01
Generic questionnaires, by Excel
Three hundred questions, identical for the caterer and the cloud provider. Both sides spend weeks proving things that do not matter for the service actually delivered.
Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm. Grimaldi Forum, a ten-minute pitch.
Book the workshopOur Assises workshopMODULE · THIRD-PARTY RISK
The Supplier Hub runs third-party risk as a relationship, not a mailbox: partners enroll on a portal, questions fit the service they actually deliver, AI helps both sides, every answer is checked against the evidence behind it, and remediation becomes a joint commitment measured by one grade.
Portal enrollment · Contextual assessment · Joint action plan · One Trust Grade
SecurityScorecard · Bitsight · Scovery · more to come
Each signal is renormalised over those present; stale signals count for less, and too little signal shows Not rated, never a misleading grade.
THE SITUATION
01
Three hundred questions, identical for the caterer and the cloud provider. Both sides spend weeks proving things that do not matter for the service actually delivered.
02
Suppliers answer the same forms for every client and hear nothing back. Effort without feedback becomes copy-paste, and copy-paste becomes risk.
03
A grade lands and nothing changes: no shared plan, no follow-through, and next year the same findings come back.
04
External ratings see the outside; questionnaires see the declared. Neither alone says whether this service, for your usage, is safe.
CAPABILITIES
Suppliers inventoried with tags, entities and statuses, mapped as a dependency graph: third-party risk piloted at scale, not per spreadsheet.
The assessment starts from the execution context: what the partner runs, accesses and hosts. AI suggests the relevant frameworks, and every question addresses the security stakes that context actually raises, instead of one generic set sent to everyone.
Partners join through a portal invitation, see what is asked and why, and work in a real workspace with state and deadlines: an experience, not an Excel to return.
On your side, Ernest drafts, scores and cross-checks, flagging contradictions with the evidence behind them. On the supplier’s side, AI pre-fills the answers from their own documents. Both sides move faster, and neither has to invent anything.
Ernest reads what sits behind an answer, certificates, audit reports, policies, and holds the claim against what the document actually says: validity dates, the scope it really covers, and the answers it contradicts elsewhere in the questionnaire.
Action plans are proposed, negotiated and accepted by both sides, then tracked as synced tickets in each organization: maturity grows together, and effort finally gets an echo.
One aggregated grade per supplier, blending your assessments, the business impact of the service and external ratings (SecurityScorecard, Bitsight, Scovery), with the computation in the open.
ONE GRADE, HONEST
The Mindlapse Trust Grade blends your assessments, the business impact of the service and external ratings into one letter, with the computation in the open: weights, freshness, coverage. Stale signals count for less, and too little signal means Not rated, never a misleading grade.
Invite the partner to the portal: they see the scope, the deadlines, and why each question is being asked.
A contextual questionnaire, AI-drafted answers on their side, automated scoring and contradiction checks on yours.
A joint action plan accepted by both sides and tracked to done; re-assessment triggers on events, and the grade follows reality.
FROM THE MARKETPLACE
These connectors feed the EASM signal of the Trust Grade, supplier by supplier, next to your own assessments and the business impact of the service.
FAQ
An aggregated grade per supplier: assessment scoring, the business impact of the service, and external attack-surface ratings, each weighted and renormalised over the signals actually present. Stale signals are flagged and count for less; too little signal shows Not rated instead of a misleading letter.
SecurityScorecard, Bitsight and Scovery today, with more to come. They cover the outside view; your assessments and the service context cover what ratings cannot see.
A portal enrollment, questions that fit the service they deliver, Ernest drafting answers from their own documents, and a joint action plan instead of silence after they hit send.
Findings become a joint action plan, negotiated and accepted by both sides, tracked as synced tickets in each organization. Re-assessments fire on events (new findings, expiring attestations, scope changes), and the grade updates as reality changes.
ECOSYSTEM, VERIFIED
A live walkthrough: enrollment, contextual assessment, joint action plan and the Trust Grade.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy