Blast radius

Supplier blast-radius: when AWS is exploited and you only listed Slack

Updated 2026-08-28

SaaS risk is not only the logo on the invoice. Parent companies, cloud hosts, and identity providers are how KEV entries miss a naive watchlist. Here is the graph ZeroDayTracker uses.

The invoice is a terrible CMDB

You pay Slack. Slack is a Salesforce company. It runs on AWS. Auth0 is Okta. GitHub is Microsoft on Azure. npm is GitHub. A KEV row that says “Amazon” or “Microsoft” is your problem if those edges exist — even when CISA never printed “Slack.”

Three relation types we fan out

Parent: the company that owns the product. Cloud host: where the SaaS runs. Identity: the IdP in front of it. These are hand-maintained, not inferred from a crawl, because a wrong edge is a false alarm and a missing edge is a missed Sunday.

Free plans see direct matches only — CISA named a tool you listed. Keep Track includes supplier matches. That split exists so the free tier stays quiet while paid accounts get the graph they are paying for.

This is not Nth-party TPRM

Black Kite and Bitsight score vendors from the outside. We do not. We will not tell you a supplier’s letter grade. We will tell you a KEV named them. If you need questionnaires and attack-surface ratings, buy that category. If you need a briefing when the cloud under your CRM is in KEV, stay here.

All guides · SaaS KEV tracker

Watch the SaaS that holds your data.

Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.

Start watching — freePricing