questions.

Noctovisor watches the companies you name in public records (court and insolvency filings, company registries, sanctions lists, regulatory notices) and emails a verified, source-linked alert when something crosses the line you set. The companies you watch are never contacted and never asked to fill in anything.

Every question we've been asked so far is answered in full below. If yours isn't here, send it to contact@noctovisor.com and we'll answer it and add it.

monitoring and alerts.

what is Noctovisor, exactly?

Noctovisor is a supplier and third-party risk monitoring service for regulated mid-market teams in the US and EU. We watch the companies you name in public records (court and insolvency filings, company registries, sanctions lists, regulatory notices) and email a verified, source-linked alert when something crosses the line you set. The companies you watch are never contacted and never asked to fill in anything. There is no portal and no login: the alert is the product, and behind it a dated record of every check and every response builds itself, returned to you as a monthly report.

how many alerts will I actually get?

Usually one a week, and you control that: you set the line in writing, and we move it whenever you ask. Every Monday you also get the watch log: what we checked, what crossed your line, and what stayed below it.

how do you know it's the right company?

Every name on your list is resolved to a registered legal entity before we start watching, and every alert names the identifier it matched, so you can check the match as well as the claim. It's worth asking of any monitoring service, including us: a similar name in a different country is how this kind of tool goes wrong.

do we still need supplier questionnaires?

For whatever your policy requires, yes. But not to make this work. We read public sources only, so the companies you watch are never contacted and nothing waits on anyone's security team.

if we get an alert and do nothing, haven't we just created a record against ourselves?

We're not your lawyers, but the standard you're worried about is "knew or should have known", and it doesn't switch off when you stop looking; not monitoring leaves you arguing you couldn't have known something that was on the public record. What protects you is a record with both halves: what you knew, and what you did. That's how ours is built. Every alert carries a link: one click marks it looking into it, dealt with or no action needed, and there's a box if you want to write a line. The monthly report shows the mark beside the event it answers, dated, with everything that came before it. A considered "no action needed", on the record, on the day you decided it, is exactly the half most records are missing. A dated trail of alerts answered is evidence of diligence. An inbox of warnings nobody answered is the thing you're describing.

what are your response times?

We don't publish alert service commitments yet. An SLA written before the service has operating history would be a guess. We'll publish what we achieve once the first watches have run. The commitments that do exist, on breach notification, export, return and deletion, are in the data processing agreement.

do you read sources in any country, any language?

We read the source in the language it was published in and send the alert in yours, with the original linked. We pick the right sources per company instead of running one English feed over everything. Agentic research and machine translation let us cover third parties anywhere in the world.

what these terms mean.

what's the difference between supplier risk monitoring and third-party risk management?

Third-party risk management is the whole discipline: due diligence before you sign, assessments, contracts, offboarding, for every external party. Supplier risk monitoring is the part that runs after onboarding: watching what changes at the companies you already rely on. That part is ours. We don't run your assessments or build your register; we watch the public record and tell you when something crossed your line.

how is continuous monitoring different from an annual assessment?

An assessment is a snapshot: a questionnaire or an audit, dated the day it's finished and aging from the next. Monitoring is what happens between snapshots. We read the public record as often as it moves, the fast sources every day, and email you when something crosses the line you set, so a March filing doesn't wait for a November review. Most teams need both: the assessment sets the baseline, the watch tells you when it moved.

your data, and buying.

what happens to the list I send you?

It stays yours. We are built around privacy: no cookies, no tracking, no analytics, no third-party scripts. Your list is your property. We never sell it, pool it across customers or train on it, and it is encrypted at rest. The trust page has the full map and the sub-processor list names every provider we may call. If you don't become a customer, we delete it within ninety days.

do you have ISO 27001 or SOC 2?

Not yet. ISO 27001 is in progress, with SOC 2 to follow. The security summary, sub-processor list and data processing agreement are published on the trust page, so your reviewer can read them before you send us anything.

does this replace anything we already pay for?

Part of it, possibly: an adverse-media or screening subscription that rarely gets opened. It doesn't replace sanctions screening for onboarding and KYC, financial data for credit decisions, or litigation research, and it doesn't build your DORA register of information. Ask and we'll put that in writing, so you can set it beside anything it overlaps.

we've classified this function as critical or important under DORA. can we still sign up?

Talk to us before you contract. Our standard agreement isn't written for a function classified as critical or important under DORA, and it says so itself. That use needs terms agreed with your compliance team before you sign.

what if you go out of business?

There's no investor clock here and no burn rate racing it. The mechanics protect you either way: monthly billing, no lock-in, no notice period, and you can export your whole record at any time. Do that once a quarter and the evidence you need lives in a file you already hold.