LOADING…
Platform  /  Supplier Assurance  ·  ● Live module
AI-driven third-party risk

Supplier Assurance,reimagined.

Built for UK public sector, CNI and nuclear. Built sovereign. Built deep. Built to defend you from the breach you didn't see coming.

See the platform
60% breaches via a third party £4.45m avg breach cost 205 controls · 21 domains
The problem

Your suppliers are your attack surface.

You can spend £10m on perimeter security and still get owned through a vendor with a £49 SaaS account.

What you think you control
Endpoints, firewalls, EDR, SIEM
Hardened cloud config, patched servers
MFA on every internal account
Annual penetration test
A mature CAF programme
What is actually exposed
Your payroll provider's HR portal
A 4-person SaaS vendor run from a living room
An MSP holding domain-admin keys
A code-signing certificate stolen 14 months ago
A subcontractor four levels deep you can't even name
The track record

The breach hall of fame.

Every one of these started with a trusted third party.

2020

SolarWinds

Nation-state implant in software updates

~18,000 organisations compromised, including US federal agencies. Industry-wide remediation estimated north of $100bn.

2021

Kaseya VSA

Ransomware via MSP management tooling

1,500+ downstream businesses encrypted in a single weekend. Schools, dentists, supermarkets — collateral damage.

2023

MOVEit / Cl0p

Zero-day in a file-transfer SaaS

2,700+ organisations breached, 90m+ records exposed — BBC, BA, Boots, Ofcom, US DoE and multiple US states.

2023

Okta

Compromised support-vendor credentials

Support session tokens stolen → 1Password, Cloudflare, BeyondTrust pivoted. Identity infrastructure weaponised.

2024

Change Healthcare

BlackCat ransomware via stolen Citrix creds

$872m Q1 hit to UnitedHealth. Pharmacy and claims offline for weeks. Data on roughly 1 in 3 Americans exposed.

2024

Synnovis

Qilin ransomware crippled NHS pathology

King's and Guy's & St Thomas' cancelled 10,000+ appointments. National blood appeal triggered. Patient harm reported.

None of these were exotic zero-days. All were preventable with proper supplier assurance.

The maths nobody admits

4 analysts. 8,000 suppliers.

Most public-sector teams aren't under-funded — they're under-staffed by an order of magnitude. A real, anonymised UK central-government department, 2026.

4
analysts in supplier assurance for a major UK department
8,000
tech suppliers needing assurance
14
properly assessed — 0.175% coverage
250yr
programme at current capacity

How E2E Risk multiplies four people into forty.

01

Pre-contract auto-tier

Two-axis criticality routes Tier-3/4 suppliers to a 30-minute self-attestation. Analyst time freed for the suppliers that matter.

02

Self-serve supplier portal

Suppliers complete questionnaires themselves. No chase-ups, no emailed PDFs, no spreadsheet version control.

03

AI evidence extraction

Multi-provider AI reads policies, certs and pen-test reports and extracts answers. Analysts review and sign off — they don't retype.

The module

A complete operating system for third-party risk.

Built for HMG, CNI and regulated industries — not a US Fortune-500 tool with a UK skin.

SAQ v30 engine

205 questions, 21 domains, conditional logic, evidence tracking, follow-up branching.

AI evidence extraction

Multi-provider — Anthropic, Azure OpenAI (UK), Groq, Google. Reads policies, certs, audit reports.

Self-serve supplier portal

Suppliers complete, upload evidence and track progress. The end of email tag.

Criticality assessment

Auto-tier suppliers with two-axis scoring. Deep diligence where it actually matters.

Threat library

Which suppliers are exposed to which threat actors and CVEs — mapped to MITRE ATT&CK.

Risk register & deficiencies

Every gap becomes a tracked risk with owner, due date and treatment. Closure with audit trail.

Outside-in scanner

BitSight-equivalent passive scanning — domain hygiene, certs, leaked creds, dark-web exposure.

Sovereign deployment

Azure UK-South/West. Customer-tenant for OFFICIAL-SENSITIVE. Source escrow available.

SAQ v30

The deepest supplier questionnaire on the market.

We didn't ship a 50-question form and call it good. We engineered the depth UK regulators expect — then tailored it so every supplier only sees what applies.

205
questions
21
domains
2,875
conditional follow-ups
51,842
pre-built answer options

Profile · criticality · applicability rules tailor every questionnaire — Tier-3/4 suppliers see ~30 questions; only Tier-1 / critical suppliers see the full depth.

Security Governance & RiskCompliance & LegalAccess Control & IdentityNetwork & InfrastructureOT / ICS SecurityVulnerability ManagementEndpoint ProtectionLogging & MonitoringCloud SecurityApplication SecurityAI GovernanceData ClassificationData Privacy & ComplianceData LifecycleCryptography & KeysBusiness Continuity & DRIncident ResponseHR SecurityPhysical SecuritySupply ChainSecurity Operations
Map once, report everywhere

One question. Every framework.

Most TPRM tools ship a generic form. Ours maps to every framework you'll ever be audited against.

Q · ACI008
"Do you enforce MFA for all privileged accounts and remote access to systems handling our data?"
This one question satisfies evidence for
ISO 27001:2022 A.5.15, A.5.17, A.8.5
NIST CSF 2.0 PR.AA-03, PR.AA-05
NCSC CAF B2.a, B2.b, B2.c
Cyber Essentials+ Access Control
GDPR Article 32 (technical measures)
DSPT Standard 8 (Secure Configuration)
The full lifecycle

The standard is 29 steps. They sell you 9.

NCSC, NIST SP 800-161r1, ISO/IEC 27036-2 and DORA all describe a full third-party lifecycle. Most TPRM tools cover a third of it. We cover all six phases.

Onboarding
Intake
Register
Profile
Tier
Assessment
Diligence
Scope
Self-assess
Indep. review
AI review
Findings
Deficiency
Risk register
Rem. plan
Rem. track
Rem. verify
Risk Decide
Risk score
Decision
Acceptance
Clauses
Verified
Monitoring
Dashboard
Cert expiry
Threat intel
Incident
Reassess
Offboarding
Exit plan
Data destr.
Access revoke
Archive
Exit test

Same standards. 3.2× the coverage.

Honest comparison

Why generic US TPRM tools fail UK public sector.

OneTrust, ServiceNow, BitSight, Risk Ledger, Vanta — benchmarked honestly.

CapabilityGeneric US TPRME2E Risk Supplier Assurance
UK CAF / NIS / GovAssureBolt-on content pack, partialNative, audit-ready
Question depth~50 generic questionsSAQ v30 — 205 Q, 21 domains
AI evidence extractionSingle proprietary modelMulti-provider, incl. Azure OpenAI UK
Data residencyUS SaaS, US dataUK-South / UK-West, customer-tenant
OFFICIAL-SENSITIVENot designed for itAir-gap-ready, customer-managed keys
Outside-in scoringSeparate, expensive add-onBuilt-in threat-centre scanner
Pricing$50–250k, supplier-count tiersModular, public-sector-friendly, G-Cloud
Sovereign by design

Deploy how you need. Up to SECRET.

The only TPRM platform on the UK market with a credible path from SaaS to fully-classified.

Managed SaaS · Fastest

OFFICIAL

UK Azure tenant
  • Hosted in our UK Azure tenant
  • UK-South + UK-West regions only
  • ISO 27001 / Cyber Essentials Plus
  • 30-day deploy, onboard suppliers same week
Customer-tenant · Sovereign

OFFICIAL-SENSITIVE

Your Azure subscription
  • Deployed into your own Azure subscription
  • Customer-managed encryption keys (CMK)
  • Your network policies, IAM and audit log
  • Splunk / ServiceNow deployment pattern
On-prem / air-gapped · Max secure

SECRET-capable

Your data centre
  • Deploys to your own DC or classified cloud
  • Air-gapped — no outbound internet
  • Manual licence + threat-feed updates
  • Source escrow available for full audit

Risk Ledger · SIG · Vanta · OneTrust · BitSight are SaaS-only. None deploy on-prem. None go classified.

Native to UK frameworks

Not bolted on. Built in.

Built for the regulators you actually answer to — framework mapping & assurance evidence, not a certification claim.

NCSC CAF v4NCSC 12 Supply-Chain PrinciplesNIS / NIS2Cyber Essentials+ISO 27001:2022ISO 27036-2NIST SP 800-161r1NIST CSF 2.0GovAssureDORA Art. 28-30GDPR / UK DPA 2018DSPT
70%
Less analyst chase-up time
95%
Faster audit-pack assembly
3–5×
Throughput per analyst
60%
Faster supplier onboarding
Get started

Don't be the next headline.

Get supplier assurance you can prove, defend, and explain to a regulator at 6am on a Saturday.

30-min discovery

We map your current supplier portfolio against tiers in one session.

Sandbox in 48h

Hands-on access to SAQ v30, AI extraction and the supplier portal.

G-Cloud / DPS

Procurement-ready. We sit on the right frameworks and route accordingly.