⚠ PREVIEW · pre-deploy build · 2026-07-28 · 13:16 GMT · on main, not yet the live site
Early access · Supplier evaluation

Verify your suppliers on evidence, not questionnaires.

Serious supplier due diligence has always meant an enterprise platform and an enterprise budget — so most UK SMEs went without. Hume closes that gap. Enter a supplier name and what you're buying, and a timestamped evidence pack comes back the same day, with recommended actions you can route straight to the risk owner. No lengthy commitment, no subscriptions, and none of your confidential information processed. Early access is open now, before public launch.

OSINTOpen-source intelligence — public sources, not self-attestation
UK registersCompanies House, ICO & more
No AIDeterministic code, not models
Audit-readyTimestamped, source-linked evidence
What Hume doesn't do · 01
No AI.
No AI collects the evidence, processes it, or decides the outcome — every step is deterministic code. That's what makes a finding repeatable, and defensible in an audit.
What Hume doesn't do · 02
No data
processed.
An evaluation takes a supplier name and the product or service — that's all. Nothing confidential of yours ever leaves your hands, and there's nothing new for you to risk-assess.
What Hume doesn't do · 03
No sign-up.
No account, no portal to log into. Order on the form, pay by card, and the evidence pack arrives by email.
What Hume doesn't do · 04
No
questionnaires.
Hume verifies public UK sources for you. Your suppliers — even the hyperscalers who never reply — get nothing to fill in and nothing to ignore.
The bottleneck

Compliance shouldn't be the reason procurement stalls.

One stretched information-security lead. Operations pushing to onboard a new supplier. A surveillance audit on the calendar and a supplier register that's still a spreadsheet. Sound familiar?

01

Too busy to check

A single Compliance or InfoSec Manager can't realistically vet every supplier by hand — so checks slip, or don't happen at all.

02

Seen as a blocker

Operations wants to move fast; compliance gets pulled in last-minute and ends up cast as the obstacle to getting the deal done.

03

Audit looming

An ISO 27001 external or surveillance audit is coming, and the supplier evidence register is thin or empty.

04

Platforms cost too much

Enterprise vendor-risk tools run into five figures a year — and you don't want a whole ISMS platform to answer one question.

A cleaner division of labour

Compliance authorises Hume. Operations procure the report.

Supplier review stops being the compliance team's queue. The standard gets set once, by the people who own risk — then the people onboarding suppliers pull the evidence themselves, and the audit trail files straight back to compliance.

Compliance

Authorise the standard

Approve Hume as the supplier-evidence standard once. No vetting every supplier by hand — set the bar, and the evidence arrives filed and audit-ready.

Operations

Procure the report

Onboarding a supplier? Order the evaluation and get the evidence pack back the same day — no waiting on a portal, a questionnaire or a compliance queue.

How it works

From supplier name to filed evidence in three steps.

No portal for your suppliers to ignore. No forms to chase. Hume does the verifying.

STEP 01

Name who and what

Name the supplier you want checked and what you're buying. No account, and no confidential data of yours needed.

STEP 02

Hume verifies the evidence

Rules-based automation gathers facts from public UK registers and open sources — Companies House, ICO, sanctions, security disclosures, public legal documents and more. Hyperscalers needn't reply to anything.

STEP 03

You get a report you can file

A timestamped evidence pack with uniquely referenced findings and exportable recommended actions. Hand risks to the risk owner to treat or accept, and proceed.

Who it's for

Built for the moment compliance gets the call.

Three situations where an SME needs supplier evidence fast — without buying a platform.

Trigger 01

New supplier sign-off

Operations wants to onboard now. Get timestamped public-register evidence so compliance clears the supplier instead of blocking the deal.

Trigger 02

ISO 27001 audit prep

Your supplier evidence register is thin and the surveillance audit is booked. Screen the whole estate and walk in with referenced, dated evidence.

Trigger 03

Legal & regulatory exposure

ICO enforcement, UK GDPR Art. 28, NIS2 / DORA, cyber-insurance demands. Get public evidence on the suppliers that process your data or hold system access — where your real exposure sits.

The report · a quick tour

From evidence, to action, to the right desk.

Hume states the evidence and leaves the risk call to you. Here's how a report turns into a decision someone can actually own.

  • STEP 01

    Read the findings

    Every check is a uniquely referenced finding with an explicit evidence state — verified, finding, partial, not found, unknown. No severity grade, no traffic light.

  • STEP 02

    Capture recommended actions

    Each finding carries a plain-English recommended action, linked by reference. Tick what's relevant and export the action list on its own.

  • STEP 03

    Route to the risk owner

    Send the action list to the procuring manager or risk owner. They make the informed call — treat or accept — and procurement moves.

Supplier evaluation report
Acme Payroll Ltd
HUM-2026-302087 · OSINT · no AI in findings
22 Jun 2026
F-014VERIFIEDICO registration active & current
F-007FINDINGNo DPA located for PII processor
F-021PARTIALSecurity page present, no certification
F-033NOT FOUNDNo public modern-slavery statement
F-040UNKNOWNSub-processor list not disclosed
Recommended actions · exportable
RE: F-007 Obtain a signed Art. 28 DPA before processing personal data.
RE: F-021 Request current ISO 27001 / SOC 2 certificate or scope statement.
RE: F-033 Ask supplier to publish a Modern Slavery Act statement.
RE: F-040 Request the current sub-processor list and transfer basis.
Export actions (PDF / CSV)
Route for an informed decision
H
Hume report + action list
Evidence stated — risk not classified
PM
Procuring manager · risk owner
Reviews actions against the deal
Informed decision: treat or accept
Logged for the audit trail · procurement proceeds
Tiers & pricing

Every check, and where each tier picks it up.

Each supplier sits on a risk tier from its own profile. Packs are cumulative — every tier runs its own checks plus every tier below it — so coverage fills in as you move up. Prices shown ex-VAT.

Check StandardRT1£1959 checks CommercialRT2a£49526 checks PIIRT2b£89531 checks CriticalRT3£1,49546 checks
Entity legitimacy & solvency
Companies House status
Charges register
People with significant control
Accounts filing currency
Sanctions screen (OFSI + OFAC)
ICO / regulatory enforcement
Government debarment list
Director disqualification
Gazette insolvency notices
Data protection & governance
5.20 legal-document review (routing)runs
Privacy policy / sub-processor disclosure (routing)runs
ISO 27001 certificate (UKAS)
ISAE 3402 Type II
Contractual scope vs operational
Exit planning & data return
Document control
Security posture
SSL/TLS configuration grade
Email authentication (DMARC/SPF/DKIM)
HTTP security headers
Incident & breach history
Corporate-email breach exposure
Portal authentication (MFA/SSO)
File-transfer security
Portal technology disclosure
Reputation & integrity
Review / reputation intelligence
Adverse-media sweep (5-year)
PEP screening
Client reputability
Personal-data (PII) assurance
Shadow-IT detection
International transfer / IDTA
PII classification
Cookie consent (PECR / ICO)
PII gate (UK GDPR Art. 7(4))
Critical-ICT depth
Cyber Essentials / CE Plus
CVE / NVD matching
Status-page / resilience
Vulnerability disclosure policy
Shodan — attack surface
SBOM / open-source
Dark-web breach data
Sub-processor discovery
Cyber-insurer SOA mapping
Pen-test evidence
HMRC deliberate tax defaulters
Certification marks / logos
Technology-partner status
Verified accreditations
Award credibility / ASA
Live today Designed · rolling out “runs” = routing input; run on every supplier, findings publish from Commercial up

Hume Watch

RT4 overlay · £95 + VAT / mo

Re-runs the applicable tier's checks on a risk-based cadence and sends a diff digest — Standard annual, Commercial quarterly, PII monthly, Critical weekly. Sits on top of whichever tier applies.

Bespoke

RT5 overlay · price on application

Up to six mandate checks, fired only when an insurer, regulator or named client framework requires them:

  • CCJ register
  • Credit-risk rating
  • UKVI sponsor licence
  • Modern Slavery statement
  • Anti-bribery policy
  • Whistleblowing channel

Buying always starts with the Standard entry screen — it confirms from evidence which tier a supplier actually needs, so you never over- or under-buy. The upgrade tiers are recommended, and sold, from your own report as their checks come online; you pay only the difference to move up. Standard is open now via early access.

Why "Hume"
"A wise man proportions his belief to the evidence."
David Hume · the principle behind every assessment
Who's behind Hume

About Cahoot Consulting

Hume is a service of Cahoot Consulting Limited — a one-person consultancy, not a platform team. It's the work of Cath Furlong, who spent twelve years as an independent information security and data-privacy consultant, ten of them as a Certified Lead ISO 27001 Assessor for UKAS-accredited certification bodies. That's a decade spent assessing the same controls Hume now verifies from the public record. (CISSP and CIPP/E certifications were held previously; both lapsed in 2018.)

That background sets what Hume is — and what it deliberately isn't. Every finding is determined by deterministic, coded rules run against public evidence: no questionnaire engine, and no AI collecting the evidence, processing it or deciding the outcome. Hume states what the public record shows — referenced and timestamped — and leaves the risk decision with you.

Cahoot Consulting Limited · Companies House 08976555 · cath@cahootconsulting.com

Get privileged early access to supplier evidence.

Order your evaluation on the form. No platform to buy, no questionnaires to chase.

Claim early access