# Coverbase Docs > Documentation for the Coverbase third-party risk and procurement platform: step-by-step user guides for the product, and the API, integration and MCP reference for building on it. - [Coverbase documentation](https://docs.coverbase.com/index.md): Guides for using the Coverbase third-party risk and procurement platform, and the API, integration and MCP reference for building on it. - [Authentication](https://docs.coverbase.com/quickstart.md): All Coverbase API requests are authenticated with a bearer token over HTTPS. - [API conventions](https://docs.coverbase.com/conventions.md): Authentication, base URLs, IDs, timestamps, idempotency, pagination, and the error envelope shared by all endpoints. - [Changelog](https://docs.coverbase.com/changelog.md): Notable changes to the Coverbase public API documentation. - [User guides](https://docs.coverbase.com/user-guides/overview.md): Every Coverbase how-to guide in one directory: setup, intake, assessments, vendor intelligence, monitoring, contracts, e-signature, RFPs, and supplier information. - [Requesting a new vendor](https://docs.coverbase.com/user-guides/requesting-a-vendor.md): The requester's side of vendor intake: what you'll be asked, how to file a request in the portal or in chat, and what happens after you submit. - [Analyst and reviewer guide](https://docs.coverbase.com/user-guides/analyst-reviewer.md): The day-to-day of vendor risk in Coverbase: triage intake, launch assessments, review and correct AI findings, follow up with vendors, and close the loop. - [Admin and setup guide](https://docs.coverbase.com/user-guides/admin-setup.md): Stand up your Coverbase environment from scratch: vendors, tags, questionnaires, scales, control sets, templates, monitoring, and integrations. - [Configuring your data model](https://docs.coverbase.com/user-guides/data-model-configuration.md): What an admin can change in Coverbase without a professional-services engagement: custom fields on nine object types, statuses, approval options, risk scales, risk domains, tags, terminology, relationships, control sets, and automations. - [Permissions and roles](https://docs.coverbase.com/user-guides/permissions-and-roles.md): How access works in Coverbase: the six default roles, how a permission is built from a resource, an action and a scope, and how to build and assign a custom role. - [Assignment, delegation and out of office](https://docs.coverbase.com/user-guides/assignment-and-delegation.md): How work reaches a person in Coverbase: user groups, round-robin and assign-to-all routing, out-of-office windows that skip a member automatically, reassignment, and the assignment log that attributes every hand-off. - [Reviews, approvals and gates](https://docs.coverbase.com/user-guides/reviews-and-approvals.md): How review gates work in Coverbase: configurable outcomes including approve with finding, policy exception and return for rework; parallel domain-scoped SME reviews; multi-approver logic; and rework loops with reasons, comments and round counts. - [Email and notifications](https://docs.coverbase.com/user-guides/email-notifications.md): Every email Coverbase sends, who gets it, and how to change how it looks. Covers the notification catalog, per-person delivery settings, email layouts, and applying your own branding. - [White-labeling your vendor-facing domain](https://docs.coverbase.com/user-guides/white-labeling.md): Send vendor emails and host the portal on your own subdomain instead of coverbase.ai and coverbase.app, and choose between Coverbase-managed and organization-managed DNS. - [Dashboards and the chart library](https://docs.coverbase.com/user-guides/dashboard-library.md): The ten dashboards and 76 charts Coverbase ships ready to use: what each one shows, who it is built for, and how to put them on a dashboard of your own. - [The IRQ library](https://docs.coverbase.com/user-guides/irq-library.md): The six inherent risk questionnaires Coverbase ships: every question each one asks, how the score is calculated, and how to pick and tailor the right starting point. - [How to run an assessment](https://docs.coverbase.com/user-guides/running-an-assessment.md): A step-by-step walkthrough of the full assessment lifecycle, from getting the vendor into Coverbase to exporting the final report. - [Assessment quick reference](https://docs.coverbase.com/user-guides/assessment-quick-reference.md): A one-page cheat sheet for running a vendor risk assessment in Coverbase: five steps, tips, common scenarios, and troubleshooting. - [Evidence quality and source credibility](https://docs.coverbase.com/user-guides/evidence-quality.md): How Coverbase grades the credibility of web evidence, where you set the minimum bar, and how that changes what the AI is allowed to cite in an assessment. - [Zero Touch Assessment guide](https://docs.coverbase.com/user-guides/zero-touch-assessments.md): How to run a lightweight, no-outreach assessment across a portfolio of vendors, read the score it produces, and decide which vendors are worth a full review. - [Corporate registrations guide](https://docs.coverbase.com/user-guides/corporate-registrations.md): How to read the registry validation on a vendor, what a match decision means, and what to do when nothing matched. - [People intelligence guide](https://docs.coverbase.com/user-guides/people-intelligence.md): How to read the leadership dossier on a vendor, what confirmed and unconfirmed mean, and how to treat an adverse-media finding. - [Financial health guide](https://docs.coverbase.com/user-guides/financial-health-score.md): How to read a vendor's Financial Health Score, what the confidence tier tells you, and how private companies with no filings are scored. - [Security intelligence guide](https://docs.coverbase.com/user-guides/security-intelligence.md): How to read a vendor's outside-in security rating, what each factor measures, and what a not-measured factor does and does not tell you. - [Sanctions screening guide](https://docs.coverbase.com/user-guides/sanctions-screening.md): How continuous sanctions and watchlist screening works, how to read an identity confidence score, and how to clear a match without guessing. - [Financial health and security intelligence guide](https://docs.coverbase.com/user-guides/vendor-fact-sheet.md): How to read the Financial Health Score and Security Posture cards in a vendor's Vendor Intelligence section, what each number is actually claiming, and what to do about what you find. - [Black Kite monitoring guide](https://docs.coverbase.com/user-guides/black-kite-monitoring.md): How to connect your Black Kite portfolio to Radar, choose which vendors are watched, and turn known exploited vulnerabilities and focus tags into alerts. - [Risk geography map](https://docs.coverbase.com/user-guides/risk-geography-map.md): See where your suppliers are on a world map, narrowed by the same vendor filters you use on the vendor list. - [Contracts workspace](https://docs.coverbase.com/user-guides/contracts-workspace.md): How to read the contracts list page and the contract record: the key statistics row, the renewal runway, and the cards on a contract. - [Contract components](https://docs.coverbase.com/user-guides/contract-components.md): What each contract component means, how Coverbase decides a document carries it, which contract fields it is allowed to answer, and what happens when two documents claim the same one. - [Contract dates and reminders](https://docs.coverbase.com/user-guides/contract-dates-and-reminders.md): How the contract timeline works: which dates Coverbase tracks, which ones it calculates for you, who gets the reminder emails, and how to turn a reminder off for a single contract. - [Contract Guardian guide](https://docs.coverbase.com/user-guides/contract-guardian.md): Set up and run Contract Guardian: build a clause set from the library or your own paper, write risk-tier variants, run clause reviews, decide each flagged clause, and export a redlined Word file for the vendor. - [Negotiation rounds](https://docs.coverbase.com/user-guides/contract-negotiation-rounds.md): Upload the marked-up contract a vendor sends back, see what they changed, which of your asks they accepted, and what they edited without being asked, without starting the clause review over. - [The clause set library](https://docs.coverbase.com/user-guides/clause-set-library.md): The 12 packaged clause standards Coverbase ships: what each one covers, how many clauses it carries, how to pick the right starting point, and what changes the moment you copy one. - [Generate a clause set from your own contract](https://docs.coverbase.com/user-guides/baseline-contract-extraction.md): Upload your template MSA or DPA and let Coverbase extract a clause set from it: what it pulls out, why it drops language it can't quote, and what you must add before the set is usable. - [Import and export clause sets as spreadsheets](https://docs.coverbase.com/user-guides/clause-set-spreadsheet-import.md): Build a clause set in Excel and upload it, or export one back out: the workbook format, every column explained, what happens on re-upload, and how to read the import result. - [E-signature overview](https://docs.coverbase.com/user-guides/signature-overview.md): How Coverbase gets an agreement signed: the template you build once, the envelope you send from it, what the counterparty sees, and the sealed copy and audit trail you keep afterwards. - [Signature templates](https://docs.coverbase.com/user-guides/signature-templates.md): Build the paper you send repeatedly once: the source document, the signing parties as roles, and the fields each role fills. Then publish it, send from it, and version it when the wording changes. - [Sending for signature](https://docs.coverbase.com/user-guides/signature-envelopes.md): Create an envelope from a template or a document, name who signs and in what order, send it, and track it to a sealed executed copy with a hash-chained audit trail. - [The signing experience](https://docs.coverbase.com/user-guides/signature-signing-experience.md): What your counterparty sees when they open a signing link: consent, the document, adopting a signature once for every block, and the executed copy they keep. Plus how to brand it as yours. - [Document expiry reminders](https://docs.coverbase.com/user-guides/document-expiry-reminders.md): How Coverbase reminds you before a vendor document lapses: which dates it fires from, who receives the email, and where to see everything that is expiring. - [Document Insights guide](https://docs.coverbase.com/user-guides/document-insights.md): Define the fields Coverbase pulls out of every document: how to write an insight, when to use Extract vs Synthesize, a starter library you can copy, and how to check the results. - [Asking your documents a question](https://docs.coverbase.com/user-guides/document-evidence-pull.md): Ask a plain-English question in chat and get back the passage from a vendor's documents that answers it: the verbatim quote, its page, a cropped image of the highlighted passage, and a link that opens the document on that page with the passage marked. - [How to run an RFP](https://docs.coverbase.com/user-guides/running-an-rfp.md): A step-by-step walkthrough of the RFP lifecycle: draft one with the AI wizard, compare the field without contacting anyone, score against your rubric, and record the decision. - [Supplier information guide](https://docs.coverbase.com/user-guides/supplier-information.md): How supplier bank details, addresses, tax registrations and diversity records are collected, checked against the rules for the supplier's country, reviewed, and handed to your finance system. - [Supplier countries](https://docs.coverbase.com/user-guides/supplier-countries/overview.md): What Coverbase asks a supplier for in each of the countries it validates. - [Albania](https://docs.coverbase.com/user-guides/supplier-countries/al.md): What Coverbase asks a supplier in Albania for, and which of those rules block a submission. - [Algeria](https://docs.coverbase.com/user-guides/supplier-countries/dz.md): What Coverbase asks a supplier in Algeria for, and which of those rules block a submission. - [Andorra](https://docs.coverbase.com/user-guides/supplier-countries/ad.md): What Coverbase asks a supplier in Andorra for, and which of those rules block a submission. - [Argentina](https://docs.coverbase.com/user-guides/supplier-countries/ar.md): What Coverbase asks a supplier in Argentina for, and which of those rules block a submission. - [Australia](https://docs.coverbase.com/user-guides/supplier-countries/au.md): What Coverbase asks a supplier in Australia for, and which of those rules block a submission. - [Austria](https://docs.coverbase.com/user-guides/supplier-countries/at.md): What Coverbase asks a supplier in Austria for, and which of those rules block a submission. - [Azerbaijan](https://docs.coverbase.com/user-guides/supplier-countries/az.md): What Coverbase asks a supplier in Azerbaijan for, and which of those rules block a submission. - [Bahrain](https://docs.coverbase.com/user-guides/supplier-countries/bh.md): What Coverbase asks a supplier in Bahrain for, and which of those rules block a submission. - [Belarus](https://docs.coverbase.com/user-guides/supplier-countries/by.md): What Coverbase asks a supplier in Belarus for, and which of those rules block a submission. - [Belgium](https://docs.coverbase.com/user-guides/supplier-countries/be.md): What Coverbase asks a supplier in Belgium for, and which of those rules block a submission. - [Bosnia and Herzegovina](https://docs.coverbase.com/user-guides/supplier-countries/ba.md): What Coverbase asks a supplier in Bosnia and Herzegovina for, and which of those rules block a submission. - [Brazil](https://docs.coverbase.com/user-guides/supplier-countries/br.md): What Coverbase asks a supplier in Brazil for, and which of those rules block a submission. - [British Virgin Islands](https://docs.coverbase.com/user-guides/supplier-countries/vg.md): What Coverbase asks a supplier in British Virgin Islands for, and which of those rules block a submission. - [Bulgaria](https://docs.coverbase.com/user-guides/supplier-countries/bg.md): What Coverbase asks a supplier in Bulgaria for, and which of those rules block a submission. - [Canada](https://docs.coverbase.com/user-guides/supplier-countries/ca.md): What Coverbase asks a supplier in Canada for, and which of those rules block a submission. - [Chile](https://docs.coverbase.com/user-guides/supplier-countries/cl.md): What Coverbase asks a supplier in Chile for, and which of those rules block a submission. - [China](https://docs.coverbase.com/user-guides/supplier-countries/cn.md): What Coverbase asks a supplier in China for, and which of those rules block a submission. - [Colombia](https://docs.coverbase.com/user-guides/supplier-countries/co.md): What Coverbase asks a supplier in Colombia for, and which of those rules block a submission. - [Costa Rica](https://docs.coverbase.com/user-guides/supplier-countries/cr.md): What Coverbase asks a supplier in Costa Rica for, and which of those rules block a submission. - [Croatia](https://docs.coverbase.com/user-guides/supplier-countries/hr.md): What Coverbase asks a supplier in Croatia for, and which of those rules block a submission. - [Cyprus](https://docs.coverbase.com/user-guides/supplier-countries/cy.md): What Coverbase asks a supplier in Cyprus for, and which of those rules block a submission. - [Czech Republic](https://docs.coverbase.com/user-guides/supplier-countries/cz.md): What Coverbase asks a supplier in Czech Republic for, and which of those rules block a submission. - [Côte d'Ivoire](https://docs.coverbase.com/user-guides/supplier-countries/ci.md): What Coverbase asks a supplier in Côte d'Ivoire for, and which of those rules block a submission. - [Denmark](https://docs.coverbase.com/user-guides/supplier-countries/dk.md): What Coverbase asks a supplier in Denmark for, and which of those rules block a submission. - [Dominican Republic](https://docs.coverbase.com/user-guides/supplier-countries/do.md): What Coverbase asks a supplier in Dominican Republic for, and which of those rules block a submission. - [Egypt](https://docs.coverbase.com/user-guides/supplier-countries/eg.md): What Coverbase asks a supplier in Egypt for, and which of those rules block a submission. - [El Salvador](https://docs.coverbase.com/user-guides/supplier-countries/sv.md): What Coverbase asks a supplier in El Salvador for, and which of those rules block a submission. - [Estonia](https://docs.coverbase.com/user-guides/supplier-countries/ee.md): What Coverbase asks a supplier in Estonia for, and which of those rules block a submission. - [Faroe Islands](https://docs.coverbase.com/user-guides/supplier-countries/fo.md): What Coverbase asks a supplier in Faroe Islands for, and which of those rules block a submission. - [Finland](https://docs.coverbase.com/user-guides/supplier-countries/fi.md): What Coverbase asks a supplier in Finland for, and which of those rules block a submission. - [France](https://docs.coverbase.com/user-guides/supplier-countries/fr.md): What Coverbase asks a supplier in France for, and which of those rules block a submission. - [French Guiana](https://docs.coverbase.com/user-guides/supplier-countries/gf.md): What Coverbase asks a supplier in French Guiana for, and which of those rules block a submission. - [Georgia](https://docs.coverbase.com/user-guides/supplier-countries/ge.md): What Coverbase asks a supplier in Georgia for, and which of those rules block a submission. - [Germany](https://docs.coverbase.com/user-guides/supplier-countries/de.md): What Coverbase asks a supplier in Germany for, and which of those rules block a submission. - [Ghana](https://docs.coverbase.com/user-guides/supplier-countries/gh.md): What Coverbase asks a supplier in Ghana for, and which of those rules block a submission. - [Gibraltar](https://docs.coverbase.com/user-guides/supplier-countries/gi.md): What Coverbase asks a supplier in Gibraltar for, and which of those rules block a submission. - [Greece](https://docs.coverbase.com/user-guides/supplier-countries/gr.md): What Coverbase asks a supplier in Greece for, and which of those rules block a submission. - [Greenland](https://docs.coverbase.com/user-guides/supplier-countries/gl.md): What Coverbase asks a supplier in Greenland for, and which of those rules block a submission. - [Guadeloupe](https://docs.coverbase.com/user-guides/supplier-countries/gp.md): What Coverbase asks a supplier in Guadeloupe for, and which of those rules block a submission. - [Guatemala](https://docs.coverbase.com/user-guides/supplier-countries/gt.md): What Coverbase asks a supplier in Guatemala for, and which of those rules block a submission. - [Hong Kong SAR](https://docs.coverbase.com/user-guides/supplier-countries/hk.md): What Coverbase asks a supplier in Hong Kong SAR for, and which of those rules block a submission. - [Hungary](https://docs.coverbase.com/user-guides/supplier-countries/hu.md): What Coverbase asks a supplier in Hungary for, and which of those rules block a submission. - [Iceland](https://docs.coverbase.com/user-guides/supplier-countries/is.md): What Coverbase asks a supplier in Iceland for, and which of those rules block a submission. - [India](https://docs.coverbase.com/user-guides/supplier-countries/in.md): What Coverbase asks a supplier in India for, and which of those rules block a submission. - [Indonesia](https://docs.coverbase.com/user-guides/supplier-countries/id.md): What Coverbase asks a supplier in Indonesia for, and which of those rules block a submission. - [Iran](https://docs.coverbase.com/user-guides/supplier-countries/ir.md): What Coverbase asks a supplier in Iran for, and which of those rules block a submission. - [Iraq](https://docs.coverbase.com/user-guides/supplier-countries/iq.md): What Coverbase asks a supplier in Iraq for, and which of those rules block a submission. - [Ireland](https://docs.coverbase.com/user-guides/supplier-countries/ie.md): What Coverbase asks a supplier in Ireland for, and which of those rules block a submission. - [Israel](https://docs.coverbase.com/user-guides/supplier-countries/il.md): What Coverbase asks a supplier in Israel for, and which of those rules block a submission. - [Italy](https://docs.coverbase.com/user-guides/supplier-countries/it.md): What Coverbase asks a supplier in Italy for, and which of those rules block a submission. - [Japan](https://docs.coverbase.com/user-guides/supplier-countries/jp.md): What Coverbase asks a supplier in Japan for, and which of those rules block a submission. - [Jordan](https://docs.coverbase.com/user-guides/supplier-countries/jo.md): What Coverbase asks a supplier in Jordan for, and which of those rules block a submission. - [Kazakhstan](https://docs.coverbase.com/user-guides/supplier-countries/kz.md): What Coverbase asks a supplier in Kazakhstan for, and which of those rules block a submission. - [Kosovo](https://docs.coverbase.com/user-guides/supplier-countries/xk.md): What Coverbase asks a supplier in Kosovo for, and which of those rules block a submission. - [Kuwait](https://docs.coverbase.com/user-guides/supplier-countries/kw.md): What Coverbase asks a supplier in Kuwait for, and which of those rules block a submission. - [Latvia](https://docs.coverbase.com/user-guides/supplier-countries/lv.md): What Coverbase asks a supplier in Latvia for, and which of those rules block a submission. - [Lebanon](https://docs.coverbase.com/user-guides/supplier-countries/lb.md): What Coverbase asks a supplier in Lebanon for, and which of those rules block a submission. - [Liechtenstein](https://docs.coverbase.com/user-guides/supplier-countries/li.md): What Coverbase asks a supplier in Liechtenstein for, and which of those rules block a submission. - [Lithuania](https://docs.coverbase.com/user-guides/supplier-countries/lt.md): What Coverbase asks a supplier in Lithuania for, and which of those rules block a submission. - [Luxembourg](https://docs.coverbase.com/user-guides/supplier-countries/lu.md): What Coverbase asks a supplier in Luxembourg for, and which of those rules block a submission. - [Malaysia](https://docs.coverbase.com/user-guides/supplier-countries/my.md): What Coverbase asks a supplier in Malaysia for, and which of those rules block a submission. - [Malta](https://docs.coverbase.com/user-guides/supplier-countries/mt.md): What Coverbase asks a supplier in Malta for, and which of those rules block a submission. - [Martinique](https://docs.coverbase.com/user-guides/supplier-countries/mq.md): What Coverbase asks a supplier in Martinique for, and which of those rules block a submission. - [Mauritania](https://docs.coverbase.com/user-guides/supplier-countries/mr.md): What Coverbase asks a supplier in Mauritania for, and which of those rules block a submission. - [Mauritius](https://docs.coverbase.com/user-guides/supplier-countries/mu.md): What Coverbase asks a supplier in Mauritius for, and which of those rules block a submission. - [Mayotte](https://docs.coverbase.com/user-guides/supplier-countries/yt.md): What Coverbase asks a supplier in Mayotte for, and which of those rules block a submission. - [Mexico](https://docs.coverbase.com/user-guides/supplier-countries/mx.md): What Coverbase asks a supplier in Mexico for, and which of those rules block a submission. - [Moldova](https://docs.coverbase.com/user-guides/supplier-countries/md.md): What Coverbase asks a supplier in Moldova for, and which of those rules block a submission. - [Monaco](https://docs.coverbase.com/user-guides/supplier-countries/mc.md): What Coverbase asks a supplier in Monaco for, and which of those rules block a submission. - [Montenegro](https://docs.coverbase.com/user-guides/supplier-countries/me.md): What Coverbase asks a supplier in Montenegro for, and which of those rules block a submission. - [Morocco](https://docs.coverbase.com/user-guides/supplier-countries/ma.md): What Coverbase asks a supplier in Morocco for, and which of those rules block a submission. - [Netherlands](https://docs.coverbase.com/user-guides/supplier-countries/nl.md): What Coverbase asks a supplier in the Netherlands for, and which of those rules block a submission. - [New Zealand](https://docs.coverbase.com/user-guides/supplier-countries/nz.md): What Coverbase asks a supplier in New Zealand for, and which of those rules block a submission. - [Nigeria](https://docs.coverbase.com/user-guides/supplier-countries/ng.md): What Coverbase asks a supplier in Nigeria for, and which of those rules block a submission. - [Norway](https://docs.coverbase.com/user-guides/supplier-countries/no.md): What Coverbase asks a supplier in Norway for, and which of those rules block a submission. - [Oman](https://docs.coverbase.com/user-guides/supplier-countries/om.md): What Coverbase asks a supplier in Oman for, and which of those rules block a submission. - [Pakistan](https://docs.coverbase.com/user-guides/supplier-countries/pk.md): What Coverbase asks a supplier in Pakistan for, and which of those rules block a submission. - [Palestine](https://docs.coverbase.com/user-guides/supplier-countries/ps.md): What Coverbase asks a supplier in Palestine for, and which of those rules block a submission. - [Peru](https://docs.coverbase.com/user-guides/supplier-countries/pe.md): What Coverbase asks a supplier in Peru for, and which of those rules block a submission. - [Philippines](https://docs.coverbase.com/user-guides/supplier-countries/ph.md): What Coverbase asks a supplier in the Philippines for, and which of those rules block a submission. - [Poland](https://docs.coverbase.com/user-guides/supplier-countries/pl.md): What Coverbase asks a supplier in Poland for, and which of those rules block a submission. - [Portugal](https://docs.coverbase.com/user-guides/supplier-countries/pt.md): What Coverbase asks a supplier in Portugal for, and which of those rules block a submission. - [Qatar](https://docs.coverbase.com/user-guides/supplier-countries/qa.md): What Coverbase asks a supplier in Qatar for, and which of those rules block a submission. - [Reunion](https://docs.coverbase.com/user-guides/supplier-countries/re.md): What Coverbase asks a supplier in Reunion for, and which of those rules block a submission. - [Romania](https://docs.coverbase.com/user-guides/supplier-countries/ro.md): What Coverbase asks a supplier in Romania for, and which of those rules block a submission. - [Saint Barthelemy](https://docs.coverbase.com/user-guides/supplier-countries/bl.md): What Coverbase asks a supplier in Saint Barthelemy for, and which of those rules block a submission. - [Saint Lucia](https://docs.coverbase.com/user-guides/supplier-countries/lc.md): What Coverbase asks a supplier in Saint Lucia for, and which of those rules block a submission. - [Saint Martin (French Section)](https://docs.coverbase.com/user-guides/supplier-countries/mf.md): What Coverbase asks a supplier in Saint Martin (French Section) for, and which of those rules block a submission. - [Saint Pierre and Miquelon](https://docs.coverbase.com/user-guides/supplier-countries/pm.md): What Coverbase asks a supplier in Saint Pierre and Miquelon for, and which of those rules block a submission. - [San Marino](https://docs.coverbase.com/user-guides/supplier-countries/sm.md): What Coverbase asks a supplier in San Marino for, and which of those rules block a submission. - [Saudi Arabia](https://docs.coverbase.com/user-guides/supplier-countries/sa.md): What Coverbase asks a supplier in Saudi Arabia for, and which of those rules block a submission. - [Senegal](https://docs.coverbase.com/user-guides/supplier-countries/sn.md): What Coverbase asks a supplier in Senegal for, and which of those rules block a submission. - [Serbia](https://docs.coverbase.com/user-guides/supplier-countries/rs.md): What Coverbase asks a supplier in Serbia for, and which of those rules block a submission. - [Seychelles](https://docs.coverbase.com/user-guides/supplier-countries/sc.md): What Coverbase asks a supplier in Seychelles for, and which of those rules block a submission. - [Singapore](https://docs.coverbase.com/user-guides/supplier-countries/sg.md): What Coverbase asks a supplier in Singapore for, and which of those rules block a submission. - [Slovakia](https://docs.coverbase.com/user-guides/supplier-countries/sk.md): What Coverbase asks a supplier in Slovakia for, and which of those rules block a submission. - [Slovenia](https://docs.coverbase.com/user-guides/supplier-countries/si.md): What Coverbase asks a supplier in Slovenia for, and which of those rules block a submission. - [South Africa](https://docs.coverbase.com/user-guides/supplier-countries/za.md): What Coverbase asks a supplier in South Africa for, and which of those rules block a submission. - [South Korea](https://docs.coverbase.com/user-guides/supplier-countries/kr.md): What Coverbase asks a supplier in South Korea for, and which of those rules block a submission. - [Spain](https://docs.coverbase.com/user-guides/supplier-countries/es.md): What Coverbase asks a supplier in Spain for, and which of those rules block a submission. - [Sweden](https://docs.coverbase.com/user-guides/supplier-countries/se.md): What Coverbase asks a supplier in Sweden for, and which of those rules block a submission. - [Switzerland](https://docs.coverbase.com/user-guides/supplier-countries/ch.md): What Coverbase asks a supplier in Switzerland for, and which of those rules block a submission. - [Thailand](https://docs.coverbase.com/user-guides/supplier-countries/th.md): What Coverbase asks a supplier in Thailand for, and which of those rules block a submission. - [Tunisia](https://docs.coverbase.com/user-guides/supplier-countries/tn.md): What Coverbase asks a supplier in Tunisia for, and which of those rules block a submission. - [Türkiye](https://docs.coverbase.com/user-guides/supplier-countries/tr.md): What Coverbase asks a supplier in Türkiye for, and which of those rules block a submission. - [Ukraine](https://docs.coverbase.com/user-guides/supplier-countries/ua.md): What Coverbase asks a supplier in Ukraine for, and which of those rules block a submission. - [United Arab Emirates](https://docs.coverbase.com/user-guides/supplier-countries/ae.md): What Coverbase asks a supplier in the United Arab Emirates for, and which of those rules block a submission. - [United Kingdom](https://docs.coverbase.com/user-guides/supplier-countries/gb.md): What Coverbase asks a supplier in the United Kingdom for, and which of those rules block a submission. - [United States](https://docs.coverbase.com/user-guides/supplier-countries/us.md): What Coverbase asks a supplier in the United States for, and which of those rules block a submission. - [Autonomous Intake](https://docs.coverbase.com/products/autonomous-intake.md): Vendor intake that researches the vendor, catches duplicate spend, screens it, and drafts the risk questionnaire, then routes every request into the TPRM program at the correct depth. - [Assessment Copilot](https://docs.coverbase.com/products/assessment-copilot.md): AI-powered assessment engine that automates approximately 90% of vendor risk assessment workload. - [Contract Guardian](https://docs.coverbase.com/products/contract-guardian.md): Contract analysis, clause review, and redline surfacing for third-party agreements. - [Document Insights](https://docs.coverbase.com/products/document-insights.md): Org-defined fields extracted from every document, with a verbatim source quote, page citation, and confidence on each value. - [Supplier Radar](https://docs.coverbase.com/products/supplier-radar.md): Continuous monitoring, triage, and response across your third-party ecosystem. - [Vendor Intelligence](https://docs.coverbase.com/products/vendor-intelligence.md): Validated corporate identity for every vendor: the legal entity, its standing, and its identifiers, from registries of record, with a citation on every fact. - [Corporate Registrations](https://docs.coverbase.com/products/corporate-registrations.md): Validates the legal entity behind a vendor against public business registers, with a citation for every fact. - [People intelligence](https://docs.coverbase.com/products/people-intelligence.md): A cited dossier on the people who run a vendor: executives, board, reporting lines, and what adverse-media screening found against them. - [Zero Touch Assessments](https://docs.coverbase.com/products/zero-touch-assessments.md): A triage assessment assembled entirely from open-source research, with no vendor outreach. - [Financial Health Score](https://docs.coverbase.com/products/financial-health-score.md): A 0-100 view of whether a vendor is financially sound enough to depend on, computed from filed statements where they exist and from signals where they do not, always labelled with which. - [Security Intelligence](https://docs.coverbase.com/products/security-intelligence.md): An outside-in security rating measured from the vendor's own infrastructure, with every point deducted traceable to a specific observed configuration. - [Document library](https://docs.coverbase.com/products/document-library.md): The library of vendor documentation Coverbase collects and curates itself: where the documents come from, how they are reviewed, and why nothing you upload ever ends up in it. - [Source library](https://docs.coverbase.com/products/source-library.md): Every data source Coverbase draws on (due-diligence blocks, continuous-monitoring feeds, and partner integrations), organized into Core, Optional, and Premium tiers. - [Detector library](https://docs.coverbase.com/products/detector-library.md): Every out-of-the-box Supplier Radar detector template, organized by segment, with the default severity and what each one flags. - [Findings Manager](https://docs.coverbase.com/products/findings-manager.md): Intelligence layer over findings across every assessment: remediation tracking and systemic risk pattern detection. - [Obligations Tracker](https://docs.coverbase.com/products/obligations-tracker.md): Track the obligations your organization takes on when engaging third parties: CUECs, legal terms, SOW duties, and technical controls. - [RFP Platform](https://docs.coverbase.com/products/rfp-platform.md): A complete RFP platform purpose-built for regulated industries, with risk, compliance, security, and legal evaluation embedded into vendor selection. - [Agentic Inspect](https://docs.coverbase.com/products/agentic-inspect.md): Agentic, browser-based vendor inspection that converts attestations into verified control evidence. - [Internal control monitoring](https://docs.coverbase.com/products/internal-controls-monitoring.md): Coverbase against your own applications: evidence collected from live admin consoles, 362 internal controls out of the box, drift detection between runs, and internal findings sharing the same findings, workflow and reporting machinery as third-party risk. - [Control Set library](https://docs.coverbase.com/control-library.md): Every built-in control set template Coverbase ships across both libraries: the vendor frameworks they map to, the internal application controls Inspect evaluates, their coverage, and links to the official sources. - [API Keys API](https://docs.coverbase.com/api-reference/api-keys.md): Manage your organization's ak_* public-API keys: list, create, rotate, revoke, and grant admin scopes. - [Vendors & Services API](https://docs.coverbase.com/api-reference/vendors.md): Create, retrieve, and update vendors, and create child services. - [Documents API](https://docs.coverbase.com/api-reference/documents.md): Upload vendor documents, link them to vendors, services, and assessments, and download them. - [Bill of Materials API](https://docs.coverbase.com/api-reference/bill-of-materials.md): Upload, version, and search machine-readable bills of materials (SBOM, AIBOM, HBOM, SaaSBOM) for vendors and services. - [Users API](https://docs.coverbase.com/api-reference/users.md): Provision users, change org roles, and deprovision, for SailPoint / IGA-driven lifecycle. - [Intake API](https://docs.coverbase.com/api-reference/intake.md): Create vendor intake requests programmatically, pass unstructured context, and let Coverbase auto-answer the inherent risk questionnaire. - [Assessments API](https://docs.coverbase.com/api-reference/assessments.md): Create and retrieve assessments for vendors. - [Zero Touch Assessments API](https://docs.coverbase.com/api-reference/zero-touch-assessments.md): Launch lightweight, no-outreach triage runs, rank a portfolio by the resulting score, and read a single run's composite and evidence. - [Findings API](https://docs.coverbase.com/api-reference/findings.md): List, create, retrieve, and status-sync findings for GRC round-trips. - [Obligations API](https://docs.coverbase.com/api-reference/obligations.md): List, create, retrieve, and status-sync obligations (CUEC) for GRC round-trips. - [Radar API](https://docs.coverbase.com/api-reference/radar.md): Create radar events, and list, retrieve, and triage (dismiss) radar alerts. - [Reassessments API](https://docs.coverbase.com/api-reference/reassessments.md): Create reassessments from radar events, curate the vendor set, and run them. - [Custom Fields API](https://docs.coverbase.com/api-reference/custom-fields.md): Discover your organization's custom field definitions and read their values on vendors, services, and assessments. - [Workflows API](https://docs.coverbase.com/api-reference/workflows.md): Invoke a named workflow and poll its run state. - [Webhooks API](https://docs.coverbase.com/api-reference/webhooks.md): Register, list, update, delete, and test webhook subscriptions. - [Export API Concepts](https://docs.coverbase.com/export-api-concepts.md): Pull vendor, assessment, control, and evaluation data out of Coverbase via configurable report endpoints. - [Export API Reference](https://docs.coverbase.com/export.md): Endpoint reference for retrieving report data via the Coverbase Export API. - [Import API Concepts](https://docs.coverbase.com/import-api.md): Push vendor, assessment, and service data into Coverbase from upstream systems of record. - [Import API Reference](https://docs.coverbase.com/import.md): Endpoint reference for submitting batches of records via the Coverbase Import API. - [Field reference](https://docs.coverbase.com/fields/overview.md): How Coverbase fields work across filters, saved views, sorting, workflow conditions, and the query API. - [Field catalog](https://docs.coverbase.com/fields/catalog.md): Every filterable, sortable, and queryable field in Coverbase, by module. - [Reporting overview](https://docs.coverbase.com/reporting/overview.md): How Coverbase turns assessment data into deliverable documents: custom Word report templates, standard exports, and the placeholder system that fills them. - [Custom Word report templates](https://docs.coverbase.com/reporting/assessment-report-templates.md): Build a .docx assessment report template: placeholder syntax, AI-written sections, repeating findings tables, signature anchors, and the rules that govern substitution. - [Template placeholder reference](https://docs.coverbase.com/reporting/template-placeholders.md): Every placeholder available in a Coverbase Word report template, what it resolves to, and how the value is formatted. - [Evidence packaging and the due-diligence file](https://docs.coverbase.com/reporting/due-diligence-file.md): Produce the complete due-diligence file for one third party: the full vendor report with profile, assessments, findings, contracts, obligations, documents, monitoring, notes and the audit trail, plus bulk document archives and structured exports. - [Integration Workflows](https://docs.coverbase.com/integrations/overview.md): How Coverbase integrates with the systems your organization already runs, end to end. - [Integration directory](https://docs.coverbase.com/integrations/directory.md): The external systems Coverbase connects with, organized by category, from cybersecurity ratings and GRC platforms to AI governance and procurement. - [Integration patterns](https://docs.coverbase.com/integrations/patterns.md): The four integration shapes every Coverbase integration composes: inbound push, outbound sync, webhooks with workflows, and file-based import. - [ProcessUnity](https://docs.coverbase.com/integrations/guides/processunity.md): Bidirectional integration with ProcessUnity: assessments flow in, scored results, review decisions, issues, and documents flow back as native ProcessUnity records. - [ServiceNow](https://docs.coverbase.com/integrations/guides/servicenow.md): Native integration with ServiceNow Vendor Risk Management: completed assessments, issues, and vendor documents land as VRM records your ServiceNow workflows already understand. - [OneTrust](https://docs.coverbase.com/integrations/guides/onetrust.md): Coverbase assessments mirror into OneTrust as Vendor Risk Assessments, advanced through their native lifecycle, with one OneTrust risk created per unresolved issue. - [Workday Strategic Sourcing](https://docs.coverbase.com/integrations/guides/workday-strategic-sourcing.md): Procurement-driven intake: Workday Strategic Sourcing pushes suppliers into Coverbase, which enriches, tiers, and assesses them automatically. - [Aravo](https://docs.coverbase.com/integrations/guides/aravo.md): Coverbase as the risk-triage and intelligence layer alongside Aravo: bulk vendor populations triaged by AI, high-risk vendors routed into Aravo workflows, risk data synced back. - [Jira](https://docs.coverbase.com/integrations/guides/jira.md): Create and track Jira issues from Coverbase workflows: findings, follow-ups, and remediation work land in the backlog your engineering teams already run. - [Slack](https://docs.coverbase.com/integrations/guides/slack.md): Coverbase's Slack app delivers work notifications where your team already lives - matched to the right person, resilient to Slack's rate limits. - [DocuSign](https://docs.coverbase.com/integrations/guides/docusign.md): Send vendor documents for e-signature without leaving Coverbase, through your own DocuSign account. - [SafeBase](https://docs.coverbase.com/integrations/guides/safebase.md): Pull vendor trust-center profiles and compliance documents from SafeBase automatically, so assessments start with the evidence vendors already publish. - [Workflow engine](https://docs.coverbase.com/integrations/workflow-engine.md): How triggers, conditions, and actions compose into orchestration logic. - [Triggering workflows from external systems](https://docs.coverbase.com/integrations/triggering-workflows.md): Three patterns for starting work in Coverbase from outside the UI. - [Webhooks](https://docs.coverbase.com/integrations/webhooks.md): Delivery format, fan-out, signature verification, retries, and the event catalog. - [Webhook delivery history](https://docs.coverbase.com/integrations/webhook-deliveries.md): Inspect every webhook delivery attempt: status, response, and payload. - [End-to-end workflows](https://docs.coverbase.com/integrations/end-to-end-workflows.md): Three full lifecycle walkthroughs showing every API and webhook touchpoint. - [What to expect during onboarding](https://docs.coverbase.com/integrations/onboarding.md): How onboarding works, what Coverbase builds with you, what you configure yourself, and what security teams typically request. - [Coverbase MCP Server](https://docs.coverbase.com/mcp/overview.md): Let AI assistants query and manage your TPRM program through natural conversation. - [Connecting clients](https://docs.coverbase.com/mcp/connecting.md): Connect Claude Code, Claude.ai, Claude Desktop, Cursor, VS Code, Microsoft Copilot Studio, and other MCP clients to the Coverbase MCP server. - [Anthropic Connectors Directory](https://docs.coverbase.com/mcp/connector-directory.md): Coverbase in Claude's official Connectors Directory: one-click install, branded card, and a published security review. - [Tool reference](https://docs.coverbase.com/mcp/tool-reference.md): Every tool the Coverbase MCP server exposes: the nine read dispatchers and their kinds, the report catalog, the write matrix, and the self-describing capabilities call. - [Vendor intake in chat](https://docs.coverbase.com/mcp/vendor-intake.md): File a complete vendor intake request through an AI assistant: identity confirmation, alternatives, pre-qualification, and the inherent risk questionnaire, without opening the portal. - [Canned prompts](https://docs.coverbase.com/mcp/prompts.md): Twenty scripted TPRM workflows you can invoke by name instead of describing what you want. - [Example prompts](https://docs.coverbase.com/mcp/example-prompts.md): Realistic prompts that exercise the core MCP server workflows. - [Roles and permissions](https://docs.coverbase.com/mcp/permissions.md): How the MCP server enforces read-only versus read/write access, why it inherits the connected user's Coverbase role, and the controls that keep every tool call least-privilege. - [Security and privacy](https://docs.coverbase.com/mcp/security.md): Authentication, authorization, data handling, and what we log when you connect the MCP server. - [Troubleshooting](https://docs.coverbase.com/mcp/troubleshooting.md): Common issues when connecting and using the Coverbase MCP server. - [Trust and security overview](https://docs.coverbase.com/security/overview.md): How Coverbase governs, secures, and makes auditable the third-party risk platform you run your program on. - [Compliance and assurance](https://docs.coverbase.com/security/compliance.md): SOC 2 Type II, independent annual penetration testing, and how to request our reports. - [Regulatory alignment for banks and credit unions](https://docs.coverbase.com/security/regulatory-alignment.md): How Coverbase maps to the 2023 Interagency Guidance on Third-Party Relationships, the Interagency Guidelines Establishing Information Security Standards (Appendix D-2 to Regulation H), FFIEC outsourcing guidance, GLBA, DORA and NCUA expectations. - [Security governance](https://docs.coverbase.com/security/governance.md): Policies, ownership, access control, personnel security, vendor management, and incident response. - [Identity and access management](https://docs.coverbase.com/security/identity-and-access.md): How people sign in to Coverbase and how their access ends: SAML 2.0 single sign-on with your identity provider's MFA and conditional access, just-in-time provisioning, IGA-driven lifecycle management, role-based access control, and network restriction. - [Data protection](https://docs.coverbase.com/security/data-protection.md): Encryption in transit and at rest, field-level encryption and role-based masking of sensitive identifiers, tenant isolation, key management and rotation, data residency, retention and deletion. - [Secure development](https://docs.coverbase.com/security/secure-development.md): Our secure SDLC: review, automated gates, dependency and secret scanning, and least-privilege CI/CD. - [AI governance](https://docs.coverbase.com/security/ai-governance.md): How we select, test, and constrain the AI models that power Coverbase, and how we handle your data. - [Audit trails](https://docs.coverbase.com/security/audit-trails.md): Every action across the dashboard, API, and AI is logged in an audit trail you can read in the dashboard and export through the API. - [Support, service levels and escalation](https://docs.coverbase.com/security/support-and-slas.md): Coverbase support channels, the P0 to P3 severity ladder with response and update commitments, the on-call escalation path, the 99.9% uptime SLO and how it is measured, and the public status page. - [Contract terms and exit](https://docs.coverbase.com/security/contract-terms.md): The commercial and contractual questions a regulated buyer asks: incident and breach notification, data return and destruction on exit, retention, renewal and notice, subprocessors, and the diligence package Coverbase provides. - [Working with Coverbase](https://docs.coverbase.com/security/working-with-coverbase.md): Company profile and viability diligence, release cadence and roadmap transparency, early access to features in development, and how customers influence what Coverbase builds. ## OpenAPI Specs - [openapi](/api-reference/openapi.json) ## Optional - [Content Library](https://www.coverbase.com/content-library)