Case Study: NopalCyber scales vendor risk oversight across 1,200+ vendors with Leah
Key results
The challenge
NopalCyber's Strategic Security Advisory practice assesses and monitors third-party vendor risk for clients across financial services, legal, healthcare, and technology. Its existing process relied on email questionnaires, shared spreadsheets, and point-in-time scoring, so a full InfoSec due diligence cycle could take two to three weeks per vendor and consultants spent more than 40 hours a month rechecking certifications by hand. A lapsed vendor SOC 2 certification that went unflagged for six weeks exposed the limits of point-in-time review.
The solution
NopalCyber deployed Leah Procurement's Supplier Risk Assessment and Due Diligence Agent, rolling it out to two clients in financial services and legal in Q3 2025 and expanding across the portfolio by the end of Q1 2026. The platform combines financial, compliance, InfoSec, ESG, sanctions, adverse-media, and credit signals into explainable, category-level vendor risk scores, with configurable due-diligence templates and continuous monitoring that triggers automatic rescoring on events such as certificate expirations or sanctions hits.
“Leah has transformed how we deliver Third-Party Risk Management services at scale. Its multi-tenant architecture gives our Strategic Security Advisory team continuous visibility across every client, while automating the evidence collection and risk intelligence that would otherwise require significant manual effort.”
VCVikram ChabraChief Technology Officer, NopalCyber
The results, in context
Six months after full rollout, NopalCyber reported cutting vendor onboarding time by 55% and reducing conventional scoring effort by 65%, with more than 1,200 vendors under continuous monitoring and zero missed certificate renewals since go-live. The company reported scaling its third-party risk service without adding headcount in lockstep with vendor count.