end-of-life
Asset referential
AUDIT RECOMMENDATIONS
Findings to closure
Overdue tracking and closure rate by audit source
Audit recommendations
BIA
Criticality on C·I·A·T
Your own qualitative level definitions per asset
Business impact assessment
Architecture & security

Two independent stacks, no shared gateway

SYNAPSERM
Frontend
React single-page app
RM backend
Risk engine · project assessment · REST API
Database
PostgreSQL
SYNAPSERM
FETCH & PUSH
NO SHARED
GATEWAY
THIRD-PARTY PORTAL
Frontend
React single-page app
Portal backend
Supplier scoring · workflow · REST API
Database
PostgreSQL

SynapseRM initiates every exchange: it fetches supplier assessment results and pushes back what the portal needs. The portal never calls in, so a compromise on the supplier-facing side does not open a path into the risk platform.

RBAC

Segregation of duties between security, procurement, DPO and management.

MFA

Multi-factor authentication on every account, including supplier access.

Audit trail

Timestamped records of every action, assessment and approval.

Auditor role

A read-only profile so your auditor reads the evidence directly.

Where SynapseRM sits

SPREADSHEETS
Cheap, until the audit

No workflow, no history, no third-party view. Every report is manual.

SYNAPSERM / TPRM
Deep functionality, easy to use

Automated project assessment, full risk lifecycle, TPRM and supplier portal, RBAC and auditor access — configured to your method in weeks.

ENTERPRISE GRC SUITES
Powerful, if you can staff it

Long implementations, heavy licensing and a configuration team you do not have.

Resources

Take the presentation with you

A 16-slide PDF covering the regulatory context (NIS2, DORA, ISO 27001), the twelve modules, the automated project assessment, TPRM and the architecture — ready to share with your team or your committee.

PDF · 16 slides · English
Sent to your screen immediately — we may follow up once by email.
DOWNLOAD THE DECK
Name
Company
Work email

See it on your own scope

Book a demo, or ask for a 30-day test tenant pre-filled with demonstration data.

Book a demo Request test access
Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog
Brussels, Belgium
© 2026 Synapse Consulting
Av. du Martin-Pêcheur 19, 1170 Watermael-Boitsfort