Vendor

Independent risk intelligence on every EdTech vendor

Schools use 30 to 50 digital tools on average. Many process children's personal data, add AI features between reviews, or transfer data internationally. Vendor gives you structured, independent assessments of over 250 EdTech vendors across six risk dimensions, so you can approve tools confidently and evidence accountability without manual research.
Speak with our team
Vendor
250+
Pre-assessed EdTech vendors
6
Risk dimensions per assessment
800+
Schools worldwide
TRUSTED BY 800+ SCHOOLS WORLDWIDE

Risk intelligence you inherit, not research

Schools are expected to know every vendor that processes children's data: what it holds, where it transfers it, how it is secured and what its AI does. Vendor contracts are long. Privacy policies change without notice. AI features appear in familiar tools between reviews. Vendor replaces manual, inconsistent review with independently maintained intelligence your school inherits from day one.

Icon

Assessed at product level

Different products from the same supplier carry different data flows, AI features and safeguarding implications. 9ine assesses each product separately, so you get intelligence for the tool actually in use rather than the parent brand.

Icon

Six risk dimensions

Every vendor is rated across privacy, AI, safeguarding, cyber security, system security and regulatory compliance. Traffic-light ratings mean any stakeholder can read the risk without specialist expertise.

Icon

Maintained continuously

Assessments are updated as vendors change their policies, data practices and AI capabilities. Your view stays current without anyone in school tracking vendor announcements.

Everything you need to govern the vendor environment

Over 250 vendors, assessed independently

 9ine's specialists review vendor contracts, privacy policies, AI documentation, security certifications and sub-processor agreements. Not the vendor's own compliance claims. Where a tool you use is not yet in the library, request it and 9ine assesses it on your behalf, so no vendor sits outside your governance. 
Vendor

The assessment stages

A consistent structure, every vendor

Traffic-light risk ratings

Risk anyone can read at a glance

AI risk identifier

See which tools use AI, and how

Processing Operation Assessments

The vendor data your DPIAs need

Vendor risk dashboard

Live view of the whole estate

Vendor log

Your estate, not just the library

Connected approval workflow

Requests trigger assessment automatically

Every vendor assessed the same way

Each assessment follows a set structure: processing operation description, processing compliance, safeguarding, security and systems, and an assessment summary. Because the structure never changes, findings are comparable across suppliers, and nothing depends on who happened to carry out the review.

Risk that reads clearly to everyone

Every assessed vendor carries colour-coded ratings across all six risk dimensions. Red, amber and green tell the story immediately, and each rating opens into the detailed assessment behind it. Headteachers, DSLs and DPOs read the same picture without needing to interpret technical findings.

Know which tools use AI before you approve them

The AI risk identifier flags which vendors incorporate AI features, identifies the type and categorises the risk. For UK schools, assessments are benchmarked against the DfE Generative AI Product Safety Standards. That gives safeguarding leads and DPOs a government-aligned basis for decisions about AI in the classroom.

DPIA-ready vendor data, captured once

Processing Operation Assessments record data transfer locations, personal data categories, sub-processors, international transfers and security measures for each vendor. That data feeds straight into DPIA workflows in Privacy, so your DPO completes assessments from structured records rather than chasing suppliers for documentation.

Your whole vendor estate in one view

The dashboard shows risk across every vendor by risk level, AI use, compliance status and assessment currency. Filter to find the tools that need attention first. Leadership gets a live picture of exposure without anyone compiling a report.

One log for every tool you actually use

Import assessments straight from the library for every EdTech provider your school uses, then build your log around them with your own notes, status and approval history. Existing vendors can be reviewed periodically rather than only when something goes wrong, so your estate stays governed rather than drifting between audits.

Every tool request follows the same path

When a teacher requests a tool through Application, the vendor assessment workflow triggers automatically and routes to the right assessor. Findings populate the application card so the approver decides with the risk picture in front of them. Every decision leaves an audit trail.

Stop relying on vendors to assess themselves

9ine reviews the contracts, privacy policies, AI documentation and security certifications independently, and updates assessments as vendors change. Schools get an honest picture rather than a supplier's own compliance claims.

Speak with us

Built for everyone who carries the risk

Vendor oversight is rarely one person's job. Leadership, IT, privacy, safeguarding and teaching staff each need a different view of the same estate.

Senior leadership and business management
Leadership

Senior leadership and business management

A live dashboard showing risk exposure across the whole supplier estate by risk level, AI use and compliance status. Accountability conversations with governors and inspectors start from evidence rather than estimates.

IT team
Technology

IT team

Structured security assessments, Processing Operation Assessments and the AI risk identifier in one place. No more manual research for every new tool, and no more tracking spreadsheet to maintain.

DPO and privacy lead
Privacy

DPO and privacy lead

A pre-assessed library and structured POA data supply the vendor intelligence DPIAs require. Your DPO stops chasing suppliers for documentation that arrives inconsistently and late.

Safeguarding lead and DSL
Safeguarding

Safeguarding lead and DSL

Clear visibility of safeguarding risk for every digital tool, with AI-enabled tools flagged and categorised. You can see whether a tool has been assessed for use with pupils before it reaches a classroom.

Teachers
Academic

Teachers

A structured way to request the tools you want to use. The assessment happens automatically behind the scenes, so you get a clear answer without needing to understand the governance process.

What changes when vendor review is structured

Most schools vet vendors through spreadsheets, email threads and one-off reviews. Here is what that approach can and cannot do.

Capability
Spreadsheets and manual review
9ine Vendor
Vendor coverage
❌ Limited to vendors someone has had time to research
✅ 250+ pre-assessed vendors, plus assessment on request
Assessment depth
❌ Usually relies on the vendor's own published claims
✅ Independent review of contracts, policies, AI docs and security certifications
Product-level accuracy
❌ Typically assessed per company, missing product-level differences
✅ Each product assessed separately from its parent vendor
AI feature visibility
❌ No systematic way to spot AI added between reviews
✅ AI risk identifier, benchmarked against DfE AI standards
Keeping assessments current
❌ Accurate only as at the last manual review
✅ Updated continuously as vendors change
Turning findings into action
❌ Findings sit in a document with no owner or deadline
✅ Risks flow into Governance as assigned, trackable tasks

Assessed against the standards schools answer to

Vendor assessments are framed by the regulatory and safeguarding landscape schools actually operate in, not a generic enterprise compliance checklist.

UK GDPR and Data Protection Act 2018

Structured third-party due diligence, Processing Operation Assessments and the audit trail needed for Article 30 Records of Processing and controller accountability.

DfE Generative AI Product Safety Standards

AI risk assessments in the vendor library are benchmarked against DfE standards, giving schools a government-aligned basis for governing AI tools and evidencing that decision.

KCSIE safeguarding obligations

Safeguarding assessments support DSLs in evidencing due diligence on the tools used with pupils, in line with Keeping Children Safe in Education.

★★★★★

"The team at 9ine have been instrumental in supporting us in our journey toward stronger data privacy controls and a better cybersecurity posture. Their materials are thorough, precise, and easy to use, all at the same time. What really makes a difference is that 9ine understands the nuance of international schools in a way that other out-of-the-box consultancies do not."

Greg Clinton
Director of Technology, American International School Chennai
★★★★★

"We began to work with 9ine for our Digital Privacy Management. We quickly expanded to their Cybersecurity services due to their professionalism, especially when such a wide range of aspects can benefit from each other. The different teams are always aware of what's happening, and we benefit significantly, whether at board level or on a very granular scale."

Yoann Saludes
IT Director, Marymount International School Paris
★★★★★

"They felt like an extension of our IT support team for the time they were with us and were never judgemental on the approach we take with our systems and security. I'd have no concerns about recommending them again in the future."

Mike Ward
Head of IT, The Dean Trust

Intelligence that reaches every decision

Vendor is the risk intelligence layer of the 9ine platform. Its findings surface wherever a decision gets made, rather than sitting in an isolated report.

Application

Application

Vendor assessment data surfaces directly on application cards, so teachers and approvers see AI risk, safeguarding flags and privacy status at the point of decision.

Privacy

Privacy

POA data feeds DPIA workflows and keeps Records of Processing accurate, so compliance documentation stays current as vendors change.

Contract

Contract

Vendor risk profiles sit alongside cost, renewal dates and notice periods, giving a complete picture of what each supplier costs and what risk it carries.

Governance

Governance

Risk findings become assigned, trackable tasks with owners and due dates, so vendor issues are resolved rather than filed.

Academy LMS

Academy LMS

Staff training on AI governance, data protection and safeguarding can be linked to vendor findings and required before access to a tool is granted.

Common questions about Vendor

How many vendors are in the pre-assessed library, and what if ours isn't there?

+
 The library covers over 250 EdTech vendors, assessed at product level and updated continuously. If a tool you use is not yet covered, submit a new vendor request and 9ine conducts an independent assessment on your behalf. No vendor is out of scope. 

Why assess products rather than companies?

+
 Many EdTech companies offer several products, each with different data flows, AI features and safeguarding implications. A company-level assessment gives an incomplete picture. 9ine assesses each product separately, which matters most for AI risk, where one product from a supplier may use AI extensively while another does not. 

We already have a process for reviewing vendors. Why do we need this?

+
 Many schools have a process. The challenge is consistency and scale. When a tool is requested on a Friday afternoon, does the process run reliably, and is there an audit trail for the decision? Vendor applies the same process every time and records it, whether or not the right person is available in the moment. 

Our DPO handles vendor reviews. Does this replace them?

+
 No. It changes what they spend their time on. Manually reviewing contracts, privacy notices and AI specifications for every tool in use is unsustainable at scale. A pre-assessed library of over 250 vendors means your DPO works on decisions rather than research. 

We don't use many EdTech tools. Is this still relevant?

+
 Schools consistently find more tools than expected once they look. Staff adopt tools informally, subscriptions accumulate, and AI features are added to tools that have been in use for years. The library lets you check what assessments already exist for your tools, which gives you a baseline quickly even if the list is short. 

We're waiting to see how AI guidance develops. Should we hold off?

+
 AI-enabled tools are already in classrooms and already processing children's data. When guidance settles, it will expect evidence of accountability rather than a plan to get ready. The AI risk identifier is updated as vendors add or change AI features, so your position moves with the risk. 

Vet every vendor. Evidence every decision.

Tell us a little about your school and we'll show you the assessments that already exist for the tools you use. Most schools find gaps they weren't aware of.