Serious supplier due diligence has always meant an enterprise platform and an enterprise budget — so most UK SMEs went without. Hume closes that gap. Enter a supplier name and what you're buying, and a timestamped evidence pack comes back the same day, with recommended actions you can route straight to the risk owner. No lengthy commitment, no subscriptions, and none of your confidential information processed. Early access is open now, before public launch.
One stretched information-security lead. Operations pushing to onboard a new supplier. A surveillance audit on the calendar and a supplier register that's still a spreadsheet. Sound familiar?
A single Compliance or InfoSec Manager can't realistically vet every supplier by hand — so checks slip, or don't happen at all.
Operations wants to move fast; compliance gets pulled in last-minute and ends up cast as the obstacle to getting the deal done.
An ISO 27001 external or surveillance audit is coming, and the supplier evidence register is thin or empty.
Enterprise vendor-risk tools run into five figures a year — and you don't want a whole ISMS platform to answer one question.
Supplier review stops being the compliance team's queue. The standard gets set once, by the people who own risk — then the people onboarding suppliers pull the evidence themselves, and the audit trail files straight back to compliance.
Approve Hume as the supplier-evidence standard once. No vetting every supplier by hand — set the bar, and the evidence arrives filed and audit-ready.
Onboarding a supplier? Order the evaluation and get the evidence pack back the same day — no waiting on a portal, a questionnaire or a compliance queue.
No portal for your suppliers to ignore. No forms to chase. Hume does the verifying.
Name the supplier you want checked and what you're buying. No account, and no confidential data of yours needed.
Rules-based automation gathers facts from public UK registers and open sources — Companies House, ICO, sanctions, security disclosures, public legal documents and more. Hyperscalers needn't reply to anything.
A timestamped evidence pack with uniquely referenced findings and exportable recommended actions. Hand risks to the risk owner to treat or accept, and proceed.
Three situations where an SME needs supplier evidence fast — without buying a platform.
Operations wants to onboard now. Get timestamped public-register evidence so compliance clears the supplier instead of blocking the deal.
Your supplier evidence register is thin and the surveillance audit is booked. Screen the whole estate and walk in with referenced, dated evidence.
ICO enforcement, UK GDPR Art. 28, NIS2 / DORA, cyber-insurance demands. Get public evidence on the suppliers that process your data or hold system access — where your real exposure sits.
Hume states the evidence and leaves the risk call to you. Here's how a report turns into a decision someone can actually own.
Every check is a uniquely referenced finding with an explicit evidence state — verified, finding, partial, not found, unknown. No severity grade, no traffic light.
Each finding carries a plain-English recommended action, linked by reference. Tick what's relevant and export the action list on its own.
Send the action list to the procuring manager or risk owner. They make the informed call — treat or accept — and procurement moves.
Each supplier sits on a risk tier from its own profile. Packs are cumulative — every tier runs its own checks plus every tier below it — so coverage fills in as you move up. Prices shown ex-VAT.
| Check | StandardRT1£1959 checks | CommercialRT2a£49526 checks | PIIRT2b£89531 checks | CriticalRT3£1,49546 checks |
|---|---|---|---|---|
| Entity legitimacy & solvency | ||||
| Companies House status | ||||
| Charges register | ||||
| People with significant control | ||||
| Accounts filing currency | ||||
| Sanctions screen (OFSI + OFAC) | ||||
| ICO / regulatory enforcement | ||||
| Government debarment list | ||||
| Director disqualification | ||||
| Gazette insolvency notices | ||||
| Data protection & governance | ||||
| 5.20 legal-document review (routing) | runs | |||
| Privacy policy / sub-processor disclosure (routing) | runs | |||
| ISO 27001 certificate (UKAS) | ||||
| ISAE 3402 Type II | ||||
| Contractual scope vs operational | ||||
| Exit planning & data return | ||||
| Document control | ||||
| Security posture | ||||
| SSL/TLS configuration grade | ||||
| Email authentication (DMARC/SPF/DKIM) | ||||
| HTTP security headers | ||||
| Incident & breach history | ||||
| Corporate-email breach exposure | ||||
| Portal authentication (MFA/SSO) | ||||
| File-transfer security | ||||
| Portal technology disclosure | ||||
| Reputation & integrity | ||||
| Review / reputation intelligence | ||||
| Adverse-media sweep (5-year) | ||||
| PEP screening | ||||
| Client reputability | ||||
| Personal-data (PII) assurance | ||||
| Shadow-IT detection | ||||
| International transfer / IDTA | ||||
| PII classification | ||||
| Cookie consent (PECR / ICO) | ||||
| PII gate (UK GDPR Art. 7(4)) | ||||
| Critical-ICT depth | ||||
| Cyber Essentials / CE Plus | ||||
| CVE / NVD matching | ||||
| Status-page / resilience | ||||
| Vulnerability disclosure policy | ||||
| Shodan — attack surface | ||||
| SBOM / open-source | ||||
| Dark-web breach data | ||||
| Sub-processor discovery | ||||
| Cyber-insurer SOA mapping | ||||
| Pen-test evidence | ||||
| HMRC deliberate tax defaulters | ||||
| Certification marks / logos | ||||
| Technology-partner status | ||||
| Verified accreditations | ||||
| Award credibility / ASA | ||||
Re-runs the applicable tier's checks on a risk-based cadence and sends a diff digest — Standard annual, Commercial quarterly, PII monthly, Critical weekly. Sits on top of whichever tier applies.
Up to six mandate checks, fired only when an insurer, regulator or named client framework requires them:
Buying always starts with the Standard entry screen — it confirms from evidence which tier a supplier actually needs, so you never over- or under-buy. The upgrade tiers are recommended, and sold, from your own report as their checks come online; you pay only the difference to move up. Standard is open now via early access.
"A wise man proportions his belief to the evidence."David Hume · the principle behind every assessment
Hume is a service of Cahoot Consulting Limited — a one-person consultancy, not a platform team. It's the work of Cath Furlong, who spent twelve years as an independent information security and data-privacy consultant, ten of them as a Certified Lead ISO 27001 Assessor for UKAS-accredited certification bodies. That's a decade spent assessing the same controls Hume now verifies from the public record. (CISSP and CIPP/E certifications were held previously; both lapsed in 2018.)
That background sets what Hume is — and what it deliberately isn't. Every finding is determined by deterministic, coded rules run against public evidence: no questionnaire engine, and no AI collecting the evidence, processing it or deciding the outcome. Hume states what the public record shows — referenced and timestamped — and leaves the risk decision with you.
Cahoot Consulting Limited · Companies House 08976555 · cath@cahootconsulting.com
Order your evaluation on the form. No platform to buy, no questionnaires to chase.
Claim early access