ShadowTrackr

Supplier Dependency Management

Know who you depend on — and where they answer to

If one of your IT suppliers gets breached, you'll want to know — but not all of them will tell you. And before you can even ask the question, you need to know who your suppliers actually are. ShadowTrackr automatically identifies the suppliers behind your software, hosting providers, certificate authorities, mail providers, and more, purely from what it observes on your external attack surface. That information lives in the suppliers index, where each entry shows the first and last time we detected an asset or service tied to that supplier.

Where your suppliers are actually controlled

Reducing dependency on non-European suppliers is a live priority across Europe right now — driven by NIS2, procurement policy, and broader digital sovereignty concerns — and it's a question most attack surface tools don't even attempt to answer. ShadowTrackr does.

For every supplier we identify, we track where their headquarters and shareholder control are actually located. The result is available directly in the supplier index, in a field called control, classified into four categories:

Sovereign European Focused on maintaining EU-only dependencies throughout the chain.
Fully European No controlling interest from outside the EU.
European Subsidiary Operates in Europe, but with a non-European controlling party.
Non-European Headquarters and control both outside the EU.

This isn't a self-reported label from the supplier — it's determined independently, based on actual ownership and control structure.

The Supplier Dependency Report

The Supplier Dependency Report brings this together in one place: every supplier you depend on, how many of your assets sit with them, and where control of that supplier is located. If reducing your reliance on non-European infrastructure is a goal — as it was for us — this is the report built specifically to support that decision.

Why this matters beyond compliance

Supplier risk isn't just a checkbox for a NIS2 audit. A supplier breach, an unexpected acquisition, or a change in jurisdiction can all materially change your risk exposure without a single asset of yours ever changing. Knowing who you depend on — and where they answer to — is the same kind of attack-surface awareness ShadowTrackr applies everywhere else: continuous, evidence-based, and automatically kept current as your infrastructure changes.

How supplier data connects to the rest of your attack surface

Supplier visibility isn't a separate exercise from asset discovery and vulnerability management — it's built from the same underlying data. Every asset ShadowTrackr discovers and every piece of software it detects feeds into supplier attribution automatically, with no separate inventory to maintain.

Asset Discovery →

See how assets are discovered and attributed in the first place.

Detection Rules →

See how detected software is verified with confidence.

Map your supplier dependencies and their control — automatically.