The wrong company.
The assessment is attached to a brand. The contract is with a legal entity. They are not the same.

A vendor approval passes through many hands: the analyst, the approver, the auditor, the regulator. Each one is asked to trust the one before. KnightGrid exists so that none of them has to take it on faith.
Change a single character. The seal will not match.
A vendor has an incident. The regulator's first question is simple: show us the basis on which you approved them. You open the system and find what most firms find: a completed questionnaire, a score of 74, an email that says “looks fine to me”, and a folder of documents.
| What you'll find | What you'll be asked |
|---|---|
| A questionnaire, 83 answers | Which controls were evaluated, and on what evidence? |
| A score: 74, green | How was that score derived? |
| An email: “agreed, proceed” | Which legal entity was assessed? |
| A folder of documents | Who was accountable, under what authority? |
The work was done. The decision was never recorded.
Most vendor risk tools were built to collect answers. They record what a vendor claims. They cannot tell a claim from a proof, a brand from a legal entity, or last year's evidence from today's. So programmes fill up with activity, and at the moment of scrutiny, there is nothing to show but the activity.
Response completeness is not evidence sufficiency.
The assessment is attached to a brand. The contract is with a legal entity. They are not the same.
A certificate is on file, but it does not cover the service you bought.
The approval was right when it was made. Nobody can now show what was known at the time.
A decision belongs to a registered legal entity, never a trading name.
We resolve the entity before any risk work begins.
A claim is not evidence, and evidence is not coverage.
We test each document against the controls it is meant to support.
What was known at the time of signing must survive everything that happens after.
We seal the record at signature and never overwrite it.
Given the same evidence, the same method must reach the same signal.
We version every rule and bind it to every decision.
Every decision leaves as a Decision Report: the entity, the evidence, the rules in force, the conditions, the person who signed and the moment they signed, with a fingerprint of the sealed record printed on it. Auditors open it in their own read-only view. If a single fact changes, the fingerprint no longer matches.
And be able to show it, to anyone, whenever they ask.
Request early access