Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Coverbase is a third-party risk and procurement platform. These docs cover both sides of it: using the product, and building against it.

Use the product

Screen-by-screen guides for setting up Coverbase and running it day to day. Start here if you have the product open in another tab.

Build an integration

Authentication, the REST API, import and export, webhooks, workflows and the MCP server. Start here if you are moving data in or out.

Evaluate the platform

Compliance posture, identity and access, data protection, regulatory alignment, service levels and contract terms. Start here if you are reviewing Coverbase as a vendor.

If you are new to Coverbase

Three guides cover most people. Read the one that matches your job, then use the user guides directory to find the rest.

I am setting up Coverbase

Import vendors, build the intake questionnaire, tune scales and control sets, then set roles, templates and monitoring.

I run vendor risk day to day

Triage requests, launch assessments, review what the AI found, follow up with vendors, and close the loop.

I need a tool approved

The short one. What you will be asked, how to file the request, and what happens next.

Guides by area

The user guides follow the left navigation in the product, so the group a screen sits in is the group its guide sits in.

Vendors

The vendor record, services and engagements, subprocessors, supplier bank and tax details with a country reference, and the centralized supplier portal.

Assessments

The full assessment walkthrough, the quick reference, questionnaires, the IRQ library, evidence quality, and Zero Touch.

Findings and obligations

What happens after an issue becomes a finding, vendor commitments, and the obligations your organization takes on.

Vendor intelligence

Registrations, people, financial health, security rating and sanctions screening, all assembled without contacting the vendor.

Monitoring and risk

Working Radar signals, feeding in a Black Kite portfolio, vendor bills of materials, breach notification filings, the risk register, and the supplier geography map.

Contracts and e-signature

The contracts workspace, intake and approval, the repository, clause review with Contract Guardian, negotiation rounds, and signing.

Documents

Document Insights, asking your documents a question, and expiry reminders.

Workflows and reporting

Ready-to-run workflow templates, building your own, the dashboard library, and Word report templates.

Sourcing and internal controls

Running an RFP end to end, and inspecting your own applications with Inspect.

Building on Coverbase

Three integration surfaces. Each works on its own, and you can combine them.

Export API

Pull vendor, assessment and control data out of Coverbase into your dashboards, BI tools and remediation workflows.

Import API

Push vendor, assessment and service data in from your ERP, CMDB, legacy GRC platform or service catalog.

MCP server

Connect Claude, Cursor or any MCP client and work with your TPRM program through conversation.
1

Get an API key

Ask a Coverbase admin in your organization to provision one. See API keys.
2

Store it properly

Keep it in a secrets manager. Never commit a key to source control or embed it in client-side code.
3

Test the connection

Call /v1/utils/authtest with your bearer token to check connectivity, key validity and firewall rules before wiring anything up. The authentication page has the request.
4

Read the concepts page for your surface

Then jump to the reference for the endpoints you need. The API conventions page covers IDs, timestamps, idempotency, pagination and the error envelope shared by every endpoint.

Base URL

https://api.coverbase.app

Format

REST, JSON over HTTPS, encrypted in transit.

If you are evaluating Coverbase

The answers a third-party risk team, a procurement team or an examiner asks for, each on its own page.

Regulatory alignment

How the platform maps to the 2023 Interagency Guidance on Third-Party Relationships, the Interagency Guidelines Establishing Information Security Standards, FFIEC, GLBA, DORA and NCUA.

Reviews, approvals and gates

Configurable gate outcomes, parallel domain-scoped SME reviews, multi-approver and threshold logic, and rework loops with reasons, comments and round counts.

Identity and access

SAML 2.0 SSO inheriting your IdP’s MFA and conditional access, just-in-time provisioning, IGA-driven lifecycle, RBAC and network restriction.

Service levels and support

The P0 to P3 severity ladder with response clocks, the timed escalation path, and the 99.9% uptime commitment.

Contract terms and exit

Incident notification, data return and destruction, renewal and notice, subprocessors, and the diligence package.

Evidence packaging

Producing the complete due-diligence file for one third party, and assembling an examination package.

What else is here

What each product does

A page per capability, from Autonomous Intake to internal controls monitoring, grouped by area under Get started.

Control Set library

Every packaged control set: the vendor frameworks to assess a third party against, and the internal sets Inspect evaluates.

Field reference

Every filterable field, its path, and where it comes from. The same paths drive saved views, workflow conditions and the query API.

Integration workflows

Platform-specific guides for ServiceNow, Jira, Slack, OneTrust, DocuSign and more.

Need help?

Product support

Security issues

Book a meeting

Talk to our team about your rollout or your integration.