For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Coverbase is a third-party risk and procurement platform. These docs cover both sides of it: using the product, and building against it.
Use the product
Screen-by-screen guides for setting up Coverbase and running it day to day. Start here if you have the product open in another tab.
Build an integration
Authentication, the REST API, import and export, webhooks, workflows and the MCP server. Start here if you are moving data in or out.
Evaluate the platform
Compliance posture, identity and access, data protection, regulatory alignment, service levels and contract terms. Start here if you are reviewing Coverbase as a vendor.
If you are new to Coverbase
Three guides cover most people. Read the one that matches your job, then use the user guides directory to find the rest.I am setting up Coverbase
Import vendors, build the intake questionnaire, tune scales and control sets, then set roles, templates and monitoring.
I run vendor risk day to day
Triage requests, launch assessments, review what the AI found, follow up with vendors, and close the loop.
I need a tool approved
The short one. What you will be asked, how to file the request, and what happens next.
Guides by area
The user guides follow the left navigation in the product, so the group a screen sits in is the group its guide sits in.Vendors
The vendor record, services and engagements, subprocessors, supplier bank and tax details with a country reference, and the centralized supplier portal.
Assessments
The full assessment walkthrough, the quick reference, questionnaires, the IRQ library, evidence quality, and Zero Touch.
Findings and obligations
What happens after an issue becomes a finding, vendor commitments, and the obligations your organization takes on.
Vendor intelligence
Registrations, people, financial health, security rating and sanctions screening, all assembled without contacting the vendor.
Monitoring and risk
Working Radar signals, feeding in a Black Kite portfolio, vendor bills of materials, breach notification filings, the risk register, and the supplier geography map.
Contracts and e-signature
The contracts workspace, intake and approval, the repository, clause review with Contract Guardian, negotiation rounds, and signing.
Documents
Document Insights, asking your documents a question, and expiry reminders.
Workflows and reporting
Ready-to-run workflow templates, building your own, the dashboard library, and Word report templates.
Sourcing and internal controls
Running an RFP end to end, and inspecting your own applications with Inspect.
Building on Coverbase
Three integration surfaces. Each works on its own, and you can combine them.Export API
Pull vendor, assessment and control data out of Coverbase into your dashboards, BI tools and remediation workflows.
Import API
Push vendor, assessment and service data in from your ERP, CMDB, legacy GRC platform or service catalog.
MCP server
Connect Claude, Cursor or any MCP client and work with your TPRM program through conversation.
1
Get an API key
Ask a Coverbase admin in your organization to provision one. See API keys.
2
Store it properly
Keep it in a secrets manager. Never commit a key to source control or embed it in client-side code.
3
Test the connection
Call
/v1/utils/authtest with your bearer token to check connectivity, key validity and firewall rules before wiring anything up. The authentication page has the request.4
Read the concepts page for your surface
Then jump to the reference for the endpoints you need. The API conventions page covers IDs, timestamps, idempotency, pagination and the error envelope shared by every endpoint.
Base URL
https://api.coverbase.appFormat
REST, JSON over HTTPS, encrypted in transit.
If you are evaluating Coverbase
The answers a third-party risk team, a procurement team or an examiner asks for, each on its own page.Regulatory alignment
How the platform maps to the 2023 Interagency Guidance on Third-Party Relationships, the Interagency Guidelines Establishing Information Security Standards, FFIEC, GLBA, DORA and NCUA.
Reviews, approvals and gates
Configurable gate outcomes, parallel domain-scoped SME reviews, multi-approver and threshold logic, and rework loops with reasons, comments and round counts.
Identity and access
SAML 2.0 SSO inheriting your IdP’s MFA and conditional access, just-in-time provisioning, IGA-driven lifecycle, RBAC and network restriction.
Service levels and support
The P0 to P3 severity ladder with response clocks, the timed escalation path, and the 99.9% uptime commitment.
Contract terms and exit
Incident notification, data return and destruction, renewal and notice, subprocessors, and the diligence package.
Evidence packaging
Producing the complete due-diligence file for one third party, and assembling an examination package.
What else is here
What each product does
A page per capability, from Autonomous Intake to internal controls monitoring, grouped by area under Get started.
Control Set library
Every packaged control set: the vendor frameworks to assess a third party against, and the internal sets Inspect evaluates.
Field reference
Every filterable field, its path, and where it comes from. The same paths drive saved views, workflow conditions and the query API.
Integration workflows
Platform-specific guides for ServiceNow, Jira, Slack, OneTrust, DocuSign and more.
Need help?
Product support
Security issues
Book a meeting
Talk to our team about your rollout or your integration.