Add up every SaaS subscription your startup pays for. Go ahead. We will wait. If you are like most 30-person startups, the number is somewhere between $15,000 and $40,000 per month. And if nobody is actively managing these subscriptions, you are overpaying by 20 to 40 percent. That is $3,000 to $16,000 per month in waste.
How vendor sprawl happens
It starts innocently. An engineer signs up for a monitoring tool on a free trial. A salesperson subscribes to a prospecting platform. The marketing team buys a design tool. Each purchase makes sense in isolation. But nobody is tracking the total, checking for overlap, or negotiating contracts. Once those vendors start holding customer data, the same sprawl becomes a security problem, which is what third party risk management addresses.
Within a year, you have three different project management tools (Jira for engineering, Asana for marketing, Monday for the sales team), two analytics platforms, two design tools, and six different communications tools. Each one has a different billing owner, a different contract term, and a different renewal date.
The vendor audit
Start by building a complete inventory of every paid tool. Check credit card statements, expense reports, and accounts payable. You will find subscriptions that nobody remembers purchasing. We routinely find startups paying for tools that were adopted by employees who left the company months ago.
For each tool, document: what it does, who uses it, how many seats are licensed vs. how many are actually used, the monthly cost, the contract renewal date, and whether there is a cancellation penalty. This inventory is your baseline for optimization.
Consolidation opportunities
Look for overlapping functionality. Do you need Datadog and New Relic? Probably not. Can one project management tool serve all teams? Usually yes, if you invest a day in configuring it. Are you paying for Zoom and Google Meet? Pick one.
Consolidation requires buy-in from the teams using the tools. Do not unilaterally cancel a tool that a team relies on. Talk to them, understand their workflows, and find a solution that works. Sometimes the "redundant" tool has a specific feature that the primary tool lacks. In that case, investigate whether the primary tool can be configured to provide that feature, or whether the cost of the redundant tool is justified by the productivity it enables.
Negotiation tactics that work
Most SaaS vendors offer significant discounts that are never advertised. Here are tactics that consistently work:
Annual contracts: Committing to an annual contract typically saves 15 to 25 percent compared to monthly billing. If you are confident you will use the tool for the next year, switch to annual billing.
Multi-year contracts: Some vendors offer 30 to 40 percent discounts for two or three year commitments. Only do this for tools that are deeply embedded in your workflow and unlikely to be replaced.
Competitive quotes: Before renewing, get a quote from the competitor. Tell your vendor rep that you are evaluating alternatives. Sales reps have discretion to offer retention discounts, but they will not offer them proactively.
Right-sizing: If you are paying for 50 seats but only 30 people use the tool, negotiate down to 35 seats. Pay for what you use, not what you might use someday.
Startup programs: Many SaaS vendors offer startup programs with discounted pricing or free tiers. AWS, GCP, Datadog, Notion, Figma, and dozens of others have programs that can save you thousands per year. Apply for every one that is relevant.
Ongoing management
Do a vendor review quarterly. Check usage data for every tool. If a tool has low adoption, either invest in training (if the tool is valuable) or cancel it (if it is not). Track renewal dates 60 days in advance so you have time to negotiate before auto-renewal kicks in. Assign vendor management as a responsibility to a specific person, even if it is only 2 hours per month. The ROI of that time is enormous.
Need help with vendor management?
traztech helps startups audit their vendor portfolio, negotiate better contracts, and build systems for ongoing vendor management that prevent overspending.
Book a free strategy callThe Second Reason to Do This, and It Is the Expensive One
Cost is the reason most founders start a vendor inventory. Compliance is the reason they have to finish it. The moment you sell to an enterprise buyer or start a SOC 2 or ISO 27001 project, that list of tools stops being a spend problem and becomes a control. Both auditors ask the same opening question: show me your list of third parties and how you decided which ones matter.
If the answer is a credit card statement, the audit gets slower. The list an auditor wants is not every tool you pay for. It is every third party that stores, processes, or can reach customer data, plus every one whose failure would take your product down. That list is usually shorter than the finance list and contains at least one thing finance never saw, because it was free.
Tier by Data Access, Not by Invoice Size
The most common structural mistake is ranking vendors by annual spend. Your cloud bill and your $19 per month log shipper both sit in the customer data path. Your sales intelligence platform probably does not.
Three tiers is enough for a startup. Tier 1 is anything that stores, processes, or transmits customer data, or that could take production down: cloud provider, database host, payment processor, email delivery, error tracking that captures request payloads, and any AI service you pipe customer content into. These get a full review before adoption, an annual reassessment, a signed data processing agreement, and a place on your public subprocessor list. Tier 2 is anything holding company confidential data but not customer data: your HR platform, your code hosting if it is separate from Tier 1, your password manager, your finance stack. These get a lighter review and a review every two years. Tier 3 is everything else, which needs to exist on the list and nothing more.
Write down the rule that assigns a tier and apply it consistently. A tiering rule with three vendors in the wrong bucket is a conversation with your auditor. No tiering rule at all is a finding.
Reading a SOC 2 Report Instead of Filing It
Collecting vendors' SOC 2 reports is the part everyone does. Reading them is the part almost nobody does, and it is where the actual risk transfer breaks down.
Four things to check on every Tier 1 report. First, the period covered and whether it is Type I or Type II. A Type I says the controls were designed properly on one day; a Type II says they operated across a period, which is the only version worth much. If the period ended nine months ago, ask for a bridge letter. Second, section four, where the auditor lists exceptions. Every real report has some, and a report with none across twelve months is either exceptional discipline or a firm that does not test hard. Third, the complementary user entity controls, usually a short list near the back. These are the controls the vendor is explicitly telling you are your job, not theirs. Enabling MFA on your account of their product is a classic one. If you have not read that list, you have assumed responsibilities you do not know about, and your own auditor may well ask about them. Fourth, whether the report is carve-out or inclusive, meaning whether the vendor's own subprocessors were covered or excluded.
Ten minutes per Tier 1 report, once a year, with the findings written into a two-line note in your vendor record. That is the whole job, and it is the difference between a vendor file that satisfies an auditor and one that proves you can download things.
The Subprocessor List Is a Contract Term You Already Signed
Most enterprise SaaS agreements and every GDPR-aligned data processing agreement contain a clause requiring you to maintain a current list of subprocessors and to notify customers before adding new ones, often with 30 days' notice and a right to object. Startups sign these in the deal room and then forget the operational commitment attached.
Six months later an engineer adds an observability tool that receives request bodies, and you are in breach of a term with every enterprise customer on your book. Nobody notices until a renewal review, when a diligent buyer compares your published subprocessor page against the vendors named in your architecture documentation. Under PIPEDA the transfer of personal information to a third party for processing carries an accountability obligation that stays with you, and Quebec's Law 25 adds disclosure expectations around where information is processed and by whom. The practical control is a single gate: no new tool touches customer data until it is on the subprocessor page and the notification obligation has been checked.
The AI Tools Nobody Put on the List
The fastest growing category of unmanaged vendor risk in startups is AI services adopted individually. A support lead pastes ticket transcripts into a summarization tool. An engineer wires a customer-facing feature to a model API on the default plan, which in some products means the provider may retain inputs. A sales rep runs call recordings through a transcription service nobody contracted.
These rarely appear in a finance-led inventory because they are free, cheap, or expensed on a personal card. They are Tier 1 by any honest reading of the tiering rule, since customer data leaves your boundary. Ask the question directly in your quarterly review: what did you paste customer data into this quarter. The answers are usually honest and usually surprising.
Exit Is Part of the Control
Onboarding a vendor gets attention because someone wants the tool. Offboarding gets none, and it is where data sits forever. Cancelling a Tier 1 vendor means the same tasks every time: revoke API keys and integrations, remove the SSO application, confirm deletion of your data, request written confirmation where your contract entitles you to it, remove the vendor from the subprocessor page, and note the termination date.
The written deletion confirmation is the one people skip, and it matters after an incident. If a vendor you left two years ago gets breached and your data was still in it, having the answer in writing is the difference between an awkward disclosure and a serious one.
When the Vendor Fails Review and You Cannot Replace It
This happens more than the tidy version of vendor management admits. A small vendor is embedded in your product, has no SOC 2, will not sign your DPA amendments, and replacing it is a two-quarter engineering project you cannot fund.
Do not pretend the review passed. Document the risk, name the specific gaps, get an accountable executive to accept it in writing with a review date, and compensate where you can: restrict what data the vendor receives, scope its credentials down, and keep a rough plan for what you would do if it disappeared. An auditor reading an accepted risk with a named owner and a date sees a functioning risk process. One reading a vendor file that quietly claims a review passed sees something worse than a gap.
When You Should Not Hire Anyone for This
Vendor management is one of the few compliance areas where a competent operations person genuinely outperforms an outside firm, and we would rather say so than sell you something. Under about 40 vendors, with one person owning the list, the whole system is a spreadsheet with eight columns, a quarterly reminder, and a rule that new tools touching customer data get approved before purchase. Buying a third-party risk platform at that size is paying subscription fees to manage your subscription fees.
The point where outside help earns its keep is narrower than firms like ours imply. It is worth it when you are inside an audit window and the vendor file is holding up fieldwork, when an enterprise buyer is asking subprocessor questions you cannot answer, or when nobody internally can read a SOC 2 report and decide whether an exception matters. If that is where you are, our compliance work covers the vendor control inside a readiness track, and the vendor register in the free traztech Workspace holds the list and its evidence whether or not you ever hire us. If your problem is genuinely that you are overpaying for three project management tools, cancel two of them and keep your money.
Stuck on a buyer review? We answer SIG, CAIQ and bespoke security questionnaires, and set up the trust center that stops most of them arriving.
Talk to usOr talk about a retainer