Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

MODULE · THIRD-PARTY RISK

Your perimeter is everyone you depend on.

The Supplier Hub runs third-party risk as a relationship, not a mailbox: partners enroll on a portal, questions fit the service they actually deliver, AI helps both sides, every answer is checked against the evidence behind it, and remediation becomes a joint commitment measured by one grade.

Portal enrollment · Contextual assessment · Joint action plan · One Trust Grade

Mindlapse Trust Grade · how it is computed Illustrative data
D Poor -10.5 declining ↘ Aethon Cloud Services · cloud · IT access
Risk scoring (NIST CSF) Stale 76 × 33% +25.33 pts
Business impact 20 × 40% +8 pts
EASM · external ratings 83 × 27% +22.13 pts

SecurityScorecard · Bitsight · Scovery · more to come

Coverage: 3/3 signals Last computed: Aug 7, 2026

Each signal is renormalised over those present; stale signals count for less, and too little signal shows Not rated, never a misleading grade.

THE SITUATION

The spreadsheet era of vendor risk has to end.

01

Generic questionnaires, by Excel

Three hundred questions, identical for the caterer and the cloud provider. Both sides spend weeks proving things that do not matter for the service actually delivered.

02

Fatigue without feedback

Suppliers answer the same forms for every client and hear nothing back. Effort without feedback becomes copy-paste, and copy-paste becomes risk.

03

Assessment ends at the scorecard

A grade lands and nothing changes: no shared plan, no follow-through, and next year the same findings come back.

04

Ratings without context

External ratings see the outside; questionnaires see the declared. Neither alone says whether this service, for your usage, is safe.

CAPABILITIES

From vendor list to living partnership.

  1. One hub for the whole ecosystem

    Suppliers inventoried with tags, entities and statuses, mapped as a dependency graph: third-party risk piloted at scale, not per spreadsheet.

  2. Questions that fit the service

    The assessment starts from the execution context: what the partner runs, accesses and hosts. AI suggests the relevant frameworks, and every question addresses the security stakes that context actually raises, instead of one generic set sent to everyone.

  3. Enrollment, not an attachment

    Partners join through a portal invitation, see what is asked and why, and work in a real workspace with state and deadlines: an experience, not an Excel to return.

  4. AI on both sides of the table

    On your side, Ernest drafts, scores and cross-checks, flagging contradictions with the evidence behind them. On the supplier’s side, AI pre-fills the answers from their own documents. Both sides move faster, and neither has to invent anything.

  5. Answers fact-checked against the evidence

    Ernest reads what sits behind an answer, certificates, audit reports, policies, and holds the claim against what the document actually says: validity dates, the scope it really covers, and the answers it contradicts elsewhere in the questionnaire.

  6. Remediation as a joint commitment

    Action plans are proposed, negotiated and accepted by both sides, then tracked as synced tickets in each organization: maturity grows together, and effort finally gets an echo.

  7. The Mindlapse Trust Grade

    One aggregated grade per supplier, blending your assessments, the business impact of the service and external ratings (SecurityScorecard, Bitsight, Scovery), with the computation in the open.

ONE GRADE, HONEST

A grade you can explain is a grade you can defend.

The Mindlapse Trust Grade blends your assessments, the business impact of the service and external ratings into one letter, with the computation in the open: weights, freshness, coverage. Stale signals count for less, and too little signal means Not rated, never a misleading grade.

  1. 01

    Enroll

    Invite the partner to the portal: they see the scope, the deadlines, and why each question is being asked.

  2. 02

    Assess in context

    A contextual questionnaire, AI-drafted answers on their side, automated scoring and contradiction checks on yours.

  3. 03

    Commit, together

    A joint action plan accepted by both sides and tracked to done; re-assessment triggers on events, and the grade follows reality.

FAQ

The Supplier Hub, in practice

What is the Mindlapse Trust Grade?

An aggregated grade per supplier: assessment scoring, the business impact of the service, and external attack-surface ratings, each weighted and renormalised over the signals actually present. Stale signals are flagged and count for less; too little signal shows Not rated instead of a misleading letter.

Which external ratings feed it?

SecurityScorecard, Bitsight and Scovery today, with more to come. They cover the outside view; your assessments and the service context cover what ratings cannot see.

What do suppliers actually experience?

A portal enrollment, questions that fit the service they deliver, Ernest drafting answers from their own documents, and a joint action plan instead of silence after they hit send.

What happens after the assessment?

Findings become a joint action plan, negotiated and accepted by both sides, tracked as synced tickets in each organization. Re-assessments fire on events (new findings, expiring attestations, scope changes), and the grade updates as reality changes.

ECOSYSTEM, VERIFIED

Pick your riskiest vendor. We’ll assess it together.

A live walkthrough: enrollment, contextual assessment, joint action plan and the Trust Grade.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.