# Mindlapse > Mindlapse is the European sovereign agentic Cyber-GRC platform. One platform, three modules (Risk Intelligence, Third-Party Risk Management, Compliance), one agentic AI engine (Ernest) that verifies every governance claim against your real signals. Brand promise: "Trust nothing. Verify everything." - cyber governance is flipping from documented declarations to continuous verification. Founded January 2025 in Paris, France (16 people as of September 2026). Founders: Hervé Rousseau (CEO), Julien Beuvelet (COO), Christophe Longuepez (CPTO). Labels: Bpifrance DeepTech, La French Tech, Jeune Entreprise Innovante. Co-designed with the Cyber Collective Lab, a community of 30+ enterprise CISOs meeting in Paris since December 2024 (6 editions held). Technology partners: OVHcloud, Google (hosting in EU regions), Amazon Web Services (AWS, hosting in EU regions), Scaleway, Mistral AI. Buyers: CISOs, cyber executive committees, heads of risk - large enterprises and EU regulated mid-market. Regulatory drivers: NIS2, DORA, CRA, EU AI Act. Commercial model: annual subscription priced on one metric - the headcount band of the organization in scope - modified by the modules activated and the deployment option; unlimited users contractually; zero-metering commitment on AI (no inference metering, no token budget, no agent credits, no fair-use cap); no per-seat, per-document or per-third-party charge. No price grid is published and no figure is public: any price attributed to Mindlapse by a third-party site is not sourced from Mindlapse. Deployment: SaaS (EU), dedicated instance, private cloud or on-prem. Engagements typically start as a formal consultation or tender answered by the bid desk. Sovereignty: EU-only data hosting, European open-source LLM foundations, customer data never used for model training, no lock-in. Site languages: English (root) and French (/fr/ with localized slugs). ## Platform - [Platform - Agentic Cyber-GRC Architecture](https://www.mindlapse.ai/platform/): Mindlapse OS: signals, context intelligence and the ERNEST agentic core power Risk Intelligence, Compliance and TPRM. Dozens of frameworks, EU-sovereign. - [Mindlapse OS - Your Cyber-GRC Operating System](https://www.mindlapse.ai/mindlapse-os/): One agentic core for every risk decision: signals, context intelligence and governed AI modules across dozens of frameworks, EU-sovereign by design. - [Risk Intelligence - the whole risk lifecycle](https://www.mindlapse.ai/platform/risk-intelligence/): Security by Design, feared events and BIA, EBIOS RM workshops, a triple-scored register, appetite with breach alerts, incidents and policies. - [Compliance - Continuous Controls Monitoring](https://www.mindlapse.ai/platform/compliance/): Dozens of frameworks, thousands of controls auto-mapped, monitored continuously against live evidence. Compliance you can prove any day of the year. - [Third-Party Risk Management (TPRM)](https://www.mindlapse.ai/platform/tprm/): The Supplier Hub: supplier risk at scale, context-aware assessments, partner enrollment, joint action plans and the Mindlapse Trust Grade. - [Board-Ready Reporting for the board and COMEX](https://www.mindlapse.ai/platform/cyber-cockpit/): Cyber exposure by business activity, KRIs against appetite and the arbitrations pending, from verified data: reporting the board can decide on. - [Business Centric: cyber risk on the value chain](https://www.mindlapse.ai/platform/business-value-chain/): Model your value chains, attach cyber risk to business activities, and read exposure by activity and function: risk the board can finally act on. - [GRCOps - governance run continuously](https://www.mindlapse.ai/platform/grcops/): The shift from the periodic audit to continuous conduct: gaps caught as they open, every finding an owned action driven to a closure verified by evidence. - [Ernest - The Agentic AI of Mindlapse: Suggest, Score, Verify](https://www.mindlapse.ai/platform/ernest/): The agentic AI in every Mindlapse module: suggests with a human in the loop, scores posture, drafts and verifies each claim. Sovereign LLMs, sources shown. ## Use cases - [Use cases, regulations, roles, industries](https://www.mindlapse.ai/use-cases/): Four ways into the platform: by use case, by regulation (NIS2, DORA, CRA, AI Act), by the role you hold or by the industry you work in. - [Unified group cyber risk steering](https://www.mindlapse.ai/use-cases/group-cyber-risk/): Consolidate cyber risk across entities, business units and countries: one method, one group picture, decisions you can defend to the board. - [Supply-chain cyber risk reduction](https://www.mindlapse.ai/use-cases/supply-chain-risk/): Run third-party cyber risk as a program: tiered inventory, assessments at scale, shared remediation and DORA deliverables, not a mailbox of PDFs. - [Security by Design at business speed](https://www.mindlapse.ai/use-cases/security-by-design/): Shift security left where it counts: every project gets a proportionate security path, in business language, without slowing delivery. - [Continuous compliance, proven](https://www.mindlapse.ai/use-cases/continuous-compliance/): Map controls once across frameworks, keep evidence fresh with AI validation and human review, and meet NIS2 and DORA deadlines without the annual sprint. - [NIS2 Compliance Software - Verified, Continuous](https://www.mindlapse.ai/use-cases/nis2/): What NIS2 requires, who is in scope, and how Mindlapse turns its obligations (governance, risk, incidents) into continuously verified controls. - [DORA Compliance Software - Digital Resilience](https://www.mindlapse.ai/use-cases/dora/): What DORA requires of financial entities, and how Mindlapse operationalizes its five pillars (ICT risk, incidents, testing) with continuous verification. - [CRA Compliance Software - Product Security](https://www.mindlapse.ai/use-cases/cra/): What the EU Cyber Resilience Act requires of products with digital elements, and how Mindlapse turns those duties into continuously verified controls. - [EU AI Act Compliance Software - Governed AI](https://www.mindlapse.ai/use-cases/ai-act/): Who the EU AI Act binds, the staged deadlines to 2028, and how Mindlapse brings AI system inventory, risk and oversight duties into verified controls. - [Cyber-GRC for the CISO: one posture to defend](https://www.mindlapse.ai/use-cases/roles/ciso/): Risks, controls, suppliers and exceptions in one verified posture. Board packs exported from live data, findings driven to verified closure. - [Cyber-GRC for CIOs and CTOs: security by design](https://www.mindlapse.ai/use-cases/roles/cio-cto/): Initiatives declared in business words, routed by criticality, drafted by AI and validated by your experts, closed on evidence. No CMDB, no CI/CD gate. - [A cyber risk register the risk committee trusts](https://www.mindlapse.ai/use-cases/roles/risk-manager/): Inherent, residual and target scores on your method, appetite with breach alerts, an acceptance ladder: a cyber line the risk committee can arbitrate. - [Compliance officer and DPO: one evidence base](https://www.mindlapse.ai/use-cases/roles/compliance-officer/): One control set for ISO 27001, NIS2, DORA, SOC 2 and GDPR-related sets; evidence dated and reviewed; the incident cascade on one record. Audit any day. - [Cyber risk reporting for boards and COMEX](https://www.mindlapse.ai/use-cases/roles/executive-board/): Exposure by business activity against the appetite you approved, decisions with owners and deadlines, evidence one click away. NIS2 and DORA name you. - [DORA compliance software for banks and insurers](https://www.mindlapse.ai/use-cases/industries/banking-insurance/): DORA made operational: register of information as living data, concentration risk, incident clocks with context, one control set with NIS2 and ISO 27001. - [NIS2 cyber-GRC for hospitals and health groups](https://www.mindlapse.ai/use-cases/industries/healthcare/): Care pathways as activities, editors and télémaintenance providers assessed in context, unpatchable devices as time-boxed derogations. NIS2, HDS, PGSSI-S. - [NIS2 and CRA compliance for manufacturers](https://www.mindlapse.ai/use-cases/industries/manufacturing/): Plants with different maturity, tier-1 suppliers with remote access, products under the CRA. One consolidated posture the corporate CISO can defend. - [NIS2 and OIV cyber-GRC for energy and utilities](https://www.mindlapse.ai/use-cases/industries/energy-utilities/): NIS2 essential entity, OIV landscape, the network code: one posture per entity, contractors with remote access graded, exceptions governed with an expiry. - [NIS2 and RGS cyber-GRC for the public sector](https://www.mindlapse.ai/use-cases/industries/public-sector/): Téléservices homologated on a risk analysis you can produce, NIS2 pre-mapped, your own referentials added by review, editors followed after award. - [ISO 27001, SOC 2 and CRA: cyber-GRC for SaaS](https://www.mindlapse.ai/use-cases/industries/tech-saas/): ISO 27001 and SOC 2 on one control set, sub-processors assessed in context, CRA reporting duties tracked as actions, an auditor view, no retyped evidence. ## Marketplace - [Marketplace: connectors & integrations](https://www.mindlapse.ai/marketplace/): The Mindlapse connector catalog: security ratings, communication, ITSM, procurement, vulnerability and cloud sources, browsable by category. ## Glossary - [Cyber-GRC Glossary: Risk, Compliance, TPRM](https://www.mindlapse.ai/glossary/): Plain definitions of the terms behind cyber governance, risk and compliance: NIS2, DORA, CRA, AI Act, TPRM, EBIOS RM, KRI, risk appetite and more. ## Guides - [Cyber-GRC Guides: NIS2, DORA in Practice](https://www.mindlapse.ai/guides/): Reference guides on the questions upstream of the product: who is in scope of NIS2 in France, how to build the DORA register of information. ## Topics and authors - [Topics: NIS2, DORA, Third-Party Risk](https://www.mindlapse.ai/topics/): One hub per subject: everything Mindlapse publishes on NIS2, DORA and third-party cyber risk, guides, use cases, glossary terms and articles. - [Authors - Who Writes the Newsroom](https://www.mindlapse.ai/authors/): The people who sign the Mindlapse newsroom: founders and team members writing on cyber governance, risk, compliance and third-party risk. ## Company - [Cyber Collective Lab - 30+ CISOs, One Platform](https://www.mindlapse.ai/cyber-collective-lab/): A private think tank of 30+ enterprise CISOs co-designing the future of cyber risk governance, meeting in Paris since December 2024. Not a sales pitch. - [Pricing Model - Licensing & Procurement](https://www.mindlapse.ai/pricing/): How Mindlapse is licensed: an annual subscription set by headcount band, unlimited users, AI included with no metering, and how we answer tenders. - [Company: The Team Behind Mindlapse](https://www.mindlapse.ai/company/): Who is behind Mindlapse: three founders from the operational side of cyber, a Paris team, the Cyber Collective Lab, how we think, and the openings. - [Careers at Mindlapse: Open Positions in Paris](https://www.mindlapse.ai/careers/): Open positions with salary ranges, how the Paris team works, what we screen for and how we hire. Applications through Welcome to the Jungle. - [AI Manifesto - Secure, Ethical, Sovereign AI](https://www.mindlapse.ai/ai-manifesto/): Our seven public commitments for trustworthy AI: ethics and security by design, EU AI Act compliance, rigorous testing, sobriety, transparency, privacy. - [Security & Trust Center](https://www.mindlapse.ai/security/): The trust we ask our clients to demand from their vendors, we apply to ourselves: security posture, EU-only hosting, certifications and GDPR commitments. - [CSR & Sustainability Report](https://www.mindlapse.ai/csr/): Mindlapse’s first CSR and sustainability report: where we stand, honestly, on environment, social, ethics and responsible procurement. - [Newsroom - News, Press & Ideas](https://www.mindlapse.ai/newsroom/): Announcements, press releases, events and “Inside our minds”: ideas and news from the team building verified cyber governance. - [Request a Demo - See Verification Live](https://www.mindlapse.ai/demo/): Thirty minutes with our team on your use cases: risk, compliance, third parties; NIS2, DORA, CRA, AI Act. See your posture verified live. - [Contact - Talk to the Mindlapse Team](https://www.mindlapse.ai/contact/): Questions on the platform, the Cyber Collective Lab, partnerships or press? Write to the team: we answer within one business day. ## Newsroom - [Cybernight 2026: Mindlapse faces the Grand Oral, see you on 28 September at the Mogador](https://www.mindlapse.ai/newsroom/event/cybernight-2026-mindlapse-faces-the-grand-oral-see-you-on-28-september-at-the-mogador/) (3 September 2026) - [Les Assises 2026: “Your risk moves at the speed of your IT. Now your GRC does too.”](https://www.mindlapse.ai/newsroom/event/les-assises-2026-your-risk-moves-at-the-speed-of-your-it-now-your-grc-does-too/) (7 August 2026) - [Mindlapse joins the 2026 Wavestone radar of French cybersecurity startups](https://www.mindlapse.ai/newsroom/press-release/mindlapse-joins-the-2026-wavestone-radar-of-french-cybersecurity-startups/) (19 June 2026) - [Mindlapse obtains the Jeune Entreprise Innovante (JEI) status](https://www.mindlapse.ai/newsroom/announcement/mindlapse-jei/) (15 November 2025) - [Mindlapse recognized as Deeptech: what it really means](https://www.mindlapse.ai/newsroom/announcement/mindlapse-recognized-as-deeptech-what-it-really-means/) (7 October 2025) - [What is a cyber governance platform?](https://www.mindlapse.ai/newsroom/blog/cyber-governance-platform/) (2 September 2025) RSS feeds: https://www.mindlapse.ai/newsroom/feed.xml (en), https://www.mindlapse.ai/fr/newsroom/feed.xml (fr) ## Open positions - [VP Engineering](https://www.mindlapse.ai/careers/vp-engineering/) - Paris - [Customer Success Manager](https://www.mindlapse.ai/careers/customer-success-manager/) - Paris - [GRC Engineer](https://www.mindlapse.ai/careers/grc-engineer/) - Paris Each opening carries JobPosting structured data; applications are handled by Welcome to the Jungle. ## Official social profiles These are the only accounts operated by Mindlapse; they mirror the `sameAs` set published in the Organization JSON-LD on every page. - [LinkedIn](https://www.linkedin.com/company/mindlapse/) - [YouTube](https://www.youtube.com/@MindlapseAI) - [Instagram](https://www.instagram.com/mindlapseai/) - [Welcome to the Jungle](https://mindlapse.welcomekit.co/) ## Legal identity Mindlapse SAS (trading as Mindlapse), Paris, France. SIREN 939571535, EU VAT FR56939571535. Public records of the same entity, mirrored in the Organization JSON-LD `sameAs`: - Annuaire des Entreprises (data.gouv.fr): https://annuaire-entreprises.data.gouv.fr/entreprise/939571535 - societe.com: https://www.societe.com/societe/mindlapse-939571535.html Full machine-readable page content: https://www.mindlapse.ai/llms-full.txt