Infrastructure & Supply Chain

Map dependency and concentration risk down to datacenters, IXPs, and submarine cables, with runnable workflows and recipes for compliance evidence.

Updated July 2026Infrastructure & Supply Chain

Infrastructure & Supply Chain Documentation

Third-party risk assessment usually stops at the contract. The layers that decide whether a vendor is actually resilient, which networks announce its prefixes, which facilities those routes pass through, which cable systems carry the traffic, sit in datasets that were never built to join, let alone join to a sanctions list or a jurisdiction map. WhisperGraph holds the network, physical, and ownership layers as one connected graph, so a single traversal walks from a vendor domain to the datacenters, internet exchanges, and submarine cables it depends on.

That walk produces the evidence NIS2, DORA, and ISO 27001 ask for. Concentration no questionnaire surfaces, such as two critical vendors landing in the same facility or riding the same cable system, becomes a query you can run and a result you can hand to an auditor. The same pass crosses ownership against sanctions feeds and maps the countries the infrastructure actually sits in, so jurisdiction and data-sovereignty review runs on observed hosting rather than declared hosting.

Run these workflows in your browser

Every workflow below runs live at /use-cases and opens with a result already loaded; swap in your own vendor domain, ASN, or country code to re-run it. Anonymous runs are capped at 2 hops; a free API key raises that to 3, no card required.

WorkflowWhat it does
Infrastructure Concentration RiskGrade an org's hosting footprint for single-provider and single-region concentration, the fourth-party risk DORA and NIS2 ask about.
Digital Infrastructure MappingOne indicator mapped to its real operator and full footprint: subdomains, DNS and mail providers, routing, physical location, cloud vendors, and a concentration grade.
Sanctions ScreeningScreen a domain, IP, or ASN against OFAC SDN and sanctions-linked threat feeds, with hosting reputation and jurisdiction attached.
M&A Digital-Footprint DiligenceAn external view of a target's infrastructure, footprint size, jurisdiction, and ownership. No cooperation from the target needed.
VASP Due DiligenceAssess a counterparty crypto exchange's hosting, real owner, jurisdiction, and sanctions exposure before transacting.
Jurisdiction & Data SovereigntyCountry-of-hosting and cloud-region spread for an org's estate, for data-sovereignty and jurisdiction review.
Datacenter & IXP ConcentrationSurface an ASN's facility and internet-exchange concentration and its co-tenants: the physical single points of failure.
Submarine-Cable ConcentrationExtend the same audit to cable landings and submarine cables, where one landing station can carry an ASN's entire intercontinental path.
CDN PoP Footprint & ResilienceA CDN operator's full point-of-presence inventory, the ASNs that carry it, and the facilities it shares with rival CDNs, with a geographic-concentration read.
DNS-Root SovereigntyWhich of the 13 DNS root letters have in-country anycast instances for a given country, which ASNs host them, and a resilience grade.

Routing-side dependency workflows, such as transit dependency, ROA expiry, and route health, sit under Network & Routing.

Copy-paste recipes

The recipe pages give you the same assessments as Cypher you run yourself, with each query's depth and anchoring explained:

  • Compliance Evidence covers registrar verification, jurisdiction and data-residency checks, portfolio-wide DNSSEC and email-posture audits, and sanctions screening, each producing timestamped output you can attach to an audit file.
  • Vendor & Portfolio Risk builds the underwriting view: an external posture snapshot per vendor, shared-provider exposure across a portfolio, and the blast radius a single provider failure would reach.

The pivots these pages are built from are cataloged in Cross-Layer Patterns. The physical-internet layer itself, facilities, internet exchanges, submarine cables and their landings, and cloud regions, is described on the Whisper Graph page.