Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

ERNEST · THE AI OF MINDLAPSE

The AI that suggests, scores and verifies. And shows its work.

Ernest is the agentic AI embedded in every Mindlapse module. It drafts what your team would otherwise write, scores what needs a number, and verifies what is claimed, against live signals and your knowledge graph. Sources shown, human in the loop. Every time.

What is Ernest?

Ernest

The agentic AI of the Mindlapse platform

Ernest is the agentic AI embedded in every Mindlapse module. It suggests what your team would otherwise write (likelihoods, scenarios, treatments, control mappings, questionnaire answers), scores what needs a number (risk, supplier Trust Grades, maturity), drafts what needs a text, and verifies every governance claim against the evidence you upload or connect, the signals your connectors bring in and your cyber knowledge graph, sources shown.

It runs specialized agents on sovereign open-source LLMs, never trains on customer data, and never decides alone: every suggestion carries a confidence level, a human accepts or rejects it, and the decision is written to the audit trail, then re-checked continuously.

Never
trains on customer data
Sovereign
open-source LLMs, hosted in the EU
Human in the loop
Ernest proposes, your team decides
Sourced
every suggestion, score and verdict

WHAT ERNEST DOES

One AI, four jobs, your team in the loop.

The same engine works in every module, specialized for the decision at hand. It proposes; your analysts accept or reject; the register remembers who decided what, and why.

01

Suggest, with a human in the loop

Likelihoods with weighted factors, attack scenarios, treatment strategies, control mappings, questionnaire answers. Each suggestion carries a confidence score; an analyst accepts or rejects it, and every decision is recorded.

02

Score security posture

Inherent, residual and target risk on the methodology you practice; supplier Trust Grades; maturity by dimension across the group. Every score shows the factors behind it, so a number can be challenged, not just read.

03

Verify every claim

A governance statement is a hypothesis until checked. Ernest verifies it against the evidence on file, the connected signals and the knowledge graph, and returns a verdict with its confidence and its sources. Or says it cannot.

04

Draft from the evidence

Questionnaire responses from a supplier’s own documents, acceptance rationales, control narratives, board-ready wording: drafted from what the platform already holds, sourced line by line, for a person to confirm.

THE VERIFICATION PIPELINE

From declarative claim to trusted, auditable posture.

Verification is the job the other three lean on. Every governance statement follows the same path, whether it comes from a policy, a control owner or a vendor.

INPUT

Declarative claim

“MFA is enforced on all admin accounts.” A claim is a hypothesis: useful, but unproven.

AGENTS

Agentic verification

Specialized agents plan the checks, gather the evidence on file and the connected signals, and cross-reference the knowledge graph.

OUTPUT

Trusted posture

A verdict with confidence level and matched sources, written to the audit trail and re-checked continuously.

ernest - claim verification

claim: "MFA enforced on all admin accounts"

agents: planner → collectors(evidence, connectors) → adjudicator

knowledge graph: 2 policies · 1 exception register consulted

verdict: VERIFIED · confidence: 94% · sources: 4 matched

audit trail: written · next check: continuous

DESIGN PRINCIPLES

No hallucination. No assumption.

Generative AI that invents an answer is worse than no AI at all in cyber governance. Ernest is engineered against it.

01

Deterministic verification

Verdicts come from explicit checks against sources, not from a model’s confidence in its own prose. The same evidence yields the same verdict.

02

Hybrid RAG on a knowledge graph

Ernest reasons over your structured cyber knowledge graph (controls, entities, policies, relationships) combined with retrieval, so context is precise, not approximate.

03

Multi-agent orchestration

Planning, collection, adjudication and writing are separate agents with separate responsibilities: reviewable, testable, and individually constrained.

04

Sources or it didn’t happen

Every output is attached to the evidence that produced it. If sources are insufficient, Ernest says so instead of filling the gap.

TRUST THROUGH TRANSPARENCY

Why teams end up trusting Ernest.

Trust in AI isn’t granted; it’s earned through inspectability. Ernest stands on three commitments.

01

Explainable

Every verdict can be unfolded: which checks ran, which sources matched, where confidence comes from.

02

Auditable

Every action is journaled. Your auditor can replay the reasoning months later, evidence included.

03

Bounded

Ernest acts within explicit mandates. It verifies and proposes; your team decides. Human judgment stays sovereign too.

SOVEREIGN BY ARCHITECTURE

European AI, on European infrastructure.

Ernest runs on open-source LLM foundations operated in the European Union. Your governance data never crosses the Atlantic, never trains anyone’s model, and never depends on a hyperscaler’s API terms.

  • Open-source LLM foundations: no proprietary black box
  • Hosted and inferenced exclusively in the EU
  • Customer data never used for model training
  • Every AI call traced, logged and attributable

Security & trust →

FAQ

Ernest, in practice

Is Ernest a chatbot?

No. Ernest is an embedded engine that powers suggestion, scoring, drafting and verification inside every module. You meet it through suggestions to accept or reject, scores you can unfold and verdicts you can audit, not a chat window bolted onto a GRC tool.

Does Ernest decide for us?

Never. Ernest proposes: a likelihood, a treatment, a questionnaire answer, a mapping, each with a confidence level. A person accepts or rejects it, and the register records who decided what and when. Verification verdicts are the one output it computes on its own, and even those are sourced for a human to challenge.

How does Ernest avoid hallucinations?

Three ways: claims are verified by deterministic checks against live sources rather than generated; retrieval is grounded in a structured knowledge graph; and when evidence is insufficient, Ernest reports “cannot verify” instead of inventing an answer.

Which signals can Ernest verify against?

Identity and access management, cloud configuration, endpoint protection and other operational sources, alongside your documents, certifications and registers. Coverage grows with your integrations.

Does our data train the models?

Never. Models are operated in the EU on open-source foundations; customer data is used to answer your questions, not to train models, and every inference is traced.

Can we audit what Ernest did?

Yes, that’s the point. Each verdict carries its full reasoning trail: checks executed, sources matched, confidence computation and timestamps, exportable for your auditors.

PUT IT TO THE TEST

Bring a claim, a risk or a supplier. Watch Ernest work.

The best way to evaluate an AI is to challenge it on your own posture: a claim to verify, a risk to score, a questionnaire to draft.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.