~ / directory / lema-ai
LA
Agentic · Third-Party Risk · reviewed 2026-04

Lema AI

Agentic TPRM and Risk Engineering platform — forensic AI assessment of vendor artifacts, blast radius monitoring, and open-source recon. Turns TPRM teams into Risk Engineers.

Visit lema.ai
01

What it does

Agentic TPRM platform that transforms third-party risk management from checkbox compliance into active risk engineering. Three core capabilities: Forensic AI Assessment (automatically analyses vendor reports, SOC 2s, pen test results, and compliance documents to surface what's hidden — like active vulnerabilities misclassified as informational), Blast Radius Monitoring (maps how vendors are actually used inside your organisation, tracking access to critical assets, data flows, procurement activity, and scope drift), and Agentic Risk Engineering (AI agents that continuously monitor vendor risk posture using open-source intelligence, detecting events like security team layoffs, breach disclosures, and compliance drift).

02

Security relevance

Addresses the gap between what vendors tell you in questionnaires and what's actually happening. The forensic artifact analysis catches discrepancies that human reviewers miss in hundreds of pages of vendor documentation. Blast radius monitoring provides continuous visibility into the real-world impact of a vendor compromise — not just whether they have a SOC 2, but how deeply they're integrated into your critical systems.

03

When to use it

Use when your TPRM programme has outgrown spreadsheets and questionnaire-based assessments, particularly for AI vendors where the risk surface changes rapidly. Designed for TPRM teams that want to move from compliance management to genuine risk mitigation. The agentic approach means assessments continue between review cycles.

04

OWASP coverage

Risks addressed — mapped to both OWASP Top 10 standards. 0 in LLM, 0 in Agentic.

LLM Top 10 · 2025 · 0/10 covered
01
02
03
04
05
06
07
08
09
10
Agentic Top 10 · 2026 · 0/10 covered
01
02
03
04
05
06
07
08
09
10
05

The raw record

What Yuntona stores. Single source of truth — fork it on GitHub.

name: Lema AI
slug: lema-ai
type: Agentic
category: Third-Party Risk
url: https://lema.ai

reviewed:   2026-04
added:      2026-04
updated:    2026-04

risks:
  llm:  []
  asi:  []

complexity:    Plug & Play
pricing:       —
audience:      CISO · GRC
lifecycle:     [govern]

tags: [Agentic, Commercial, Risk Engineering, TPRM, Vendor Risk]