Infrastructure & Supply Chain
Map dependency and concentration risk down to datacenters, IXPs, and submarine cables, with runnable workflows and recipes for compliance evidence.
Infrastructure & Supply Chain Documentation
Third-party risk assessment usually stops at the contract. The layers that decide whether a vendor is actually resilient, which networks announce its prefixes, which facilities those routes pass through, which cable systems carry the traffic, sit in datasets that were never built to join, let alone join to a sanctions list or a jurisdiction map. WhisperGraph holds the network, physical, and ownership layers as one connected graph, so a single traversal walks from a vendor domain to the datacenters, internet exchanges, and submarine cables it depends on.
That walk produces the evidence NIS2, DORA, and ISO 27001 ask for. Concentration no questionnaire surfaces, such as two critical vendors landing in the same facility or riding the same cable system, becomes a query you can run and a result you can hand to an auditor. The same pass crosses ownership against sanctions feeds and maps the countries the infrastructure actually sits in, so jurisdiction and data-sovereignty review runs on observed hosting rather than declared hosting.
Run these workflows in your browser
Every workflow below runs live at /use-cases and opens with a result already loaded; swap in your own vendor domain, ASN, or country code to re-run it. Anonymous runs are capped at 2 hops; a free API key raises that to 3, no card required.
| Workflow | What it does |
|---|---|
| Infrastructure Concentration Risk | Grade an org's hosting footprint for single-provider and single-region concentration, the fourth-party risk DORA and NIS2 ask about. |
| Digital Infrastructure Mapping | One indicator mapped to its real operator and full footprint: subdomains, DNS and mail providers, routing, physical location, cloud vendors, and a concentration grade. |
| Sanctions Screening | Screen a domain, IP, or ASN against OFAC SDN and sanctions-linked threat feeds, with hosting reputation and jurisdiction attached. |
| M&A Digital-Footprint Diligence | An external view of a target's infrastructure, footprint size, jurisdiction, and ownership. No cooperation from the target needed. |
| VASP Due Diligence | Assess a counterparty crypto exchange's hosting, real owner, jurisdiction, and sanctions exposure before transacting. |
| Jurisdiction & Data Sovereignty | Country-of-hosting and cloud-region spread for an org's estate, for data-sovereignty and jurisdiction review. |
| Datacenter & IXP Concentration | Surface an ASN's facility and internet-exchange concentration and its co-tenants: the physical single points of failure. |
| Submarine-Cable Concentration | Extend the same audit to cable landings and submarine cables, where one landing station can carry an ASN's entire intercontinental path. |
| CDN PoP Footprint & Resilience | A CDN operator's full point-of-presence inventory, the ASNs that carry it, and the facilities it shares with rival CDNs, with a geographic-concentration read. |
| DNS-Root Sovereignty | Which of the 13 DNS root letters have in-country anycast instances for a given country, which ASNs host them, and a resilience grade. |
Routing-side dependency workflows, such as transit dependency, ROA expiry, and route health, sit under Network & Routing.
Copy-paste recipes
The recipe pages give you the same assessments as Cypher you run yourself, with each query's depth and anchoring explained:
- Compliance Evidence covers registrar verification, jurisdiction and data-residency checks, portfolio-wide DNSSEC and email-posture audits, and sanctions screening, each producing timestamped output you can attach to an audit file.
- Vendor & Portfolio Risk builds the underwriting view: an external posture snapshot per vendor, shared-provider exposure across a portfolio, and the blast radius a single provider failure would reach.
The pivots these pages are built from are cataloged in Cross-Layer Patterns. The physical-internet layer itself, facilities, internet exchanges, submarine cables and their landings, and cloud regions, is described on the Whisper Graph page.