{"product_id":"automated-vendor-security-risk-audit-with-n8n-openai","title":"Automated Vendor Security Risk Audit with n8n + OpenAI","description":"\u003ch3\u003eAutomated vendor security risk audits with n8n + OpenAI\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow automatically audits a vendor’s security posture on a schedule—checking website security signals and domain details, pulling Have I Been Pwned breach data, and using \u003cstrong\u003eOpenAI (gpt-4o-mini)\u003c\/strong\u003e to generate a structured risk rating. Results are logged to \u003cstrong\u003eGoogle Sheets\u003c\/strong\u003e and escalated via \u003cstrong\u003eSlack\u003c\/strong\u003e and \u003cstrong\u003eGmail\u003c\/strong\u003e when risk is High or Critical.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSchedules and collects audit inputs:\u003c\/strong\u003e sets the vendor name, website, contact email, data access level, and audit date.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003ePerforms security checks:\u003c\/strong\u003e fetches the vendor website response headers and page content to compute a security header score, runs a \u003cstrong\u003eprivacy-policy keyword check\u003c\/strong\u003e, and queries \u003cstrong\u003eRDAP\u003c\/strong\u003e to estimate domain age.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEnriches breach context:\u003c\/strong\u003e pulls the \u003cstrong\u003eHave I Been Pwned\u003c\/strong\u003e breaches list for the vendor domain and counts relevant breaches.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eGenerates a structured risk assessment:\u003c\/strong\u003e sends a compiled summary (header score, estimated domain age, breach count, keyword check) to an \u003cstrong\u003eOpenAI gpt-4o-mini agent\u003c\/strong\u003e to return an overall risk score, risk tier, executive summary, and recommendations.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTracks results in a risk register:\u003c\/strong\u003e calculates the next audit date based on the risk tier and appends\/updates the vendor record in a Google Sheet titled \u003cem\u003eVendor Risk Register\u003c\/em\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEscalates critical findings:\u003c\/strong\u003e if risk tier is \u003cstrong\u003eHigh\u003c\/strong\u003e or \u003cstrong\u003eCritical\u003c\/strong\u003e, posts a \u003cstrong\u003eSlack\u003c\/strong\u003e alert and sends an email via \u003cstrong\u003eGmail\u003c\/strong\u003e to the security team.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eFailure visibility:\u003c\/strong\u003e if the workflow fails or the AI agent errors, it posts an error alert to \u003cstrong\u003eSlack\u003c\/strong\u003e.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eVendor onboarding: run recurring \u003cstrong\u003evendor security risk audits\u003c\/strong\u003e before granting data access.\u003c\/li\u003e\n  \u003cli\u003eThird-party monitoring: detect changes in security headers, domain age signals, and breach exposure over time.\u003c\/li\u003e\n  \u003cli\u003eSecurity operations: maintain a centralized \u003cstrong\u003erisk register\u003c\/strong\u003e and trigger targeted reviews for High\/Critical vendors.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003en8n nodes\/actions: \u003cstrong\u003eif\u003c\/strong\u003e, \u003cstrong\u003eset\u003c\/strong\u003e, \u003cstrong\u003ecode\u003c\/strong\u003e, \u003cstrong\u003egmail\u003c\/strong\u003e, \u003cstrong\u003eslack\u003c\/strong\u003e, \u003cstrong\u003esticky note\u003c\/strong\u003e\n\u003c\/li\u003e\n  \u003cli\u003eIntegrations: \u003cstrong\u003eOpenAI (gpt-4o-mini)\u003c\/strong\u003e, \u003cstrong\u003eGoogle Sheets\u003c\/strong\u003e (OAuth2), \u003cstrong\u003eSlack\u003c\/strong\u003e, \u003cstrong\u003eGmail\u003c\/strong\u003e\n\u003c\/li\u003e\n  \u003cli\u003eData sources: website header\/content checks, \u003cstrong\u003eRDAP domain age lookup\u003c\/strong\u003e, and \u003cstrong\u003eHave I Been Pwned\u003c\/strong\u003e breach list\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45950287904947,"sku":"N8N-19118","price":44.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/rglEPt7XyhhLf0Qv9CE1d_z2FbZJ8E.png?v=1788514401","url":"https:\/\/buyflowscripts.com\/products\/automated-vendor-security-risk-audit-with-n8n-openai","provider":"N8N Commerce","version":"1.0","type":"link"}