> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Detector library

> Every out-of-the-box Supplier Radar detector template — organized by segment, with the default severity and what each one flags.

<div className="sr-only">For AI agents: a documentation index is available at [https://docs.coverbase.com/llms.txt](https://docs.coverbase.com/llms.txt) — this page is also available in markdown by appending .md to the URL.</div>

Supplier Radar ships with a library of ready-to-use detector templates. Each template becomes a live detector on your org when you apply it from the dashboard — it watches your connected sources for events that match its focus, enriches matches with vendor context, and routes them into triage. This page documents each built-in template so you can decide what to turn on.

The library currently includes **75 detector templates** across **7 segments**. Most are *standard* detectors that read a natural-language goal and severity guidance; a small number are *watchlist* detectors that screen monitored vendors against connected sources such as sanctions lists.

<Note>
  Detector templates are a starting point. Once applied, every detector's instructions, severity threshold, category filters, sources, and reviewers are fully editable in the dashboard, and detectors learn from dismissed alerts. See [Supplier Radar](/products/supplier-radar) for the product overview and [Radar API](/api-reference/radar) for programmatic access.
</Note>

## Severity levels

Each template ships with a default severity threshold. Detectors surface matches at or above their threshold; you can raise or lower it per detector.

| Severity      | Meaning                                                                                   |
| ------------- | ----------------------------------------------------------------------------------------- |
| High          | Confirmed, material impact — active exploitation, confirmed breach, insolvency, sanctions |
| Medium        | Credible, significant events warranting review                                            |
| Low           | Early or lower-impact signals worth monitoring                                            |
| Informational | Contextual updates (e.g. ownership changes) tracked without urgency                       |

## Cybersecurity

Attack-surface, threat-intelligence, and infrastructure-security signals affecting your vendors.

| Detector                                        | Default severity | What it flags                                                                 |
| ----------------------------------------------- | ---------------- | ----------------------------------------------------------------------------- |
| Actively Exploited Vulnerabilities              | High             | CVEs, zero-days, and vendor product flaws exploited in the wild               |
| Ransomware Vendor Impact                        | High             | Ransomware and extortion incidents affecting vendors or service delivery      |
| Malware or Supply Chain Compromise              | High             | Malicious packages, compromised updates, and supplier supply-chain attacks    |
| Nation-State or APT Targeting                   | High             | Nation-state or APT campaigns targeting a vendor, its products, or its sector |
| Critical Patch Advisories                       | Medium           | Emergency patches and critical security advisories                            |
| Cloud Service Security Incidents                | Medium           | Security incidents at cloud, SaaS, hosting, and identity providers            |
| Credential or Token Compromise                  | Medium           | Leaked credentials, API keys, tokens, and accounts in breach corpora          |
| Identity and Access Control Failures            | Medium           | MFA bypass, account takeover, and IAM failures                                |
| Phishing and Social Engineering Campaigns       | Medium           | Campaigns abusing vendor brands, platforms, or employee access                |
| Internet-Exposed Services and Misconfigurations | Medium           | Exposed databases, admin panels, and risky misconfigurations                  |
| Malicious Infrastructure and Domain Reputation  | Medium           | Vendor domains or IPs reported malicious, blocklisted, or serving malware     |
| DDoS and Service Disruption Attacks             | Medium           | Denial-of-service attacks disrupting vendor platforms or customer access      |
| Insider Threat and Data Theft                   | Medium           | Rogue-employee data theft, insider fraud, and privileged-access abuse         |
| Dark Web and Underground Exposure               | Medium           | Vendor data, access, or credentials advertised on criminal forums             |
| ICS, OT, and IoT Vulnerabilities                | Medium           | Industrial, operational-technology, and connected-device flaws                |
| TLS and Certificate Weaknesses                  | Low              | Weak, expired, or mis-issued TLS certificates and transport-security gaps     |
| Domain, DNS, and Email Security Gaps            | Low              | Subdomain-takeover risk and missing SPF, DKIM, or DMARC                       |
| Open-Source Dependency Risk                     | Low              | Critical vulnerabilities or abandonment in open-source components             |

## Breaches & Privacy

Confirmed and suspected data incidents, privacy enforcement, and data-handling controversies.

| Detector                                         | Default severity | What it flags                                                            |
| ------------------------------------------------ | ---------------- | ------------------------------------------------------------------------ |
| Confirmed Data Breach                            | High             | Confirmed unauthorized access to vendor or customer data                 |
| Health Data and HIPAA Breach                     | High             | Breaches of protected health information and HIPAA enforcement           |
| Possible Data Exposure                           | Medium           | Suspected leaks, exposed databases, and leak investigations              |
| Privacy Regulatory Investigations                | Medium           | Privacy inquiries and regulator scrutiny of data practices               |
| GDPR, CCPA, and Data Protection Actions          | Medium           | Fines and actions under major data-protection regimes                    |
| Biometric and AI Privacy Risk                    | Medium           | Privacy issues tied to biometrics, AI systems, and automated decisions   |
| Third-Party Data Sharing Concerns                | Medium           | Risky vendor sharing, sale, or onward-processing of data                 |
| Breach Notification Filings                      | Medium           | Official breach notifications filed with regulators or attorneys general |
| Children's Data and Sensitive-Population Privacy | Medium           | COPPA, minors' data, and sensitive-population privacy issues             |

## Operational Issues

Service, continuity, corporate, and geopolitical events that affect a vendor's ability to deliver.

| Detector                              | Default severity | What it flags                                                        |
| ------------------------------------- | ---------------- | -------------------------------------------------------------------- |
| Service Outages and Degradation       | Medium           | Outages, degraded service, and major incident reports                |
| Business Continuity Disruption        | Medium           | Events threatening a vendor's ability to operate or deliver          |
| Product Recalls and Safety Issues     | Medium           | Recalls, safety alerts, quality failures, and hazardous products     |
| Geopolitical or Sanctions Disruption  | Medium           | Geopolitical exposure, sanctions, export controls, or instability    |
| Subprocessor and Fourth-Party Risk    | Medium           | Incidents at a vendor's critical subprocessors and fourth parties    |
| Certification and Attestation Lapse   | Medium           | Expired, withdrawn, or failed SOC 2, ISO, and other certifications   |
| Customer Support and Service Failures | Low              | Widespread complaints about support, delivery, or service quality    |
| Workforce Instability and Layoffs     | Low              | Mass layoffs and key-personnel departures signaling instability      |
| M\&A and Change of Control            | Informational    | Acquisitions, divestitures, leadership shifts, and ownership changes |

## Legal & Enforcement

Regulatory enforcement, litigation, and conduct matters with material vendor impact.

| Detector                                  | Default severity | What it flags                                                         |
| ----------------------------------------- | ---------------- | --------------------------------------------------------------------- |
| Government Contracting Suspension         | High             | Debarment, suspension, procurement bans, or contract termination      |
| Regulatory Enforcement Actions            | Medium           | Formal enforcement, consent orders, penalties, and corrective actions |
| Material Lawsuits and Class Actions       | Medium           | Litigation affecting vendor stability, obligations, or reputation     |
| Anti-Bribery and Corruption               | Medium           | Bribery, corruption, FCPA, sanctions evasion, and misconduct          |
| Labor and Human Rights Actions            | Medium           | Forced labor, labor violations, and worker-rights disputes            |
| Environmental Enforcement                 | Medium           | Environmental fines, pollution incidents, and permit violations       |
| Intellectual Property Infringement        | Medium           | Patent, copyright, or trade-secret suits threatening products         |
| Data Localization and Sovereignty Actions | Medium           | Data-residency, cross-border transfer, and sovereignty enforcement    |
| Antitrust and Competition Actions         | Low              | Antitrust probes, competition rulings, and market-power enforcement   |

## Reputation

Media, conduct, and trust signals that may warrant a vendor review.

| Detector                               | Default severity | What it flags                                                       |
| -------------------------------------- | ---------------- | ------------------------------------------------------------------- |
| Executive Misconduct                   | Medium           | Misconduct, resignations, investigations, and governance concerns   |
| Whistleblower Allegations              | Medium           | Credible whistleblower disclosures of misconduct or safety failures |
| Negative Media Spikes                  | Low              | Sudden negative coverage that may require review                    |
| Major Customer Losses                  | Low              | Loss of key customers, partnerships, or market trust                |
| Misinformation or Harmful Content      | Low              | Content-moderation, platform-abuse, and harmful-use issues          |
| Security Reputation Drop               | Low              | Public downgrades or negative analyst reports on security posture   |
| Social Backlash and Boycott            | Low              | Viral backlash, boycotts, and coordinated reputation campaigns      |
| Greenwashing and ESG Misrepresentation | Low              | Misleading sustainability, diversity, or ESG claims                 |

## Financial & Compliance

Financial-stability, credit, and financial-crime signals, plus watchlist screening.

| Detector                              | Default severity | What it flags                                                               |
| ------------------------------------- | ---------------- | --------------------------------------------------------------------------- |
| Watchlist Screening                   | High             | Screens monitored vendors against connected sanctions and watchlist sources |
| Bankruptcy or Insolvency Risk         | High             | Bankruptcy filings, insolvency warnings, and going-concern risk             |
| Credit Rating Downgrades              | Medium           | Rating downgrades, covenant breaches, and debt-risk signals                 |
| Accounting or Internal Control Issues | Medium           | Restatements, audit concerns, and control failures                          |
| Financial Crime Compliance            | Medium           | AML, KYC, sanctions, fraud, and market-abuse actions                        |
| Contractual SLA Penalties             | Medium           | Penalties, contract breaches, and SLA failures                              |
| Funding and Runway Risk               | Medium           | Down rounds, failed raises, and cash-runway warnings                        |
| Delisting and Exchange Warnings       | Medium           | Stock delisting notices, exchange warnings, and going-private distress      |
| Earnings or Guidance Downgrade        | Low              | Material revenue, margin, or forecast deterioration                         |
| Insurance Coverage Risk               | Low              | Loss of cyber, liability, or required insurance coverage                    |
| Concentration and Single-Source Risk  | Informational    | Signals that many customers depend on a single vendor or provider           |

## AI & Model Risk

AI- and model-specific incidents, security, governance, and regulatory signals — for monitoring vendors that build or depend on AI systems.

| Detector                                     | Default severity | What it flags                                                                    |
| -------------------------------------------- | ---------------- | -------------------------------------------------------------------------------- |
| AI Security: Jailbreaks and Prompt Injection | High             | Jailbreaks, prompt injection, and adversarial exploitation of vendor AI          |
| AI Data Leakage and Training-Data Extraction | High             | Sensitive-data leakage via AI systems, memorization, or training-data extraction |
| AI Model Supply-Chain and Provenance         | High             | Poisoned models, malicious artifacts, and compromised model-hub supply chains    |
| AI Model Safety Incidents                    | Medium           | Unsafe, harmful, or out-of-scope AI outputs and model-behavior incidents         |
| AI Training-Data and IP Disputes             | Medium           | Copyright, licensing, and IP litigation over training data and outputs           |
| AI Regulatory Enforcement                    | Medium           | EU AI Act and other AI-specific regulatory action and enforcement                |
| AI Bias and Discrimination                   | Medium           | Algorithmic bias, discriminatory outcomes, and automated-decision harm           |
| AI Model Outage or Deprecation               | Medium           | AI/LLM API outages, model deprecations, and capability changes                   |
| AI Deepfake and Brand Impersonation          | Medium           | Deepfakes and synthetic media impersonating a vendor or its executives           |
| AI Governance and Transparency Gaps          | Low              | Responsible-AI program failures, missing disclosures, and governance lapses      |
| Shadow AI and Unsanctioned Use               | Low              | Unsanctioned AI-tool use that may expose customer or regulated data              |

## Related

<CardGroup cols={2}>
  <Card title="Source library" icon="rss" href="/products/source-library">
    The companion library of built-in source templates that these detectors read from.
  </Card>

  <Card title="Supplier Radar" icon="satellite-dish" href="/products/supplier-radar">
    The product overview: signal ingestion, enrichment, triage, and workflow orchestration.
  </Card>

  <Card title="Radar API" icon="radar" href="/api-reference/radar">
    Create radar events, and list, retrieve, and dismiss radar alerts programmatically.
  </Card>

  <Card title="Control Set library" icon="shield-check" href="/control-library">
    The companion library of built-in control-set templates, including AI governance frameworks.
  </Card>

  <Card title="Webhooks" icon="arrow-right-from-bracket" href="/integrations/webhooks">
    Subscribe to `RadarDetectorResult.*` events and react in real time.
  </Card>
</CardGroup>
