Automate vendor risk assessments, track compliance frameworks, and leverage AI-driven risk scoring to protect your organization from third-party threats.
Getting Started • API Documentation • Architecture • Deployment
- Vendor Lifecycle Management — Onboard, monitor, and manage vendors through a centralized platform
- AI-Powered Risk Scoring — Machine learning models (scikit-learn) that analyze vendor data and assign dynamic risk scores
- Compliance Tracking — Built-in support for SOC 2, ISO 27001, HIPAA, and PCI DSS frameworks
- Risk Assessments — Create, assign, and review structured risk assessments with questionnaire templates
- Continuous Monitoring — Real-time threat intelligence and risk event tracking
- AI Auto-Fill — Intelligent form auto-completion for assessment questionnaires
- Notifications — Configurable alerts for risk changes, compliance deadlines, and vendor updates
- Dashboard Analytics — Comprehensive security insights and reporting
- Vendor Portal — Self-service portal for vendors to submit documentation
- Background Tasks — Celery workers for async processing of heavy operations
| Layer | Technology |
|---|---|
| Framework | FastAPI 0.109 with Uvicorn ASGI server |
| Language | Python 3.11+ |
| Database | PostgreSQL 15 (production) / SQLite (development) |
| ORM | SQLAlchemy 2.0 (async) + Alembic migrations |
| Cache / Broker | Redis 7 |
| Task Queue | Celery 5.3 + Flower monitoring |
| AI/ML | scikit-learn, NumPy |
| Auth | JWT (python-jose) + bcrypt password hashing |
| Validation | Pydantic v2 |
| Containerization | Docker + Docker Compose |
| Testing | pytest + pytest-asyncio |
vendorshield-api/
├── app/
│ ├── api/
│ │ ├── deps.py # Dependency injection
│ │ └── v1/ # API v1 route handlers
│ │ ├── assessment.py
│ │ ├── compliance.py
│ │ ├── monitoring.py
│ │ ├── notification.py
│ │ ├── organization.py
│ │ ├── risk.py
│ │ ├── user.py
│ │ └── vendor.py
│ ├── models/ # SQLAlchemy ORM models
│ │ ├── assessment.py
│ │ ├── compliance.py
│ │ ├── dashboard.py
│ │ ├── monitoring.py
│ │ ├── notification.py
│ │ ├── organization.py
│ │ ├── risk.py
│ │ ├── user.py
│ │ └── vendor.py
│ ├── schemas/ # Pydantic request/response schemas
│ ├── services/ # Business logic layer
│ │ ├── ai_autofill.py
│ │ ├── ai_risk_scoring.py
│ │ ├── auth.py
│ │ ├── compliance_mapping.py
│ │ ├── file_storage.py
│ │ ├── questionnaire_templates.py
│ │ └── risk_events.py
│ ├── utils/ # Utility functions
│ ├── config.py # Application settings
│ ├── database.py # Database connection setup
│ ├── main.py # FastAPI app entry point
│ └── worker.py # Celery worker config
├── alembic/ # Database migrations
├── tests/ # Test suite
│ ├── conftest.py
│ ├── test_assessments.py
│ ├── test_auth.py
│ ├── test_compliance.py
│ ├── test_health.py
│ ├── test_notifications.py
│ ├── test_risks.py
│ └── test_vendors.py
├── docker-compose.yml
├── Dockerfile
├── requirements.txt
├── alembic.ini
├── pytest.ini
└── main.py # Dev server entry point
- Python 3.11+
- PostgreSQL 15+ (or use SQLite for local dev)
- Redis 7+
- Docker & Docker Compose (optional)
# Clone the repository
git clone https://github.com/mejba13/vendorshield-api.git
cd vendorshield-api
# Create virtual environment
python -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
# Install dependencies
pip install -r requirements.txt
# Set up environment variables
cp .env.example .env
# Edit .env with your configuration
# Run database migrations
alembic upgrade head
# Start the development server
python main.pyThe API will be available at http://localhost:8000.
# Start all services (API + PostgreSQL + Redis + Celery Worker)
docker-compose up --build
# Run in detached mode
docker-compose up --build -dThis starts:
| Service | Port | Description |
|---|---|---|
| API | 8000 |
FastAPI application |
| PostgreSQL | 5432 |
Database |
| Redis | 6379 |
Cache & message broker |
| Celery Worker | — | Background task processing |
Once the server is running, interactive documentation is available at:
| Format | URL |
|---|---|
| Swagger UI | http://localhost:8000/docs |
| ReDoc | http://localhost:8000/redoc |
| OpenAPI JSON | http://localhost:8000/openapi.json |
All endpoints are prefixed with /api/v1:
| Module | Endpoint | Description |
|---|---|---|
| Auth | /api/v1/auth |
Registration, login, JWT token management |
| Users | /api/v1/users |
User profile and management |
| Vendors | /api/v1/vendors |
Vendor CRUD and lifecycle management |
| Assessments | /api/v1/assessments |
Risk assessment workflows |
| Risks | /api/v1/risks |
Risk scoring and event tracking |
| Compliance | /api/v1/compliance |
Compliance framework tracking |
| Monitoring | /api/v1/monitoring |
Continuous monitoring and alerts |
| Dashboard | /api/v1/dashboard |
Analytics and reporting |
| Notifications | /api/v1/notifications |
Alert management |
| Vendor Portal | /api/v1/vendor-portal |
Vendor self-service portal |
| Reports | /api/v1/reports |
Report generation |
The API uses JWT Bearer tokens. Include the token in the Authorization header:
Authorization: Bearer <your_access_token>
┌─────────────┐ ┌─────────────┐ ┌─────────────────┐
│ Client │────▶│ FastAPI │────▶│ PostgreSQL │
│ (Frontend) │◀────│ (Uvicorn) │◀────│ (Database) │
└─────────────┘ └──────┬──────┘ └─────────────────┘
│
┌──────┴──────┐
│ │
┌─────▼─────┐ ┌────▼────┐
│ Redis │ │ Celery │
│ (Cache) │ │ Worker │
└───────────┘ └─────────┘
| Variable | Default | Description |
|---|---|---|
DATABASE_URL |
sqlite+aiosqlite:///./vendorshield.db |
Async database connection string |
DATABASE_URL_SYNC |
sqlite:///./vendorshield.db |
Sync database connection string |
REDIS_URL |
redis://localhost:6379/0 |
Redis connection URL |
SECRET_KEY |
— | JWT signing secret (change in production!) |
ALGORITHM |
HS256 |
JWT algorithm |
ACCESS_TOKEN_EXPIRE_MINUTES |
30 |
JWT access token TTL |
CORS_ORIGINS |
http://localhost:3000,... |
Comma-separated allowed origins |
CELERY_BROKER_URL |
redis://localhost:6379/1 |
Celery broker URL |
OPENAI_API_KEY |
— | OpenAI API key for AI features |
ENVIRONMENT |
development |
Runtime environment |
DEBUG |
false |
Enable debug mode |
# Run the full test suite
pytest
# Run with verbose output
pytest -v
# Run a specific test module
pytest tests/test_vendors.py
# Run tests with coverage
pytest --cov=app# Build the production image
docker build -t vendorshield-api .
# Run with Docker Compose
docker-compose -f docker-compose.yml up -d- Set
DEBUG=falseandENVIRONMENT=production - Use a strong, unique
SECRET_KEY - Configure
DATABASE_URLto point to your production PostgreSQL instance - Configure
REDIS_URLfor your Redis instance - Set
CORS_ORIGINSto your frontend domain(s)
I build AI-powered applications, mobile apps, and enterprise solutions. Let's bring your ideas to life!
| Platform | Description | Link |
|---|---|---|
| Fiverr | Custom builds, integrations, performance optimization | fiverr.com/s/EgxYmWD |
| Mejba Personal Portfolio | Full portfolio & contact | mejba.me |
| Ramlit Limited | Software development company | ramlit.com |
| ColorPark Creative Agency | UI/UX & creative solutions | colorpark.io |
| xCyberSecurity | Global cybersecurity services | xcybersecurity.io |
Built with FastAPI + AI/ML for intelligent vendor risk management