Partner and Vendor Due Diligence

How do you do vendor due diligence from a domain?

You run vendor due diligence from a domain by pulling its tech stack, infrastructure, security grade, and firmographics in one correlated call, then reading the operational tells (TLS expiry, email auth, header grade) that a pitch deck hides. Bassethound returns all five layers together, so a red flag in one layer sits next to context in the others. One keyless call, nothing carried between calls.

Best move: read the operational layers a vendor cannot dress up (TLS expiry, email auth, security headers, the live stack) before you read the pitch.

Why it works: a domain exposes how a company operates, not how it markets. Certs expire on a date, DMARC is present or it is not, and the running stack is whatever the browser loads.

Key takeaways

  • Vendor due diligence from a domain reads operational tells (TLS days remaining, SPF/DKIM/DMARC, security header grade) that a sales page never surfaces.
  • A near-expiry cert plus missing DMARC plus an F header grade points to a thin operations team, each signal a lead rather than a verdict.
  • The AI-readiness layer separates “AI-powered” marketing from a backend that loads model SDKs and vector stores.
  • A domain scan is the first pass, not the whole review. It cannot see financials, contracts, or controls behind the edge, and Bassethound reports those gaps.
  • One keyless call returns five correlated layers, so an agent can sweep an entire vendor list and rank by security grade and icp_signal.

What does a domain tell you about a vendor’s operational health?

The infrastructure and security layers carry the tells. Start with the TLS certificate: issuer, expiry, and days_remaining. A cert with eight days left is not a crisis, but paired with other signals it reads as a team running close to the edge. Next, the email-auth booleans. SPF, DKIM, and DMARC are each present or absent, and a missing DMARC record means the vendor’s domain is spoofable, which matters if you are about to trust their invoices or their support email.

Then the security header grade, A through F. It scores HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. These headers are cheap to set and free to check, so their absence tells you about priorities, not budget. The infrastructure layer also names the hosting org, ASN, CDN, nameservers, and MX provider, which confirms whether a vendor runs on serious infrastructure or a shared host. None of this is a verdict on its own. Together, in one dossier, the pattern is the point: an F grade next to an expiring cert next to no DMARC is a coherent story about how the company operates.

How do you separate a vendor’s claims from what they run?

Two layers do this work. The tech stack layer detects frameworks, CMS, analytics, payments, and ecommerce, each with a category, version, confidence, and the evidence behind the match. That tells you whether the stack is current or frozen. The AI-readiness layer goes deeper, and it is where marketing and reality split hardest.

Every vendor deck in 2026 says “AI-powered.” The AI-readiness layer ignores the copy and fingerprints the backend: model providers (Anthropic, OpenAI, Gemini), AI SDKs, orchestration frameworks, vector stores, and LLM observability. It returns a score out of six and a verdict of shipping, experimenting, or none. A vendor that leads with AI and scores none is a gap you get to name in the call. A vendor that scores shipping, with a vector store and a model SDK detected, has receipts.

Be honest about the limit. A static crawl plus optional JS render can miss components that live fully server-side or sit behind a proxy. The dossier records how it detected each signal and flags what it could not reach, so you weight a confident match above a maybe.

Which domain signals are red flags in vendor due diligence?

Rank them by how cheap they are to fix, because an unfixed cheap problem is the loudest signal. An expired or near-expiry TLS certificate tops the list, since renewal is automated for most shops and letting it lapse means nobody is watching. A missing DMARC record is next, because it leaves the domain open to spoofing and shows a gap in email hygiene. A security header grade of D or F means no CSP and no HSTS, which is a five-minute config left undone.

Beyond the security layer, watch for an abandoned or end-of-life framework in the tech stack, which suggests deferred maintenance. Watch for firmographics that do not line up: a company name, vertical, or contact set in the structured data that contradicts what the vendor told you. The top-level summary fuses all of this into an icp_signal of hot, warm, or cold, which for due diligence you read inverted. Cold is your caution flag.

Treat each as a lead, not a conviction. A single red flag opens a question. Three that agree close it.

What can a domain scan not tell you?

Plenty, and pretending otherwise is how due diligence goes wrong. A domain cannot show you a vendor’s financials, ownership structure, customer contracts, SLAs, data residency, or their list of subprocessors. It cannot verify a SOC 2 report or confirm the security controls that sit behind the edge. What you see is the public surface and the operational hygiene around it.

There are technical blind spots too. A static crawl plus optional JS render misses stacks that never reach the browser: fully server-side rendering, backend services with no client footprint, and components routed through a reverse proxy. Bassethound reports these gaps rather than papering over them, so a layer that returns thin evidence reads as “could not reach,” not “nothing there.”

Use the scan for what it is good at: a fast, repeatable first pass that tells you where to spend expensive diligence. It ranks a vendor list, surfaces the operational red flags, and confirms whether the AI story is real. Then you send the security questionnaire, request the SOC 2, and read the contract. The domain narrows the field. It does not sign the deal.

How do you run due diligence across a whole vendor list?

Because the tool is stateless and keyless, scale is a loop, not a project. Each call to sniff_domain(domain, profile) is self-contained, so an agent iterates your vendor list one domain at a time with no session to manage and no key to rotate. There is no bring-your-own-key step, because Bassethound owns the crawl and carries nothing from one request to the next.

Pick the profile by depth. Run fast (deterministic, one to three seconds) for a quick sweep across dozens of domains when you want the stack and infrastructure signal. Run deep when a vendor makes the shortlist: it adds the security grade, follow-on probes, and Wayback first-seen history. That first-seen date is its own diligence signal, since a domain registered two weeks ago that claims enterprise scale deserves a second look.

The agent ranks the results by security_grade and icp_signal, and you read the tail first. The cold, low-grade domains are where you spend your questions. Because the endpoint is a remote MCP server at mcp.bassethound.ai/mcp, this runs inside whatever agent host you already use (Claude, Cursor, ChatGPT), so the sweep lives next to the rest of your evaluation work instead of in a separate tool.

Bassethound perspective

The diligence tools you already pay for each own one layer. Censys and Shodan see infrastructure. Apollo and ZoomInfo see firmographics. BuiltWith sees the tech stack. To assemble a vendor picture you run three logins, export three files, and correlate them by hand in a spreadsheet, a step teams skip under deadline. The correlation is the work, and none of them do it for you.

A competitor would dispute this: for vendor due diligence, fusion beats fan-out, and you cannot cheaply reconstruct that fusion from five separate tools. A near-expiry cert means little alone. Next to a missing DMARC record, an F header grade, and an AI-readiness verdict of none against a homepage that shouts “AI-powered,” it becomes a coherent read on how a company operates. That correlation is the product.

We are also honest about the edge. A domain scan is the first pass, not the SOC 2. It tells you where to dig, ranks the list, and reports what it could not reach. Bassethound reads the vendor’s operations, not their pitch.

Sources

Frequently asked questions

Can a domain scan replace a security questionnaire?

No. It replaces the first pass. A domain gives you the operational tells (TLS expiry, DMARC, header grade, live stack) that tell you where to dig. It cannot see SOC 2 controls, subprocessors, or data residency behind the edge, and the dossier says so.

What is the fastest way to flag a risky vendor from their URL?

Check the security layer and TLS expiry first. An F header grade plus a cert with days remaining in single digits plus no DMARC is a stretched operations team. Bassethound returns all three in the security and infrastructure layers of one call.

Does the AI-readiness layer help vendor due diligence?

Yes, when the vendor sells AI. The layer fingerprints the backend (model providers, SDKs, vector stores) and returns a verdict of shipping, experimenting, or none. A vendor that claims AI and scores none is a claims-versus-reality gap worth naming.

Can you due-diligence a list of vendors at once?

Yes. The tool is stateless and keyless, so an agent loops your list, one sniff_domain call per domain, and ranks by icp_signal and security_grade. No key management, and nothing carried from one call to the next.

What can a domain scan miss?

Fully server-side or proxied components. A static crawl plus optional JS render cannot see a stack that never reaches the browser or that hides behind a reverse proxy. The dossier reports what it could not reach rather than guessing.

Sniff a domain.

Run sniff_domain on any site and read its five-layer dossier in one call.

Sniff a domain