⚠ PREVIEW BUILD 4 · on main, not yet the live site
For Compliance

Set the standard, and stand back.

Operations wants to buy a new shiny SaaS solution. They go ahead and order the discovery pack, route the report and its findings and recommendations to the decision maker the same day, and file the evidence — not your supplier, not your risk to accept, but always on hand should an auditor ask.

Set onceApprove the standard, not each individual supplier
Audit-readyTimestamped, source-linked, referenced findings
No AIDeterministic code decides nothing — you do
Not your riskNot your supplier, not your risk to accept — that's the risk owner's call
Where this fits

Hume states the evidence. It doesn't clear the supplier.

The report format is built to leave the risk decision with a named owner — never with Hume, and not silently defaulted to whoever ordered it.

What you approve

The standard, not the queue

Approve Hume as the supplier-evidence standard once — set the bar, and what comes back is filed and audit-ready without you reviewing every supplier by hand.

Where it ends up

Filed for the auditor, not just for you

Every report carries uniquely referenced findings and recommended actions, but no severity grade and no affirmative "this is fine" verdict. Operations routes the decision to the risk owner and files the evidence — on hand to present to an auditor, or forwarded to you, under your own organisation's policy.

What you catch

Classification isn't Operations' call

Mis-classifying a supplier as low-risk is one of the most common mistakes in supplier evaluation. Hume determines the recommended tier from evidence, not simply from what Operations assumes going in — it surfaces the actual signals so you make the classification call, not whoever just wanted the deal to move.

What's inside

More than a pass or fail

Supplier-agreement checks reference ISO 27001 Annex A 5.20, and Hume Watch's re-run cadence covers Annex A 5.22. Where the evidence warrants it, recommendations point to a deeper tier — and every finding exports to PDF or CSV, straight into whatever risk register or actions tracker you already use.

Approve the standard.

Same form either way — this just skips straight to what Compliance needs.

Claim early access See the full site — tiers, the report tour, FAQ