1(globalThis.TURBOPACK||(globalThis.TURBOPACK=[])).push(["object"==typeof document?document.currentScript:void 0,291726,362028,252080,e=>{"use strict";var t=e.i(83790);let i={name:"menu",size:24,node:[["path",{d:"M4 5h16",key:"1tepv9"}],["path",{d:"M4 12h16",key:"1lakjw"}],["path",{d:"M4 19h16",key:"1djgab"}]]};i.node;let r=(0,t.default)(i);e.s(["Menu",0,r],291726);var n=e.i(727448),a=e.i(992150),o=e.i(709948),s=e.i(778841),c=e.i(7667),l=e.i(302056);let d={"financial-institutions":{slug:"for-financial-institutions",navTitle:"Financial Institutions",navDescription:"Procurement and third-party risk for banks of every size",metaTitle:"Vendor risk management for financial institutions",metaDescription:"Coverbase runs vendor risk management for financial institutions, mapped to interagency guidance with exam-ready evidence built in. Book a demo.",hero:{label:"Guides for Financial Institutions",title:"Coverbase gives banks, credit unions, and financial institutions one system to run procurement and third-party risk.",subtitle:"Intake, due diligence, and ongoing monitoring stop living in spreadsheets and email threads. Coverbase orchestrates them end to end, with the audit trail examiners expect built in from the start."},why:{title:"Why financial institutions run on Coverbase",features:[{title:"AI-native risk orchestration",description:"Automate intake, assessments, and contract reviews with workflows mapped to your policies, your control sets, and the frameworks examiners hold you to."},{title:"Built around interagency guidance",description:"Line planning, due diligence, and monitoring up with the 2023 Interagency Guidance on third-party relationships, so your process matches what the OCC, FDIC, and Fed look for."},{title:"Faster procurement, fewer gaps",description:"Cut cycle times from supplier request to signed contract while keeping every approval, exception, and control inside one record."},{title:"Continuous oversight",description:"Track suppliers across financial, security, compliance, and reputational risk in real time, and catch problems before they reach an exam."},{title:"Audit-ready by design",description:"Every action, document, and approval is captured and traceable, so prepping for an exam means pulling a report, not rebuilding history."}]},helps:{label:"How Coverbase helps",title:"Run vendor risk the way examiners expect",subtitle:"Banks rarely fail exams for lack of policy. They fail because the evidence is scattered. Coverbase keeps the work and the proof in one place.",features:[{icon:"/icon-images/shield.png",title:"Exam-ready evidence",description:"Pull a complete, time-stamped record of diligence and monitoring for any vendor on demand."},{icon:"/icon-images/data.png",title:"Connects to core systems",description:"Integrate with core banking, ERP, and GRC tools without ripping out what already works."},{icon:"/icon-images/radar.png",title:"Concentration and nth-party visibility",description:"See where you are concentrated and which fourth parties sit behind your critical vendors."},{icon:"/icon-images/gear.png",title:"Controls that match your policy",description:"Configure assessments around your own control library, not a generic template."}]}},"community-banks":{slug:"for-community-banks",navTitle:"Community Banks",navDescription:"Big-bank vendor management without the big-bank team",metaTitle:"Community bank vendor management platform | Coverbase",metaDescription:"Coverbase gives community banks examiner-ready vendor management under the 2023 Interagency Guidance, without adding headcount. Book a demo.",hero:{label:"Guides for Community Banks",title:"Community banks get held to big-bank standards. Coverbase gives you big-bank vendor management without the big-bank team.",subtitle:"Examiners don't grade on a curve for headcount. Coverbase does the legwork on intake, diligence, and monitoring so a lean team can manage a full vendor portfolio without falling behind."},why:{title:"Why community banks choose Coverbase",features:[{title:"Examiner expectations, met with a small team",description:"The 2023 Interagency Guidance applies whether you have three risk staff or three hundred. Coverbase covers the work the headcount can't."},{title:"Fintech partnerships, handled",description:"Onboard and monitor fintech and BaaS partners with the same rigor you apply to core providers, including the vendors behind them."},{title:"No questionnaire busywork",description:"Coverbase pulls SOC 2s, financials, and public filings automatically, so you review findings instead of chasing PDFs."},{title:"One source of truth",description:"Replace the shared drive and the spreadsheet tracker with one record every examiner and auditor can follow."},{title:"Live in weeks",description:"Stand up a defensible program without a six-month implementation or a new hire to run it."}]},helps:{label:"How Coverbase helps",title:"A vendor program that scales down, not just up",subtitle:"Most TPRM tools assume a dedicated team to feed them. Coverbase is built to do the feeding.",features:[{icon:"/icon-images/agent.png",title:"Does the diligence for you",description:"AI gathers evidence, reads it, and drafts the assessment so your team reviews a finished file."},{icon:"/icon-images/report.png",title:"Board and committee reporting",description:"Generate the vendor risk reporting your board and exam prep already require, on a schedule."},{icon:"/icon-images/alert.png",title:"Renewals and reviews on time",description:"Automatic reminders for reassessments, SOC report refreshes, and contract renewals so nothing lapses."},{icon:"/icon-images/check.png",title:"Right-sized diligence",description:"Tier vendors by risk and skip the deep dive on the low-risk ones, automatically."}]}},"regional-banks":{slug:"for-regional-banks",navTitle:"Regional Banks",navDescription:"Keep vendor risk under control as the portfolio scales",metaTitle:"Regional bank vendor management | Coverbase",metaDescription:"Coverbase gives regional banks vendor management across business lines, states, and regulators, with a defensible record at exam time. Book a demo.",hero:{label:"Guides for Regional Banks",title:"Regional banks outgrow spreadsheets fast. Coverbase keeps vendor risk under control as the portfolio scales.",subt
1itle:"More vendors, more states, more regulators, more scrutiny. Coverbase orchestrates the whole third-party lifecycle so growth doesn't outrun your controls."},why:{title:"Why regional banks choose Coverbase",features:[{title:"Built to scale",description:"Manage hundreds of vendors across business lines without adding a headcount for every hundred."},{title:"Multi-regulator ready",description:"Keep diligence aligned across state and federal regulators with one consistent process and audit trail."},{title:"M&A integration",description:"Fold an acquired bank's vendor book into your program quickly, with full visibility into overlap and concentration."},{title:"Consistent controls across lines",description:"Enforce the same diligence standard whether the request comes from retail, commercial, or treasury."},{title:"Defensible at exam time",description:"Hand examiners a complete record instead of reconstructing it across teams and tools."}]},helps:{label:"How Coverbase helps",title:"Control without slowing the business down",subtitle:"Growth creates vendor sprawl. Coverbase gives risk teams leverage so they stay ahead of it instead of chasing it.",features:[{icon:"/icon-images/layers.png",title:"Portfolio-wide visibility",description:"See every vendor, tier, and open finding across the institution in one view."},{icon:"/icon-images/radar.png",title:"Concentration risk surfaced",description:"Spot where critical services depend on the same few providers before a regulator does."},{icon:"/icon-images/cycle.png",title:"Continuous monitoring",description:"Security, financial, and compliance signals refresh automatically, not once a year."},{icon:"/icon-images/gear.png",title:"Workflows per business line",description:"Configure intake and approval logic for each line without engineering."}]}},"credit-unions":{slug:"for-credit-unions",navTitle:"Credit Unions",navDescription:"Protect member data and satisfy the NCUA",metaTitle:"Credit union vendor management, NCUA-aligned | Coverbase",metaDescription:"Coverbase maps credit union vendor management to NCUA expectations, tracking member data flows and CUSO oversight with examiner-ready reporting. Book a demo.",hero:{label:"Guides for Credit Unions",title:"Credit unions answer to the NCUA and to their members. Coverbase helps you protect both.",subtitle:"Member data and member trust are the whole business. Coverbase runs vendor due diligence and monitoring so third parties never become the weak link."},why:{title:"Why credit unions choose Coverbase",features:[{title:"NCUA-aligned diligence",description:"Map vendor management to NCUA expectations and document it the way examiners want to see it."},{title:"Member data, protected",description:"Track how every vendor and CUSO touches member data, and where that data goes next."},{title:"More coverage, same budget",description:"Automate the evidence gathering so a small team covers a growing vendor list without growing the team."},{title:"Fintech and CUSO oversight",description:"Vet and monitor fintech partners and CUSOs with the rigor their access deserves."},{title:"One defensible record",description:"Replace scattered files with a single, time-stamped history for every third party."}]},helps:{label:"How Coverbase helps",title:"Vendor management that fits a member-owned model",subtitle:"You're stewarding members' money, not chasing margin. Coverbase keeps diligence thorough without making it a cost center.",features:[{icon:"/icon-images/shield.png",title:"Member data mapped",description:"Know which vendors handle member PII and confirm their controls hold up."},{icon:"/icon-images/agent.png",title:"Evidence gathered automatically",description:"SOC reports, financials, and filings collected and read for you."},{icon:"/icon-images/report.png",title:"Examiner-ready reporting",description:"Produce the vendor risk reporting NCUA exams expect, on demand."},{icon:"/icon-images/alert.png",title:"Nothing slips",description:"Automated reassessment and renewal reminders keep the program current."}]}},"sponsor-banks":{slug:"for-sponsor-banks",navTitle:"Sponsor Banks",navDescription:"Program-level oversight and nth-party visibility for BaaS",metaTitle:"Sponsor bank third party risk oversight | Coverbase",metaDescription:"Sponsor bank third party risk oversight covers every fintech program and the vendors behind it, with nth-party visibility built in. Book a demo.",hero:{label:"Guides for Sponsor Banks",title:"Sponsor banks own the risk of every fintech program and every vend
1or behind it. Coverbase makes that risk visible.",subtitle:"When you sponsor a fintech, you inherit its third parties too. Coverbase gives you program-level oversight and the nth-party visibility regulators now demand from BaaS."},why:{title:"Why sponsor banks choose Coverbase",features:[{title:"Program-level oversight",description:"Monitor each fintech program and the vendors inside it from one place, not a stack of partner spreadsheets."},{title:"Nth-party visibility",description:"See the fourth and fifth parties sitting behind your fintech partners, where the real concentration risk hides."},{title:"Built for BaaS scrutiny",description:"Stand up the documentation and monitoring regulators expect from sponsor banks, given the recent wave of consent orders."},{title:"Partner due diligence at scale",description:"Assess and re-assess fintech partners on a consistent schedule without manual chasing."},{title:"Evidence for every program",description:"Keep a complete, exam-ready record for each sponsorship relationship."}]},helps:{label:"How Coverbase helps",title:"Oversight that keeps pace with your programs",subtitle:"BaaS moves fast and regulators are watching. Coverbase gives compliance the visibility to stay in front of both.",features:[{icon:"/icon-images/layers.png",title:"Per-program risk views",description:"Roll risk up by program or drill into a single partner's vendors."},{icon:"/icon-images/radar.png",title:"Fourth-party monitoring",description:"Continuously watch the vendors your partners depend on."},{icon:"/icon-images/control.png",title:"Consistent partner standards",description:"Hold every fintech to the same diligence bar, automatically."},{icon:"/icon-images/report.png",title:"Regulator-ready packages",description:"Generate documentation for each program when examiners ask."}]}},"asset-managers":{slug:"for-asset-managers",navTitle:"Asset Managers",navDescription:"Operational due diligence across every service provider",metaTitle:"Asset manager vendor due diligence | Coverbase",metaDescription:"Run asset manager vendor due diligence on administrators, custodians, and data providers, with SOC 1 and SOC 2 exceptions flagged automatically. Book a demo.",hero:{label:"Guides for Asset Managers",title:"Asset managers depend on data providers, administrators, and custodians. Coverbase keeps that web of vendors in check.",subtitle:"Outsourcing is everywhere in asset management, and so is the SEC's attention to it. Coverbase runs operational due diligence and ongoing monitoring across every service provider."},why:{title:"Why asset managers choose Coverbase",features:[{title:"Operational due diligence, structured",description:"Run consistent ODD on administrators, custodians, market data, and tech vendors instead of one-off reviews."},{title:"SEC outsourcing expectations",description:"Document oversight of service providers the way the SEC's focus on outsourcing expects."},{title:"SOC reports, read for you",description:"Coverbase ingests SOC 1 and SOC 2 reports, flags exceptions, and tracks bridge letters automatically."},{title:"Critical provider monitoring",description:"Watch the financial and operational health of the providers your funds can't run without."},{title:"One record across funds",description:"Keep diligence consistent and traceable across strategies, entities, and mandates."}]},helps:{label:"How Coverbase helps",title:"Diligence built for an outsourced operating model",subtitle:"Your edge is investing, not chasing vendor paperwork. Coverbase handles the oversight that comes with relying on third parties.",features:[{icon:"/icon-images/report.png",title:"SOC report intelligence",description:"Exceptions, scope gaps, and complementary user controls surfaced automatically."},{icon:"/icon-images/chart.png",title:"Provider financial health",description:"Monitor the stability of administrators and custodians continuously."},{icon:"/icon-images/search.png",title:"Consistent ODD",description:"Apply the same diligence framework to every provider, every review cycle."},{icon:"/icon-images/shield.png",title:"Data and access mapped",de
1scription:"Know which providers touch portfolio and investor data, and how."}]}},insurance:{slug:"for-insurance",navTitle:"Insurance",navDescription:"Vendor oversight for carriers, to NAIC standards",metaTitle:"Vendor risk management for insurance carriers | Coverbase",metaDescription:"Coverbase brings vendor risk management to insurers overseeing data aggregators, claims vendors, and TPAs, aligned to NAIC standards. Book a demo.",hero:{label:"Guides for Insurance Carriers",title:"Carriers depend on data aggregators, claims vendors, and TPAs. Coverbase keeps that ecosystem in line.",subtitle:"Third parties touch underwriting, claims, and policyholder data at every step. Coverbase brings carriers, from regional mutuals to national names like Nationwide, disciplined vendor oversight that holds up to state regulators and the NAIC."},why:{title:"Why insurers choose Coverbase",features:[{title:"NAIC and state-regulator aligned",description:"Document vendor oversight to the standards state insurance departments and NAIC model guidance expect."},{title:"Sensitive vendors, vetted",description:"Vet and monitor the third parties involved in underwriting, servicing, and claims, and confirm their controls hold up."},{title:"Claims and TPA oversight",description:"Vet and monitor third-party administrators and claims vendors continuously."},{title:"Data aggregator diligence",description:"Assess the data providers feeding underwriting and pricing with the rigor they warrant."},{title:"Audit-ready across the book",description:"Keep a complete, examiner-ready record for every vendor relationship."}]},helps:{label:"How Coverbase helps",title:"Oversight across the policy lifecycle",subtitle:"Underwriting, servicing, and claims all run on vendors. Coverbase keeps risk visible at every stage.",features:[{icon:"/icon-images/shield.png",title:"Underwriting and claims vendors covered",description:"Bring the third parties across underwriting, servicing, and claims under one consistent program."},{icon:"/icon-images/report.png",title:"Regulator-ready records",description:"Produce documentation for DOI exams and NAIC reviews on demand."},{icon:"/icon-images/radar.png",title:"Continuous monitoring",description:"Financial, security, and compliance signals on every vendor, in real time."},{icon:"/icon-images/agent.png",title:"Diligence automated",description:"Evidence gathered and assessed without manual chasing."}]}},healthcare:{slug:"for-healthcare",navTitle:"Healthcare",navDescription:"Keep PHI accounted for across every business associate",metaTitle:"Third party risk management for healthcare | Coverbase",metaDescription:"Coverbase brings third party risk management to healthcare, tracking BAAs, mapping PHI flow to vendors, and collecting HITRUST and SOC 2 evidence.",hero:{label:"Guides for Healthcare",title:"In healthcare, a vendor breach is your breach. Coverbase keeps PHI accounted for across every business associate.",subtitle:"HIPAA makes you responsible for the vendors handling protected health information. Coverbase manages BAAs, diligence, and monitoring so PHI never leaves your sight."},why:{title:"Why healthcare organizations choose Coverbase",features:[{title:"HIPAA and BAA tracking",description:"Know which vendors are business associates, where the signed BAAs are, and what data each one touches."},{title:"PHI mapped end to end",description:"Track how protected health information flows to vendors and to their subcontractors."},{title:"HITRUST and security evidence",description:"Collect and review HITRUST, SOC 2, and security attestations automatically."},{title:"More oversight, lean teams",description:"Cover a growing vendor list without adding compliance headcount."},{title:"OCR-ready documentation",description:"Keep the records you'd need to show diligence if a vendor incident draws scrutiny."}]},helps:{label:"How Coverbase helps",title:"Diligence built around protected data",subtitle:"The whole point of vendor risk in healthcare is protecting patients' data. Coverbase keeps that at the center.",features:[{icon:"/icon-images/shield.png",title:"Business associate registry",description:"A current list of every BA, their BAA status, and their data access."},{icon:"/icon-images/scan.png",title:"PHI flow visibility",description:"See where patient data goes and who handles it downstream."},{icon:"/icon-images/agent.png",title:"Evidence gathered for you",description:"Security and compliance documents collected and read automatically."},{icon:"/icon-images/alert.png",title:"Incident-ready records",de
1scription:"Show a complete diligence trail the moment it's needed."}]}},biotech:{slug:"for-biotech",navTitle:"Biotech",navDescription:"Protect the data and IP your research partners touch",metaTitle:"Biotech vendor risk management platform | Coverbase",metaDescription:"Coverbase supports biotech vendor risk management for CROs, CDMOs, and lab partners, with inspection-ready records for FDA audits. Book a demo.",hero:{label:"Guides for Biotech",title:"Biotech runs on CROs, CDMOs, and lab vendors. Coverbase protects the data and IP they touch.",subtitle:"Your clinical and research partners hold your most valuable assets. Coverbase runs diligence and monitoring across every vendor in the GxP chain, without slowing the science."},why:{title:"Why biotech teams choose Coverbase",features:[{title:"GxP vendor oversight",description:"Assess CROs, CDMOs, and lab partners against the quality and data-integrity standards your programs require."},{title:"IP and data protection",description:"Track exactly which vendors touch research data and IP, and confirm the controls protecting them."},{title:"Clinical trial vendor risk",description:"Vet and monitor the vendors running trials, where a lapse can stall a program."},{title:"Diligence that keeps up with R&D",description:"Onboard new partners quickly so vendor risk never becomes the bottleneck to a milestone."},{title:"Inspection-ready records",description:"Keep complete documentation for in-scope vendors when auditors and the FDA come calling."}]},helps:{label:"How Coverbase helps",title:"Vendor risk that respects the timeline",subtitle:"Programs move on hard deadlines. Coverbase makes diligence fast enough to keep up and thorough enough to defend.",features:[{icon:"/icon-images/scan.png",title:"Data-integrity focus",description:"Assess vendors against the standards that keep clinical and lab data trustworthy."},{icon:"/icon-images/shield.png",title:"IP exposure mapped",description:"See which partners hold sensitive research and how it's protected."},{icon:"/icon-images/agent.png",title:"Diligence done for you",description:"Evidence gathered and reviewed automatically, so quality and security teams move faster."},{icon:"/icon-images/folder.png",title:"Audit-ready files",description:"Pull a complete vendor record for inspections without a fire drill."}]}},"technology-firms":{slug:"for-technology-firms",navTitle:"Technology Firms",navDescription:"Keep sub-processors and SaaS vendors under control",metaTitle:"SaaS vendor risk management for tech firms | Coverbase",metaDescription:"Coverbase automates SaaS vendor risk management: live sub-processor inventory, automated SOC 2 collection, and shadow IT detection. Book a demo.",hero:{label:"Guides for Technology Firms",title:"Your product is only as trustworthy as your sub-processors. Coverbase keeps that list under control.",subtitle:"Every SaaS tool and sub-processor you add is something your own customers will audit. Coverbase manages vendor and sub-processor risk so security reviews stop being a fire drill."},why:{title:"Why technology firms choose Coverbase",features:[{title:"Sub-processor management",description:"Maintain an accurate, current view of every sub-processor and the data each one handles."},{title:"Built for SOC 2 and customer audits",description:"Keep the vendor evidence your auditors and enterprise customers ask for ready year-round."},{title:"Tames vendor sprawl",description:"SaaS adoption is decentralized and fast. Coverbase catches new tools and assesses them before they become shadow risk."},{title:"Security reviews without the scramble",description:"Answer customer security questionnaires from a maintained source of truth instead of starting over each time."},{title:"Diligence at startup speed",description:"Onboard vendors in hours, not weeks, with automated evidence collection."}]},helps:{label:"How Coverbase helps",title:"Vendor risk that moves at your speed",subtitle:"You ship fast and your customers hold you to a high security bar. Coverbase keeps the vendor side of that bar without slowing you down.",features:[{icon:"/icon-images/layers.png",title:"Live sub-processor inventory",description:"A current map of who processes what, ready for your trust page and DPAs."},{icon:"/icon-images/agent.png",title:"Automated assessments",description:"SOC 2s and security docs collected and reviewed without manual chasing."},{icon:"/icon-images/scan.png",title:"Shadow IT surfaced",description:"Catch tools entering through the business before they go unreviewed."},{icon:"/icon-images/report.png",title:"Audit evidence on demand",description:"Hand auditors and customers a complete vendor record
1instantly."}]}},"legal-firms":{slug:"for-legal-firms",navTitle:"Legal Firms",navDescription:"Keep vendor risk client-ready and privilege protected",metaTitle:"Law firm vendor risk management platform | Coverbase",metaDescription:"Coverbase gives law firms vendor risk management that meets outside counsel guidelines and keeps privileged data protected. Book a demo.",hero:{label:"Guides for Legal Firms",title:"Clients audit your security before they trust you with their matters. Coverbase keeps your vendor risk client-ready.",subtitle:"Outside counsel guidelines now read like security frameworks. Coverbase manages diligence on the vendors touching privileged data so you can answer any client audit with confidence."},why:{title:"Why law firms choose Coverbase",features:[{title:"Outside counsel guidelines, met",description:"Keep the vendor controls clients require in their OCGs documented and current."},{title:"Client confidentiality protected",description:"Track which vendors touch privileged and client data, and confirm their safeguards."},{title:"eDiscovery and legal vendor risk",description:"Vet and monitor eDiscovery, hosting, and support vendors with the rigor matters demand."},{title:"Ready for client security audits",description:"Respond to client questionnaires from a maintained record instead of scrambling each time."},{title:"One firmwide source of truth",description:"Replace per-practice tracking with a single, defensible vendor program."}]},helps:{label:"How Coverbase helps",title:"Diligence that protects privilege",subtitle:"A vendor lapse is a confidentiality lapse. Coverbase keeps client data protected across every third party.",features:[{icon:"/icon-images/shield.png",title:"Privileged data mapped",description:"See which vendors handle confidential matter data and how it's secured."},{icon:"/icon-images/report.png",title:"Client audit responses ready",description:"Answer security reviews from a current, organized record."},{icon:"/icon-images/agent.png",title:"Evidence collected for you",description:"Vendor security documentation gathered and reviewed automatically."},{icon:"/icon-images/control.png",title:"Consistent firmwide standards",description:"Hold every vendor to the bar your clients expect."}]}},"higher-education":{slug:"for-higher-education",navTitle:"Higher Education",navDescription:"One view of vendor risk across a decentralized campus",metaTitle:"Higher education TPRM for decentralized campuses | Coverbase",metaDescription:"Higher education TPRM for decentralized campuses. Track EdTech and research vendors, meet GLBA and FERPA, and cover more ground without adding staff.",hero:{label:"Guides for Higher Education",title:"Procurement in higher ed is everywhere and nowhere. Coverbase brings vendor risk under one roof.",subtitle:"Departments buy their own tools, research handles sensitive data, and GLBA and FERPA still apply to all of it. Coverbase gives a central team visibility into vendor risk across a decentralized campus."},why:{title:"Why universities choose Coverbase",features:[{title:"GLBA and FERPA aligned",description:"Meet the GLBA Safeguards expectations tied to financial aid and protect student records under FERPA."},{title:"Decentralized procurement, centralized view",description:"See vendors brought on by every department, even the ones that skipped central IT."},{title:"EdTech and research vendor risk",description:"Assess the platforms touching student data and the vendors handling research data."},{title:"More coverage without more staff",description:"Automate diligence so a small central team covers the whole institution."},{title:"Audit-ready records",description:"Keep documentation that holds up for auditors and federal reviews."}]},helps:{label:"How Coverbase helps",title:"One view across a sprawling campus",subtitle:"No central team can chase every department's vendors by hand. Coverbase does the chasing and the diligence for you.",features:[{icon:"/icon-images/scan.png",title:"Shadow procurement surfaced",description:"Catch departmental tools entering without review."}
1,{icon:"/icon-images/shield.png",title:"Student data mapped",description:"Know which vendors touch FERPA-protected records and aid data."},{icon:"/icon-images/agent.png",title:"Automated diligence",description:"Evidence gathered and assessed across vendors automatically."},{icon:"/icon-images/report.png",title:"Reporting for leadership and auditors",description:"Produce institution-wide vendor risk reporting on demand."}]}},transportation:{slug:"for-transportation",navTitle:"Transportation",navDescription:"Keep carriers, brokers, and suppliers accountable",metaTitle:"Transportation vendor risk management | Coverbase",metaDescription:"Coverbase brings transportation vendor risk management to carriers, brokers, and 3PLs, with continuous checks on insurance and authority. Book a demo.",hero:{label:"Guides for Transportation & Logistics",title:"Transportation runs on a deep bench of carriers, brokers, and suppliers. Coverbase keeps every link accountable.",subtitle:"When a vendor fails, freight stops and customers feel it. Coverbase runs diligence and continuous monitoring across the partners your operation depends on."},why:{title:"Why transportation companies choose Coverbase",features:[{title:"Carrier and broker vetting",description:"Onboard carriers, brokers, and 3PLs with consistent checks on insurance, authority, and safety."},{title:"Supply chain visibility",description:"See the suppliers and subcontractors behind your critical lanes and services."},{title:"Continuous monitoring",description:"Catch lapsed insurance, financial trouble, or compliance issues before they disrupt operations."},{title:"Onboarding that keeps freight moving",description:"Bring on new partners fast without skipping the checks that protect the business."},{title:"One record for every partner",description:"Replace scattered certificates and emails with a single source of truth."}]},helps:{label:"How Coverbase helps",title:"Resilience across the partner network",subtitle:"A logistics operation is only as reliable as its weakest vendor. Coverbase keeps the whole network in view.",features:[{icon:"/icon-images/radar.png",title:"Continuous risk signals",description:"Insurance, financial, and compliance status tracked in real time."},{icon:"/icon-images/shield.png",title:"Insurance and authority checks",description:"Confirm coverage and operating authority on every carrier, automatically."},{icon:"/icon-images/layers.png",title:"Network-wide visibility",description:"Map dependencies across lanes, modes, and providers."},{icon:"/icon-images/alert.png",title:"Early disruption warning",description:"Flag at-risk partners before they cause a delay."}]}},"food-distributors":{slug:"for-food-distributors",navTitle:"Food Distributors",navDescription:"Food safety and vendor risk in one system",metaTitle:"Food distributor supplier risk management | Coverbase",metaDescription:"Coverbase runs food distributor supplier risk management with FSMA-aligned verification and GFSI certificate tracking. Book a demo.",hero:{label:"Guides for Food Distributors",title:"One supplier's lapse can trigger a recall. Coverbase keeps food safety and vendor risk in one system.",subtitle:"Distributors answer for every supplier, co-packer, and carrier in the chain. Coverbase runs diligence and continuous monitoring so FSMA compliance and food safety hold up from source to shelf."},why:{title:"Why food distributors choose Coverbase",features:[{title:"FSMA-aligned supplier verification",description:"Run the supplier verification FSMA expects, with documentation ready for an FDA inspection."},{title:"Food safety certifications tracked",description:"Keep SQF, BRC, and other GFSI audit certificates current across every supplier."},{title:"Traceability and recall readiness",description:"Know your supplier chain well enough to act fast when a recall hits."},{title:"Cold chain and co-packer oversight",description:"Vet and monitor co-packers, carriers, and cold-storage partners on a consistent schedule."},{title:"One record per supplier",description:"Replace binders and spreadsheets with a single, inspection-ready history."}]},helps:{label:"How Coverbase helps",title:"Safety and compliance from source to shelf",subtitle:"Food safety is a chain-wide problem. C
1overbase keeps every link documented and monitored.",features:[{icon:"/icon-images/shield.png",title:"Certification tracking",description:"Audit certificates and expirations monitored automatically."},{icon:"/icon-images/alert.png",title:"Recall-ready visibility",description:"Map the supplier chain so you can trace and respond fast."},{icon:"/icon-images/agent.png",title:"Verification automated",description:"Supplier documentation collected and reviewed for you."},{icon:"/icon-images/folder.png",title:"Inspection-ready files",description:"Pull a complete supplier record when the FDA or an auditor asks."}]}}},p={dora:{slug:"dora",navTitle:"DORA",navDescription:"EU digital operational resilience for finance",metaTitle:"DORA compliance for ICT third-party risk | Coverbase",metaDescription:"DORA requires a register of information, contractual safeguards and incident reporting within hours. Coverbase runs ICT vendor risk in one place.",hero:{label:"Coverbase for DORA",title:"DORA made the ICT third parties behind your firm a board-level problem. Coverbase helps you manage them.",subtitle:"The Digital Operational Resilience Act has applied to EU financial entities since January 2025. It expects a real ICT third-party risk framework, a register of every provider arrangement, and incident reporting on a tight clock. Coverbase gives you the inventory, oversight, and evidence to run it."},about:{title:"Who DORA applies to",description:"DORA (Regulation (EU) 2022/2554) is an EU regulation that applies directly across all member states. It covers roughly twenty categories of financial entities, from banks and payment firms to investment firms, insurers, and crypto-asset service providers, plus the ICT third-party providers that serve them. It has applied since 17 January 2025."},requirements:{title:"What DORA asks of you",features:[{title:"An ICT third-party risk framework",description:"Treat reliance on ICT providers as part of your overall risk management, with diligence proportional to how critical the service is."},{title:"A register of information",description:"Maintain a complete register of every contractual arrangement with ICT third-party providers, ready to report to your competent authority."},{title:"Contractual safeguards",description:"Provider contracts must cover service levels, data access and recovery, audit rights, sub-contracting, and exit, with stricter terms for critical or important functions."},{title:"Major incident reporting on a clock",description:"Classify and report major ICT-related incidents fast: an initial notification within hours, an intermediate report within 72 hours, and a final report within a month."}]},helps:{label:"How Coverbase helps",title:"Run your ICT third-party risk program in one place",subtitle:"DORA rewards organizations that can show their work. Coverbase keeps the inventory, diligence, and evidence current so you're not rebuilding it for every authority request.",features:[{icon:"/icon-images/folder.png",title:"Register-ready inventory",description:"Keep a structured, exportable record of every ICT provider arrangement and the function it supports."},{icon:"/icon-images/agent.png",title:"Diligence, automated",description:"Gather and review provider security and resilience evidence automatically, scaled to how critical the service is."},{icon:"/icon-images/control.png",title:"Contract terms tracked",description:"Capture the DORA-relevant clauses (audit rights, sub-contracting, exit) and flag what's missing."},{icon:"/icon-images/radar.png",title:"Concentration and nth-party view",description:"See where you depend on the same critical providers, and the fourth parties sitting behind them."}]}},nis2:{slug:"nis2",navTitle:"NIS2",navDescription:"EU cybersecurity and supply-chain security",metaTitle:"NIS2 compliance for supply-chain security | Coverbase",metaDescription:"NIS2 compliance requires evidence that you assess and monitor suppliers continuously. Coverbase automates assessments for NIS2 third-party obligations.",hero:{label:"Coverbase for NIS2",title:"NIS2 puts your suppliers' security on your shoulders. Coverbase helps you carry it.",subtitle:"The NIS2 Directive raises the cybersecurity bar for essential and important entities across eighteen sectors, and it names supply-chain security as a required risk-management measure. Because it's a directive, the exact rules live in each country's law, but the vendor obligation is constant. Coverbase helps you meet it."},about:{title:"Who NIS2 applies to",description:"NIS2 (Directive (EU) 2022/2555) applies, through national law, to 'essential' and 'important' entities across eighteen sectors, including energy, transport, banking, health, digital infrastru
1cture, public administration, and the manufacturing of critical products. It generally captures medium and large organizations. Member states were to transpose it by October 2024, so specifics vary by country."},requirements:{title:"What NIS2 asks of you",features:[{title:"Supply-chain security measures",description:"Address the security risks of your direct suppliers and service providers, including their own development and security practices."},{title:"Risk-based cybersecurity controls",description:"Adopt proportionate technical and organizational measures across your operations, with management accountable for them."},{title:"Incident notification on a clock",description:"For significant incidents, send an early warning within 24 hours, a fuller notification within 72 hours, and a final report within a month."},{title:"Management accountability",description:"Leadership can be held responsible for cybersecurity risk management, including the supplier side."}]},helps:{label:"How Coverbase helps",title:"Bring supplier security under one program",subtitle:"NIS2 wants evidence that you actually assess and monitor your suppliers. Coverbase turns that from a yearly scramble into a standing process.",features:[{icon:"/icon-images/agent.png",title:"Supplier assessments, automated",description:"Collect and review supplier security evidence without chasing PDFs."},{icon:"/icon-images/radar.png",title:"Continuous monitoring",description:"Watch suppliers for security and stability signals between formal reviews."},{icon:"/icon-images/alert.png",title:"Incident-ready records",description:"Keep the supplier facts you'd need on hand when a 24-hour clock starts."},{icon:"/icon-images/report.png",title:"Evidence for leadership and regulators",description:"Produce the supplier oversight reporting that accountable management and national authorities expect."}]}},"interagency-guidance":{slug:"interagency-guidance",navTitle:"Interagency Guidance",navDescription:"US bank third-party risk (Fed / OCC / FDIC)",metaTitle:"Interagency guidance on third-party relationships",metaDescription:"The interagency guidance on third-party relationships sets a five-stage lifecycle for US banks. Coverbase runs it with exam-ready evidence.",hero:{label:"Coverbase for the Interagency Guidance",title:"Examiners hold US banks to the Interagency Guidance. Coverbase helps you run it end to end.",subtitle:"The 2023 Interagency Guidance on Third-Party Relationships, issued jointly by the Federal Reserve, OCC, and FDIC, lays out the third-party risk lifecycle banks are expected to follow. It's guidance, not a rule, but examiners review against it, and Coverbase keeps the work and the proof in one place."},about:{title:"Who the Interagency Guidance applies to",description:"The guidance applies to banking organizations supervised by the Federal Reserve, OCC, and FDIC, including community banks. It's principles-based and scalable: oversight should match the risk of the relationship, with the most scrutiny on 'critical activities.' It replaced the agencies' prior separate guidance, including OCC Bulletin 2013-29. Credit unions fall under the NCUA instead."},requirements:{title:"The third-party risk lifecycle it expects",features:[{title:"Planning",description:"Weigh the risks and benefits before entering a third-party relationship."},{title:"Due diligence and selection",description:"Assess a prospective third party's financials, controls, and ability to perform before you sign."},{title:"Contract negotiation",description:"Put the right terms in place: performance, security, audit rights, and termination."},{title:"Ongoing monitoring and termination",description:"Monitor the relationship for its whole life, with heightened attention to critical activities, and plan for a clean exit."}]},helps:{label:"How Coverbase helps",title:"Cover all five stages, with the evidence",subtitle:"Banks rarely fall short on policy. They fall short because the evidence is scattered. Coverbase keeps every stage in one defensible record.",features:[{icon:"/icon-images/agent.png",title:"Diligence done for you",description:"Gather and assess third-party evidence automatically, scaled to the risk of the activity."},{icon:"/icon-images/control.png",title:"Critical activities flagged",description:"Tier relationships so your most critical vendors get the deepest oversight."},{icon:"/icon-images/cycle.png",title:"Lifecycle monitoring",description:"Track each relationship from planning through termination, not just at onboarding."},{icon:"/icon-images/folder.png",title:"Exam-ready evidence",description:"Pull a complete, time-stamped record for any vendor when examiners ask."}]}},ncua:{slug:"ncua",navTitle:"NCUA",navDescription:"US credit union vendor due diligence",metaTitle:"NCUA third-party due diligence softw
1are | Coverbase",metaDescription:"Coverbase automates NCUA third-party due diligence, monitoring, and 72-hour incident-ready records for credit unions. Book a demo.",hero:{label:"Coverbase for NCUA Guidance",title:"The NCUA can't examine your vendors. It examines how you manage them. Coverbase helps you show your work.",subtitle:"NCUA guidance puts the responsibility for third-party relationships on the credit union, not the vendor. Coverbase runs the risk assessment, due diligence, and ongoing monitoring that examiners look for."},about:{title:"Who NCUA guidance applies to",description:"It applies to federally insured credit unions (Supervisory Letter 07-01 and related due-diligence guidance). Importantly, the NCUA does not have authority to examine or supervise third-party vendors or CUSOs directly, so the credit union remains ultimately responsible for managing those relationships. The NCUA's separate cyber incident rule (12 CFR Part 748) requires reporting a reportable cyber incident, including one at a third-party provider, within 72 hours."},requirements:{title:"What NCUA guidance asks of you",features:[{title:"Risk assessment and planning",description:"Understand the risk a relationship carries before you take it on."},{title:"Due diligence",description:"Review the vendor's background, business model, financial health, and contract terms."},{title:"Monitoring and control",description:"Keep oversight current for the life of the relationship; you stay responsible regardless of vendor involvement."},{title:"72-hour cyber incident reporting",description:"Be ready to notify the NCUA within 72 hours of a reportable cyber incident, including one at a third-party provider."}]},helps:{label:"How Coverbase helps",title:"Defensible vendor diligence on a credit union's budget",subtitle:"You carry the responsibility without the ability to examine vendors yourself. Coverbase gives you the next best thing: thorough, documented diligence.",features:[{icon:"/icon-images/agent.png",title:"Evidence gathered for you",description:"SOC reports, financials, and security documentation collected and reviewed automatically."},{icon:"/icon-images/shield.png",title:"Member data mapped",description:"Know which vendors and CUSOs touch member data and how it's protected."},{icon:"/icon-images/alert.png",title:"Incident-ready records",description:"Keep the vendor facts on hand for the 72-hour cyber incident clock."},{icon:"/icon-images/report.png",title:"Examiner-ready reporting",description:"Produce the documentation NCUA exams expect, on demand."}]}},"nydfs-500":{slug:"nydfs-500",navTitle:"NYDFS Part 500",navDescription:"New York financial services cybersecurity",metaTitle:"NYDFS cybersecurity regulation: Part 500 compliance",metaDescription:"The NYDFS cybersecurity regulation requires a §500.11 third-party policy and 72-hour incident notice for vendor breaches. See how Coverbase supports it.",hero:{label:"Coverbase for NYDFS Part 500",title:"NYDFS Part 500 makes your vendors' security your written policy. Coverbase helps you back it up.",subtitle:"New York's cybersecurity regulation, amended in 2023, requires covered financial-services companies to maintain a third-party service provider security policy, and to report incidents, including ones at a vendor, within 72 hours. The §500.11 third-party requirements take full effect November 1, 2025."},about:{title:"Who Part 500 applies to",description:"23 NYCRR Part 500, issued by the New York State Department of Financial Services, applies to 'covered entities,' meaning institutions licensed or authorized under New York banking, insurance, and financial-services law, with heightened obligations for larger 'Class A' companies. The 2023 Second Amendment phased in new requirements through November 2025."},requirements:{title:"What Part 500 asks of you",features:[{title:"A third-party security policy (§500.11)",description:"Maintain written policies for the due diligence, minimum controls, and contractual terms required of vendors with access to nonpublic information."},{title:"Vendor due diligence and reassessment",description:"Assess third-party providers based on the risk they present, and reassess them periodically."},{title:"Contractual security terms",description:"Require access controls including MFA, encryption, and breach-notification obligations in vendor contracts."},{title:"72-hour incident notice",description:"Notify DFS within 72 hours of a qualifying cybersecurity incident, including one at a third-party provider, with a 24-hour notice for extortion payments."}]},helps:{label:"How Coverbase helps",title:"Stand up your §500.11 program with evidence behind it",subtitle:"A policy on paper isn't enough. Part 500 wants diligence, reassessment, and contract terms to match. Coverbase keeps all three current.",features:[{icon:"/icon-images/agent.png",title:"Vendor diligence, automated",description:"Assess and reassess third-party providers on a
1schedule, not ad hoc."},{icon:"/icon-images/control.png",title:"Required contract terms tracked",description:"Flag whether vendor contracts carry the MFA, encryption, and notification clauses §500.11 expects."},{icon:"/icon-images/alert.png",title:"Incident-ready records",description:"Keep vendor facts on hand for the 72-hour DFS clock."},{icon:"/icon-images/folder.png",title:"Audit-ready documentation",description:"Hold the evidence behind your annual certification of material compliance."}]}},"glba-safeguards":{slug:"glba-safeguards",navTitle:"GLBA Safeguards",navDescription:"FTC Safeguards Rule for financial firms",metaTitle:"GLBA Safeguards Rule vendor oversight | Coverbase",metaDescription:"The GLBA Safeguards Rule requires vetting, contracting, and monitoring service providers, plus FTC notice within 30 days for breaches of 500+ consumers.",hero:{label:"Coverbase for the GLBA Safeguards Rule",title:"The Safeguards Rule makes you responsible for the providers handling customer data. Coverbase helps you oversee them.",subtitle:"The FTC's Safeguards Rule requires non-bank financial institutions to vet, contract with, and monitor their service providers, and since May 2024, to notify the FTC within 30 days of a breach affecting 500 or more consumers. Coverbase runs the oversight side."},about:{title:"Who the Safeguards Rule applies to",description:"The rule (16 CFR Part 314), enforced by the FTC under the Gramm-Leach-Bliley Act, applies to non-banking 'financial institutions' under FTC jurisdiction, such as mortgage lenders and brokers, finance companies, auto dealers, tax preparers, collection agencies, and certain advisers. Banks and credit unions are overseen by their own prudential regulators."},requirements:{title:"What the Safeguards Rule asks of you",features:[{title:"Service provider oversight (§314.4(f))",description:"Select providers that can safeguard customer information, require safeguards by contract, and periodically assess them based on risk."},{title:"A written information security program",description:"Run a documented program overseen by a designated Qualified Individual."},{title:"Risk-based safeguards",description:"Apply controls like access management, encryption, and MFA across customer information."},{title:"30-day breach notification",description:"Notify the FTC as soon as possible, and no later than 30 days, after discovering a breach affecting 500 or more consumers."}]},helps:{label:"How Coverbase helps",title:"Make service-provider oversight a standing process",subtitle:"The rule names three things: pick capable providers, contract for safeguards, and reassess by risk. Coverbase does all three on a schedule.",features:[{icon:"/icon-images/agent.png",title:"Provider assessments, automated",description:"Vet and reassess service providers based on the risk they present."},{icon:"/icon-images/control.png",title:"Safeguard clauses tracked",description:"Confirm provider contracts require the safeguards the rule expects."},{icon:"/icon-images/alert.png",title:"Breach-ready records",description:"Keep provider facts on hand for the 30-day FTC notification clock."},{icon:"/icon-images/report.png",title:"Program documentation",description:"Give your Qualified Individual the evidence to oversee the program."}]}},fedramp:{slug:"fedramp",navTitle:"FedRAMP",navDescription:"US federal cloud authorization",metaTitle:"FedRAMP compliance for your supply chain | Coverbase",metaDescription:"FedRAMP compliance runs on NIST 800-53 baselines and 3PAO assessment. See how Coverbase tracks the providers behind your authorized service. Book a demo.",hero:{label:"Coverbase for FedRAMP",title:"FedRAMP is how the government vets its cloud. Coverbase helps you vet yours.",subtitle:"The Federal Risk and Authorization Management Program, run by GSA, authorizes the cloud services federal agencies can use, built on NIST 800-53 baselines and verified by independent assessors. Whether you're pursuing authorization or relying on authorized providers, Coverbase keeps the third-party side organized."},about:{title:"What FedRAMP is and who it touches",description:"FedRAMP is a US government authorization program, given statutory footing by the FedRAMP Authorization Act of 2022. It isn't a voluntary framework. It applies to cloud service providers selling to federal agencies, which must use authorized offerings. Its 2025 'FedRAMP 20x' modernization aims to make authorizations faster and more automated."},requirements:{title:"What FedRAMP involves",features:[{title:"NIST 800-53 control baselines",description:"Authorization is built on Low, Moderate, or High control baselines, including the Supply Chain Risk Management (SR) family."},{title:"Independent assessment (3PAO)",description:"Accredited third-party assessors verify a provider's controls."},{title:"Continuous monitoring",description:"Authorized providers maintain ongoing monitoring and reporting, not a one-time review."},{title:"Supply-chain assurance",description:"FedRAMP itself is a third-party assurance mechanism for the federal cloud supply chain."}]},helps:{label:"How Coverbase helps",title:"Manage the vendors behind your own service",subtitle:"FedRAMP authorization depends on understanding your own supply chain. Coverbase gives you that view and keeps it current.",features:[{icon:"/icon-images/layers.png",title:"Provider inventory",description:"Track the cloud and software providers in your environment and what they support."},{icon:"/icon-images/agent.png",title:"Evidence gathered for you",description:"Collect and review provider security attestations automatically."},{icon:"/icon-images/radar.png",title:"Continuous monitoring",description:"Watch providers for changes between assessment cycles."},{icon:"/icon-images/scan.png",title:"Configuration inspection",description:"With Coverbase Inspect, verify how a provider is actually configured, not just what they attest."}]}},cmmc:{slug:"cmmc",navTitle:"CMMC",navDescription:"US DoD contractor security certification",metaTitle:"CMMC compliance for defense subcontractor chains | Coverbase",metaDescription:"CMMC compliance requires flowing NIST 800-171 requirements down to subcontractors handling FCI or CUI. Coverbase tracks subcontractor level and evidence.",hero:{label:"Coverbase for CMMC",title:"CMMC flows security requirements down your subcontractor chain. Coverbase helps you manage it.",subtitle:"The DoD's Cybersecurity Maturity Model Certification requires defense contractors handling federal contract information and controlled unclassified information to meet NIST 800-171-based requirements, and to flow them down to subcontractors. Coverbase keeps that supply-chain side organized and verifiable."},about:{title:"Who CMMC applies to",description:"CMMC applies to Department of Defense contractors and subcontractors (the Defense Industrial Base) that handle FCI or CUI. It has three levels, with Level 2 aligned to NIST SP 800-171 and verified by self-assessment or an accredited C3PAO. The requirement began appearing in DoD contracts on November 10, 2025, on a phased rollout."},requirements:{title:"What CMMC involves",features:[{title:"Three certification levels",description:"From Level 1 foundational safeguarding of FCI to Level 3 expert protection of CUI."},{title:"NIST 800-171 alignment",description:"Level 2 maps to the 110 requirements of NIST SP 800-171."},{title:"Flow-down to subcontractors",description:"Prime contractors must ensure subcontractors handling FCI or CUI meet the right level."},{title:"Independent verification",description:"Many contracts require assessment by an accredited C3PAO, not just a self-attestation."}]},helps:{label:"How Coverbase helps",title:"Keep your subcontractor chain in view",subtitle:"CMMC is a supply-chain assurance regime. Coverbase gives primes a standing view of the subs they have to flow requirements down to.",features:[{icon:"/icon-images/layers.png",title:"Subcontractor inventory",description:"Track the subs and suppliers in scope and the information they handle."},{icon:"/icon-images/agent.png",title:"Evidence gathered for you",description:"Collect and review subcontractor security documentation automatically."},{icon:"/icon-images/control.png",title:"Requirements tracked",description:"Flag whether each sub carries the level and terms its scope requires."},{icon:"/icon-images/radar.png",title:"Continuous monitoring",description:"Watch the chain for changes, not just at award."}]}},"sec-cyber-disclosure":{slug:"sec-cyber-disclosure",navTitle:"SEC Cyber Rules",navDescription:"US public company cyber disclosure",metaTitle:"SEC cyber disclosure rules: third-party risk | Coverbase",metaDescription:"SEC cyber rules give companies four days to report material incidents, including vendor breaches. Coverbase maps vendor exposure to judge materiality.",hero:{label:"Coverbase for SEC Cyber Disclosure",title:"A breach at your vendor can become your 8-K. Coverbase helps you see it coming.",subtitle:"The SEC's 2023 cybersecurity rules require public companies to describe their risk-management processes annually and to disclose material incidents on Form 8-K within four business days of deciding they're material. The rules count third-party and cloud systems you use, so a vendor incident can trigger your obligation."},about:{title:"Who the SEC rules apply to",description:"The rules, adopted by the SEC in July 2023, apply to public companies (SEC registrants). Regulation S-K Item 106 covers annual disclosure of cybersecurity risk management and governance; Form 8-K Item 1.05 covers material incident disclosure. The four-business-day clock starts when you determine an incident is material, not when you discover it. Reduced visibility into a third party's systems doesn't excuse disclosure."},requirements:{title:"What the SEC rules ask of you",features:[{title:"Annual risk-management disclosure",description:"Describe how you assess, identify, and manage material cybersecurity risks, including from third parties, and how the board oversees them."},{title:"Material incident disclosure",description:"File an 8-K describing a material incident's nature, scope, timing, and impact."},{title:"A four-business-day clock",description:"Disclose within four business days of determining the incident is material."},{title:"Third-party systems count",description:"An incident on a vendor or cloud system you use can be material to you."}]},helps:{label:"How Coverbase helps",title:"Know your third-party exposure before you disclose it",subtitle:"You can't assess materiality on a vendor incident if you don't know
1what the vendor touches. Coverbase keeps that picture current.",features:[{icon:"/icon-images/layers.png",title:"Vendor and data mapping",description:"Know which vendors support which systems and data, so impact is faster to judge."},{icon:"/icon-images/radar.png",title:"Continuous monitoring",description:"Catch vendor incidents and changes through standing monitoring."},{icon:"/icon-images/alert.png",title:"Incident-ready records",description:"Pull the vendor facts you need when the four-day clock starts."},{icon:"/icon-images/report.png",title:"Governance evidence",description:"Support your annual disclosure with documented third-party risk processes."}]}},hipaa:{slug:"hipaa",navTitle:"HIPAA",navDescription:"US health data and business associates",metaTitle:"HIPAA compliance software for BAAs | Coverbase",metaDescription:"HIPAA compliance software tracks every business associate handling PHI: BAA status, subcontractor flow-down, and records for the 60-day breach clock.",hero:{label:"Coverbase for HIPAA",title:"Every vendor touching PHI is a business associate. Coverbase helps you keep them accounted for.",subtitle:"HIPAA requires covered entities to sign business associate agreements with vendors handling protected health information, ensure those terms flow to subcontractors, and notify affected individuals of a breach within 60 days. Coverbase keeps the BAAs, diligence, and monitoring in one place."},about:{title:"Who HIPAA applies to",description:"HIPAA, enforced by the HHS Office for Civil Rights, applies to covered entities (health plans, clearinghouses, and most providers) and their business associates, the vendors that create, receive, maintain, or transmit PHI. Under HITECH, business associates are directly liable for certain requirements. A 2024 proposed update to the Security Rule would strengthen ePHI requirements, but it isn't final."},requirements:{title:"What HIPAA asks of you",features:[{title:"Business associate agreements",description:"Sign a BAA with every vendor handling PHI, requiring them to safeguard it."},{title:"Subcontractor flow-down",description:"Ensure business associates bind their own subcontractors to the same protections."},{title:"Safeguards for ePHI",description:"Vendors handling electronic PHI must maintain appropriate security controls."},{title:"60-day breach notification",description:"Notify affected individuals within 60 days; breaches of 500 or more also require notice to HHS and the media."}]},helps:{label:"How Coverbase helps",title:"Keep your business associates accounted for",subtitle:"The risk isn't the BAA you signed. It's the vendor you forgot. Coverbase keeps the whole business associate population in view.",features:[{icon:"/icon-images/shield.png",title:"Business associate registry",description:"A current list of every BA, their BAA status, and the PHI they handle."},{icon:"/icon-images/agent.png",title:"Diligence gathered for you",description:"Collect and review vendor security evidence automatically."},{icon:"/icon-images/scan.png",title:"Data flow visibility",description:"See where PHI goes downstream to subcontractors."},{icon:"/icon-images/alert.png",title:"Incident-ready records",description:"Keep the vendor facts on hand when a breach clock starts."}]}},"pci-dss":{slug:"pci-dss",navTitle:"PCI DSS",navDescription:"Payment card data security standard",metaTitle:"PCI DSS compliance for third-party providers | Coverbase",metaDescription:"PCI DSS compliance requires a vendor inventory, written agreements and monitoring under Req. 12.8. Coverbase tracks provider status automatically.",hero:{label:"Coverbase for PCI DSS",title:"Your payment providers are in scope too. Coverbase helps you manage them.",subtitle:"PCI DSS requires anyone handling cardholder data to manage their third-party service providers: keep a list, contract for security, and monitor each provider's compliance. With v4.x's future-dated requirements now mandatory, the third-party expectations are firmer than ever. Coverbase runs that program."},about:{title:"What PCI DSS is and who it applies to",description:"PCI DSS is a contractual standard from the PCI Security Standards Council, not a law. The card brands and acquiring banks enforce it. It applies to any merchant or service provider that stores, processes, or transmits cardholder data. The current version is v4.0.1, and v4.x's future-dated requirements became mandatory on March 31, 2025."},requirements:{title:"What PCI DSS asks of you (Req. 12.8 and 12.9)",features:[{title:"A list of service providers",description:"Maintain an inventory of the third-party service providers with access to cardholder data."},{title:"Written agreements",description:"Have agreements where providers acknowledge responsibility for the cardholder data they handle."},{title:"Due diligence and monitoring",description:"Vet providers before engaging them and monitor their PCI DSS compliance status."},{title:"A clear responsibility split",description:"Document which PCI requirements each party manages."}]},helps:{label:"How Coverbase helps",title:"Manage your service providers without the spreadsheet",subtitle:"Requirement 12.8 is a vendor-management program in disguise. Coverbase gives you the inventory, agreements, and monitoring it asks for.",features:[{icon:"/icon-images/layers.png",title:"Provider inventory",description:"Keep a current list of service providers and the cardholder data they touch."},{icon:"/icon-images/control.png",title:"Responsibility matrix",description:"Track which requirements each provider is responsible for."},{icon:"/icon-images/agent.png",title:"Compliance status tracked",description:"Collect and monitor providers' PCI DSS status automatically."},{icon:"/icon-images/radar.png",title:"Continuous monitoring",description:"Watch providers between assessments, not once a year."}]}},"iso-27001":{slug:"iso-27001",navTitle:"ISO 27001",navDescription:"Information security management (ISMS)",metaTitle:"ISO 27001 compliance for supplier risk | Coverbase",metaDescription:"ISO 27001 compliance covers supplier relationships under Annex A.5.19-A.5.23. Coverbase automates supplier diligence and monitoring for audits. Book a demo.",hero:{label:"Coverbase for ISO 27001",title:"ISO 27001 puts supplier security in your ISMS. Coverbase helps you run it.",subtitle:"ISO/IEC 27001:2022 expects an information security management system that addresses supplier relationships, the ICT supply chain, and cloud services, covered by Annex A controls A.5.19 through A.5.23. Coverbase operates that supplier side so your ISMS holds up to a certification audit."},about:{title:"What ISO 27001 is and who it's for",description:"ISO/IEC 27001 is a voluntary international standard for an information security management system, published by ISO and IEC. Organizations can earn third-party certification from an accredited body. The current 2022 revision restructured Annex A into 93 controls and added a dedicated control for cloud-service security."},requirements:{title:"The supplier controls (Annex A.5.19-A.5.23)",features:[{title:"Security in supplier relationships (A.5.19)",description:"Define and manage the information security risk of using suppliers."},{title:"Security in supplier agreements (A.5.20)",description:"Address security requirements in your supplier contracts."},{title:"ICT supply-chain security (A.5.21)",description:"Manage risk across the ICT products and services supply chain."},{title:"Monitoring and cloud services (A.5.22-A.5.23)",description:"Review and monitor supplier services, and manage the security of cloud services you use."}]},helps:{label:"How Coverbase helps",title:"Operate the supplier side of your ISMS",subtitle:"Auditors want to see supplier risk managed, not just documented. Coverbase keeps the diligence and monitoring running.",features:[{icon:"/icon-images/agent.png",title:"Supplier diligence, automated",description:"Collect and review supplier security evidence on a schedule."},{icon:"/icon-images/control.png",title:"Agreement terms tracked",description:"Flag whether supplier contracts carry the security terms Annex A expects."},{icon:"/icon-images/radar.png",title:"Ongoing monitoring",description:"Review and monitor supplier services over time."},{icon:"/icon-images/scan.png",title:"Cloud service inspection",description:"With Coverbase Inspect, verify how a cloud service is actually configured."}]}}
1,"soc-2":{slug:"soc-2",navTitle:"SOC 2",navDescription:"AICPA service-organization attestation",metaTitle:"SOC 2 compliance review, explained for vendors | Coverbase",metaDescription:"Learn what SOC 2 compliance covers, Type I vs Type II, exceptions, and subservice organizations, and see how Coverbase reads reports and tracks CUECs.",hero:{label:"Coverbase for SOC 2",title:"SOC 2 reports pile up faster than anyone can read them. Coverbase reads them for you.",subtitle:"A SOC 2 report is the artifact most vendor reviews hinge on, but only if someone actually reads it, checks the exceptions, and tracks the subservice organizations behind it. Coverbase ingests SOC 2 reports, surfaces what matters, and keeps the review current."},about:{title:"What SOC 2 is (and isn't)",description:"SOC 2 is an attestation report from a licensed CPA firm against the AICPA's Trust Services Criteria. It isn't a certification, and it isn't a law. A Type I report covers control design at a point in time; a Type II covers operating effectiveness over a period. Reports also note subservice organizations and complementary user-entity controls you're expected to implement."},requirements:{title:"What to actually check in a SOC 2",features:[{title:"Type I vs Type II",description:"Know whether you're relying on design at a point in time or effectiveness over a period."},{title:"Exceptions and qualifications",description:"Read the testing exceptions and the auditor's opinion, not just the logo."},{title:"Subservice organizations",description:"Understand the vendors behind your vendor, whether carved-out or included."},{title:"Complementary user controls (CUECs)",description:"Implement the controls the report says are your responsibility."}]},helps:{label:"How Coverbase helps",title:"Turn SOC 2 reports into decisions",subtitle:"The report is only useful if it changes your risk picture. Coverbase pulls the signal out and tracks the follow-ups.",features:[{icon:"/icon-images/report.png",title:"SOC 2 read for you",description:"Exceptions, scope gaps, and qualifications surfaced automatically."},{icon:"/icon-images/layers.png",title:"Subservice visibility",description:"See the subservice organizations a report carves out."},{icon:"/icon-images/check.png",title:"CUECs tracked",description:"Capture the complementary user controls you need to own."},{icon:"/icon-images/cycle.png",title:"Refresh on schedule",description:"Track report periods and bridge letters so coverage never lapses."}]}},"nist-csf":{slug:"nist-csf",navTitle:"NIST CSF",navDescription:"NIST cybersecurity and supply-chain framework",metaTitle:"NIST CSF for third-party risk management | Coverbase",metaDescription:"NIST CSF 2.0 added a Govern function with supply-chain risk management (GV.SC). See how Coverbase operationalizes C-SCRM across your supplier lifecycle.",hero:{label:"Coverbase for NIST CSF",title:"NIST CSF 2.0 made supply-chain risk its own discipline. Coverbase helps you run it.",subtitle:"The 2024 update to the NIST Cybersecurity Framework added a sixth function, Govern, with a dedicated category for cybersecurity supply-chain risk management (GV.SC). Coverbase operationalizes that work, from supplier prioritization and diligence to monitoring and offboarding, with the evidence to show for it."},about:{title:"What the NIST frameworks are",description:"NIST publications are voluntary frameworks, though they become mandatory by reference when adopted into contracts and regulations (for example, 800-53 via FedRAMP and 800-171 via CMMC). CSF 2.0 (2024) added the Govern function and broadened the framework to all organizations; 800-53 Rev. 5 includes a dedicated Supply Chain Risk Management (SR) control family."},requirements:{title:"Cybersecurity supply-chain risk management (GV.SC)",features:[{title:"Supplier prioritization",description:"Identify and prioritize suppliers by the risk they present."},{title:"Contractual requirements",description:"Set cybersecurity requirements in supplier agreements."},{title:"Due diligence and monitoring",description:"Assess suppliers before engagement and monitor them through the relationship."},{title:"Incident coordination and offboarding",description:"Plan for incidents involving suppliers and for ending the relationship cleanly."}]},helps:{label:"How Coverbase helps",title:"Operationalize C-SCRM, don't just document it",subtitle:"GV.SC reads like a checklist for what Coverbase already does. We turn the framework into a running program.",features:[{icon:"/icon-images/control.png",title:"Supplier prioritization",description:"Tier suppliers by risk so oversight matches exp
1osure."},{icon:"/icon-images/agent.png",title:"Diligence, automated",description:"Collect and assess supplier evidence on a schedule."},{icon:"/icon-images/radar.png",title:"Continuous monitoring",description:"Watch suppliers across risk domains over time."},{icon:"/icon-images/cycle.png",title:"Lifecycle coverage",description:"From onboarding through offboarding, in one record."}]}}},u={title:"Coverbase Inspect",description:"Inspect a vendor's live configuration with read-only access.",href:"/solutions/coverbase-inspect"},h={title:"Fourth-Party Monitoring",description:"See past your vendors to their sub-processors, cloud, and software (SBOMs).",href:"/solutions/fourth-party-monitoring"},m={"third-party-risk-management":{slug:"third-party-risk-management",navTitle:"Third-Party Risk Management",navDescription:"Assess and monitor vendor risk continuously",metaTitle:"Third-party risk management platform | Coverbase",metaDescription:"Coverbase is a third-party risk management platform that scores inherent risk and monitors vendors continuously. Book a demo.",hero:{label:"Third-Party Risk Management",tagline:"Vendor risk that never goes stale.",title:"Assess and monitor third-party risk continuously, not once a year.",description:"Coverbase runs the full vendor risk lifecycle: inherent risk scoring, assessment, continuous monitoring, and findings. AI does the reading; your team makes the calls.",problemText:"A questionnaire is a snapshot, and most go stale the day they're filed. Posture drifts, vendors change, and the fourth parties you never see introduce risk you never assessed.",solutionText:"Coverbase treats third-party risk as a living program. AI ingests questionnaires and SOC 2 reports, maps evidence to your controls, and surfaces gaps. Continuous monitoring blends security, financial, and compliance signals into a live risk picture, and fourth-party visibility extends past your direct vendors to the providers behind them."},capabilities:{label:"In this category",title:"The capabilities behind continuous TPRM",subtitle:"These solutions carry the assessment, monitoring, findings, and nth-party side of the vendor lifecycle.",items:[{title:"Risk Assessment Copilot",description:"AI analysis of questionnaires, contracts, and evidence against your controls.",href:"/solutions/risk-assessment-copilot"},{title:"Zero-Touch Assessments",description:"Vendor assessments that complete without an analyst.",href:"/solutions/zero-touch-assessments"},{title:"Supplier Radar",description:"Continuous monitoring across every supplier risk domain.",href:"/solutions/supplier-radar"},{title:"Findings Manager",description:"Track findings to closure and surface systemic risk patterns across assessments.",href:"/solutions/findings-manager"},{title:"Risk Reporting & Quantification",description:"Quantify third-party risk in financial terms.",href:"/solutions/risk-reporting-quantification"},h,u]},benefits:{label:"Benefits",title:"Why teams run TPRM on Coverbase",items:[{icon:"/icon-images/shield.png",title:"Risk-based by default",description:"Tier vendors by inherent risk so effort matches exposure."},{icon:"/icon-images/agent.png",title:"AI does the reading",description:"Questionnaires and SOC 2s analyzed automatically, against your controls."},{icon:"/icon-images/radar.png",title:"Always current",description:"Continuous signals replace the annual reassessment scramble."},{icon:"/icon-images/layers.png",title:"Past the third party",description:"See fourth parties and concentration risk, not just direct vendors."}]}},"intake-to-procure":{slug:"intake-to-procure",navTitle:"Intake to Procure",navDescription:"A guided front door for every request",metaTitle:"Intake to procure software for procurement teams | Coverbase",metaDescription:"Run intake to procure from one guided front door: enrich requests, score risk, and orchestrate approvals across finance, legal, and security. Book a demo.",hero:{label:"Intake to Procure",tagline:"Procurement shouldn't be a guessing game.",title:"Give every request one guided front door, from intake to a ready-to-process PO.",description:"Coverbase captures requests in plain language, enriches them with context, runs risk and validation behind the scenes, and orchestrates approvals across finance, legal, security, and procurement.",problemText:"Employees don't know
1what procurement needs or who to ask, so requests scatter across email and Slack. Approvals stall in disconnected systems, and procurement inherits messy, half-scoped requests.",solutionText:"Coverbase replaces the maze with a single intake that adapts to what's being bought. AI guides the requester, pulls context from internal and external sources, scores risk, and routes parallel approvals across stakeholders. Procurement gets complete, validated requests instead of the usual back-and-forth."},capabilities:{label:"In this category",title:"The capabilities behind the front door",subtitle:"These solutions carry intake, the orchestration that follows it, and sourcing.",items:[{title:"Autonomous Intake",description:"Research, risk-score, and validate vendor requests automatically.",href:"/solutions/autonomous-intake"},{title:"Workflow Autopilot",description:"Orchestrate procurement approvals across every stakeholder.",href:"/solutions/workflow-autopilot"},{title:"Autonomous RFP",description:"Agents run your RFPs end to end.",href:"/solutions/autonomous-rfp"}]},benefits:{label:"Benefits",title:"Why teams run intake on Coverbase",items:[{icon:"/icon-images/send.png",title:"Frictionless for employees",description:"Submit a request in minutes, no training required."},{icon:"/icon-images/sort.png",title:"Clean for procurement",description:"Requests arrive scoped, risk-scored, and validated."},{icon:"/icon-images/gear.png",title:"Orchestrated approvals",description:"Route finance, legal, security, and procurement in parallel."},{icon:"/icon-images/fast.png",title:"Faster cycle times",description:"Cut the time from request to PO without losing control."}]}},"contract-lifecycle-management":{slug:"contract-lifecycle-management",navTitle:"Contract Lifecycle Management",navDescription:"Turn contracts into living controls",metaTitle:"Contract lifecycle management software | Coverbase",metaDescription:"Coverbase's contract lifecycle management software extracts obligations, SLAs, and renewal terms, then flags deviations against vendor performance.",hero:{label:"Contract Lifecycle Management",tagline:"The contract doesn't end at signature.",title:"Turn signed contracts into living risk controls.",description:"Coverbase extracts obligations, SLAs, and renewal terms from every contract, monitors performance against real data, and flags deviations. The post-signature life of a contract gets managed, not forgotten.",problemText:"Most of a contract's value and risk lives after signing, but obligations, SLAs, and renewal windows get buried in PDFs no one reads again until something goes wrong.",solutionText:"Coverbase reads every contract and turns it into structured, trackable commitments. Obligations, SLAs, and breach terms are extracted automatically. Renewals and auto-renewals surface before they lapse, and assessment findings can flow back as contract addendums, closing the loop between risk and legal."},capabilities:{label:"In this category",title:"The solutions behind it",subtitle:"Contract Guardian carries contract intelligence; Obligations Tracker keeps the duties you take on accounted for.",items:[{title:"Contract Guardian",description:"Extract obligations and turn contracts into living controls.",href:"/solutions/contract-guardian"},{title:"Obligations Tracker",description:"Track the obligations you take on: CUECs, legal terms, SOW duties, and controls.",href:"/solutions/obligations-tracker"}]},benefits:{label:"Benefits",title:"Why teams run contracts on Coverbase",items:[{icon:"/icon-images/report.png",title:"Obligations extracted",description:"SLAs, renewals, and breach terms pulled from every contract."},{icon:"/icon-images/alert.png",title:"No silent renewals",description:"Renewal and termination windows surface before they pass."},{icon:"/icon-images/control.png",title:"Performance monitored",description:"Track vendor performance against contract terms with real data."},{icon:"/icon-images/cycle.png",title:"Closed loop with risk",description:"Assessment findings flow back into contract terms."}]}},"application-security-inspection":{slug:"application-security-inspection",navTitle:"Ap
1plication Security Inspection",navDescription:"Verify a vendor's real configuration",metaTitle:"Application security testing for vendors | Coverbase",metaDescription:"Coverbase runs application security testing on live vendor environments, checking MFA, access sprawl, and integrations with read-only access. Book a demo.",hero:{label:"Application Security Inspection",tagline:"Stop taking a vendor's word for it.",title:"Inspect how a vendor is actually configured, not just what the questionnaire claims.",description:"Coverbase connects to a vendor's application with read-only access and inspects the live environment: security settings, access controls, and integrations. Findings land in the risk profile as verified evidence.",problemText:"Questionnaires are self-attested and go stale as configurations drift. Misconfiguration is a leading cause of breaches, and OAuth integration sprawl hides risk no questionnaire captures.",solutionText:"Coverbase inspects the real thing. With read-only access, an AI agent walks the vendor's environment the way an analyst would, checking MFA, access sprawl, public exposure, and connected integrations. It writes scored findings straight into the vendor's risk profile, so you verify the control instead of trusting the claim. (This is sometimes called SaaS security posture management; we call it inspection.)"},capabilities:{label:"In this category",title:"The solutions behind it",subtitle:"Coverbase Inspect verifies live configuration; Fourth-Party Monitoring extends visibility down the software supply chain.",items:[u,h]},benefits:{label:"Benefits",title:"Why teams inspect with Coverbase",items:[{icon:"/icon-images/scan.png",title:"Verified, not attested",description:"Evidence from the live environment, not a self-report."},{icon:"/icon-images/shield.png",title:"Access and config checks",description:"MFA, permissions, exposure, and integrations inspected."},{icon:"/icon-images/search.png",title:"Findings that matter",description:"AI triages misconfigurations against your controls."},{icon:"/icon-images/cycle.png",title:"Continuous re-checks",description:"Catch configuration drift between reviews."}]}}},g=[...["third-party-risk-management","intake-to-procure","contract-lifecycle-management","application-security-inspection"].map(e=>{let t=m[e];return{title:t.navTitle,href:`/solutions/${t.slug}`,description:t.navDescription,items:t.capabilities.items.map(e=>({title:e.title,href:e.href,description:e.description}))}}),{title:"MCP & In-App Agents",href:"/solutions/mcp-in-app-agents",description:"Bring Coverbase agents into the tools you already use",items:[]},{title:"Managed Services",href:"/solutions/managed-tprm-services",description:"Fully managed TPRM with human experts",items:[]}],v=[{title:"Elevate Your Team",href:"/why-coverbase/elevate-your-team",description:"Empower your procurement team with AI tools"},{title:"Prioritize Safety",href:"/why-coverbase/prioritize-safety",description:"Built-in security and compliance features"},{title:"Control The AI",href:"/why-coverbase/control-the-ai",description:"Maintain full control over AI decision-making"},{title:"Unify Your Data",href:"/why-coverbase/unify-your-data",description:"Centralize all procurement data in one platform"},{title:"Integrate Everything",href:"/why-coverbase/integrations",description:"Connect every system into one single pane of glass"}],y=[{title:"Content Library",href:"/content-library",description:"Articles, guides, and best practices"},{title:"Third Party Incident Briefings",href:"/resources/third-party-incident-briefings",description:"Monthly third-party incidents that matter"},{title:"Build vs Buy Calculator",href:"/build-vs-buy/calculator",description:"Estimate the cost of building TPRM in-house"},{title:"Documentation",href:"https://docs.coverbase.com",description:"Product docs and API reference",external:!0}],f=[{label:"By Industry",items:["financial-institutions","community-banks","regional-banks","credit-unions","sponsor-banks","asset-managers","insurance","healthcare","biotech","technology-firms","legal-firms","higher-education","transportation","food-distributors"].map(e=>{let t=d[e];return{title:t.navTitle,href:`/resources/${t.slug}`,description:t.navDescription}})},{label:"By Regulation",items:["dora","nis2","interagency-guidance","ncua","
1nydfs-500","glba-safeguards","fedramp","cmmc","sec-cyber-disclosure","hipaa","pci-dss","iso-27001","soc-2","nist-csf"].map(e=>{let t=p[e];return{title:t.navTitle,href:`/resources/regulations/${t.slug}`,description:t.navDescription}})}],b=[{title:"Security & Privacy",href:"/company/security-and-privacy",description:"Our commitment to data security"},{title:"About Us",href:"/company/about-us",description:"Learn about our mission and team"},{title:"Partnerships",href:"/company/partnerships",description:"How we build with advisors and platforms"},{title:"Careers",href:"/careers",description:"Join our growing team"}];function w(e){let t,i,r,s=(0,a.c)(9),{label:c,isExpanded:l,isDark:d,onToggle:p}=e,u=`text-base leading-6 ${d?"text-white":"text-gray-900"} ${l?"font-medium":"font-normal"}`;s[0]!==c||s[1]!==u?(t=(0,n.jsx)("span",{className:u,children:c}),s[0]=c,s[1]=u,s[2]=t):t=s[2];let h=`h-5 w-5 transition-transform duration-300 ${d?"text-white":"text-gray-900"} ${l?"rotate-180":""}`;return s[3]!==h?(i=(0,n.jsx)(o.ChevronDown,{className:h}),s[3]=h,s[4]=i):i=s[4],s[5]!==p||s[6]!==t||s[7]!==i?(r=(0,n.jsxs)("button",{type:"button",onClick:p,className:"flex w-full items-center justify-between text-left",children:[t,i]}),s[5]=p,s[6]=t,s[7]=i,s[8]=r):r=s[8],r}function C(e){let t,i,r,o,c=(0,a.c)(19),{item:l,isDark:d,onClose:p}=e,u=`flex flex-col gap-1 rounded-lg p-3 active:opacity-70 ${d?"bg-white/8":"bg-gray-100"}`,h=`text-sm leading-5.5 ${d?"text-white":"text-gray-900"}`;c[0]!==l.title||c[1]!==h?(t=(0,n.jsx)("span",{className:h,children:l.title}),c[0]=l.title,c[1]=h,c[2]=t):t=c[2];let m=`text-sm leading-5 ${d?"text-white/70":"text-gray-900/70"}`;c[3]!==l.description||c[4]!==m?(i=(0,n.jsx)("span",{className:m,children:l.description}),c[3]=l.description,c[4]=m,c[5]=i):i=c[5],c[6]!==t||c[7]!==i?(r=(0,n.jsxs)(n.Fragment,{children:[t,i]}),c[6]=t,c[7]=i,c[8]=r):r=c[8];let g=r;if(l.external){let e;return c[9]!==g||c[10]!==u||c[11]!==l.href||c[12]!==p?(e=(0,n.jsx)("a",{href:l.href,target:"_blank",rel:"noopener noreferrer",suppressHydrationWarning:!0,className:u,onClick:p,children:g}),c[9]=g,c[10]=u,c[11]=l.href,c[12]=p,c[13]=e):e=c[13],e}return c[14]!==g||c[15]!==u||c[16]!==l.href||c[17]!==p?(o=(0,n.jsx)(s.default,{href:l.href,className:u,onClick:p,children:g}),c[14]=g,c[15]=u,c[16]=l.href,c[17]=p,c[18]=o):o=c[18],o}function k(e){let t,i,r,o=(0,a.c)(13),{label:s,items:c,isDark:l,isExpanded:d,onToggle:p,onClose:u}=e;return o[0]!==l||o[1]!==d||o[2]!==s||o[3]!==p?(t=(0,n.jsx)(w,{label:s,isExpanded:d,isDark:l,onToggle:p}),o[0]=l,o[1]=d,o[2]=s,o[3]=p,o[4]=t):t=o[4],o[5]!==l||o[6]!==d||o[7]!==c||o[8]!==u?(i=d&&(0,n.jsx)("div",{className:"flex flex-col gap-2",children:c.map(e=>(0,n.jsx)(C,{item:e,isDark:l,onClose:u},e.title))}),o[5]=l,o[6]=d,o[7]=c,o[8]=u,o[9]=i):i=o[9],o[10]!==t||o[11]!==i?(r=(0,n.jsxs)("div",{className:"flex flex-col gap-2",children:[t,i]}),o[10]=t,o[11]=i,o[12]=r):r=o[12],r}function S(e){let t,i,r,o=(0,a.c)(11),{isDark:c,isExpanded:l,onToggle:d,onClose:p}=e;return o[0]!==c||o[1]!==l||o[2]!==d?(t=(0,n.jsx)(w,{label:"Solutions",isExpanded:l,isDark:c,onToggle:d}),o[0]=c,o[1]=l,o[2]=d,o[3]=t):t=o[3],o[4]!==c||o[5]!==l||o[6]!==p?(i=l&&(0,n.jsx)("div",{className:"flex flex-col gap-3",children:g.map(e=>(0,n.jsxs)("div",{className:"flex flex-col gap-2",children:[(0,n.jsx)(s.default,{href:e.href,onClick:p,className:`text-sm font-medium ${c?"text-white":"text-gray-900"}`,children:e.title}),(0,n.jsx)("div",{className:"grid grid-cols-2 gap-2",children:e.items.map(e=>(0,n.jsx)(s.default,{href:e.href,onClick:p,className:`rounded-lg px-3 py-2 text-sm active:opacity-70 ${c?"bg-white/8 text-white":"bg-gray-100 text-gray-900"}`,children:e.title},e.href))})]},e.title))}),o[4]=c,o[5]=l,o[6]=p,o[7]=i):i=o[7],o[8]!==t||o[9]!==i?(r=(0,n.jsxs)("div",{className:"flex flex-col gap-2",children:[t,i]}),o[8]=t,o[9]=i,o[10]=r):r=o[10],r}function A(e){let t,i,r,o=(0,a.c)(11),{isDark:c,isExpanded:l,onToggle:d,onClose:p}=e;return o[0]!==c||o[1]!==l||o[2]!==d?(t=(0,n.jsx)(w,{label:"Resources",isExpanded:l,isDark:c,onToggle:d}),o[0]=c,o[1]=l,o[2]=d,o[3]=t):t=o[3],o[4]!==c||o[5]!==l||o[6]!==p?(i=l&&(0,n.jsxs)("div",{className:"flex flex-col gap-3",children:[(0,n.jsx)("div",{className:"flex flex-col gap-2",children:y.map(e=>(0,n.jsx)(C,{item:e,isDark:c,onClose:p},e.title))}),f.map(e=>(0,n.jsxs)("div",{className:"flex flex-col gap-2",children:[(0,n.jsx)("span",{className:`text-xs font-medium tracking-wider up
1percase ${c?"text-white/50":"text-gray-900/50"}`,children:e.label}),(0,n.jsx)("div",{className:"grid grid-cols-2 gap-2",children:e.items.map(e=>(0,n.jsx)(s.default,{href:e.href,onClick:p,className:`rounded-lg px-3 py-2 text-sm active:opacity-70 ${c?"bg-white/8 text-white":"bg-gray-100 text-gray-900"}`,children:e.title},e.title))})]},e.label))]}),o[4]=c,o[5]=l,o[6]=p,o[7]=i):i=o[7],o[8]!==t||o[9]!==i?(r=(0,n.jsxs)("div",{className:"flex flex-col gap-2",children:[t,i]}),o[8]=t,o[9]=i,o[10]=r):r=o[10],r}e.s(["companyItems",0,b,"resourcesGroups",0,f,"resourcesPrimaryItems",0,y,"solutionsSections",0,g,"whyCoverbaseItems",0,v],362028),e.s(["MobileMenu",0,function(e){let t,i,r,o,d,p,u,h,m,g,y,f,w,C,x=(0,a.c)(28),{isDark:T,onClose:I}=e,[D,P]=(0,c.useState)(null);x[0]!==D?(t=e=>{P(D===e?null:e)},x[0]=D,x[1]=t):t=x[1];let R=t;x[2]===Symbol.for("react.memo_cache_sentinel")?(i=[],x[2]=i):i=x[2],x[3]===Symbol.for("react.memo_cache_sentinel")?(r={label:"Solutions",key:"solutions",items:i},o={label:"Why Coverbase",key:"why",items:v},x[3]=r,x[4]=o):(r=x[3],o=x[4]),x[5]===Symbol.for("react.memo_cache_sentinel")?(d=[],x[5]=d):d=x[5],x[6]===Symbol.for("react.memo_cache_sentinel")?(p=[r,o,{label:"Resources",key:"resources",items:d},{label:"Company",key:"company",items:b}],x[6]=p):p=x[6];let M=p,O=`absolute top-full right-0 left-0 z-50 max-h-[calc(100vh-120px)] overflow-y-auto rounded-b-lg shadow-[20px_20px_40px_0px_rgba(0,50,137,0.1),-20px_-20px_40px_0px_rgba(0,119,255,0.1)] lg:hidden ${T?"bg-gray-900":"bg-white"}`;x[7]!==D||x[8]!==T||x[9]!==I||x[10]!==R?(u=M.map((e,t)=>(0,n.jsxs)("div",{children:["solutions"===e.key?(0,n.jsx)(S,{isDark:T,isExpanded:D===e.key,onToggle:()=>R(e.key),onClose:I}):"resources"===e.key?(0,n.jsx)(A,{isDark:T,isExpanded:D===e.key,onToggle:()=>R(e.key),onClose:I}):(0,n.jsx)(k,{label:e.label,items:e.items,isDark:T,isExpanded:D===e.key,onToggle:()=>R(e.key),onClose:I}),t<M.length-1&&(0,n.jsx)("div",{className:`mt-4 h-px ${T?"bg-gray-800":"bg-gray-200"}`})]},e.key)),x[7]=D,x[8]=T,x[9]=I,x[10]=R,x[11]=u):u=x[11];let F=`h-px ${T?"bg-gray-800":"bg-gray-200"}`;x[12]!==F?(h=(0,n.jsx)("div",{className:F}),x[12]=F,x[13]=h):h=x[13];let N=`text-base leading-6 ${T?"text-white":"text-gray-900"}`;return x[14]!==N?(m=(0,n.jsx)("a",{href:"https://dashboard.coverbase.app/",target:"_blank",rel:"noopener noreferrer",suppressHydrationWarning:!0,className:N,children:"Sign In"}),x[14]=N,x[15]=m):m=x[15],x[16]===Symbol.for("react.memo_cache_sentinel")?(g=(0,n.jsx)("span",{children:"Book a demo"}),y=(0,n.jsx)(l.ArrowRightIcon,{className:"relative top-px h-[18px] w-[18px]"}),x[16]=g,x[17]=y):(g=x[16],y=x[17]),x[18]!==I?(f=(0,n.jsxs)(s.default,{href:"/contact",className:"flex w-full items-center justify-center gap-1.5 rounded-md bg-linear-to-b from-blue-700 to-blue-800 px-4 py-3 text-base font-medium text-white shadow-[0px_1px_4px_0px_rgba(24,55,236,0.32),0px_1px_1px_0px_rgba(0,12,72,0.2),0px_0px_0px_0.5px_rgba(24,55,236,0.16)]",onClick:I,children:[g,y]}),x[18]=I,x[19]=f):f=x[19],x[20]!==h||x[21]!==m||x[22]!==f||x[23]!==u?(w=(0,n.jsxs)("div",{className:"flex flex-col gap-4 p-4",children:[u,h,m,f]}),x[20]=h,x[21]=m,x[22]=f,x[23]=u,x[24]=w):w=x[24],x[25]!==w||x[26]!==O?(C=(0,n.jsx)("div",{className:O,children:w}),x[25]=w,x[26]=O,x[27]=C):C=x[27],C}],252080)}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.