KnightGrid
Why we exist

Trust should be checkable.

A vendor approval passes through many hands: the analyst, the approver, the auditor, the regulator. Each one is asked to trust the one before. KnightGrid exists so that none of them has to take it on faith.

Sealed Matches the sealed record.

Change a single character. The seal will not match.

01 · The call

Eighteen months later, someone asks.

A vendor has an incident. The regulator's first question is simple: show us the basis on which you approved them. You open the system and find what most firms find: a completed questionnaire, a score of 74, an email that says “looks fine to me”, and a folder of documents.

What you'll findWhat you'll be asked
A questionnaire, 83 answersWhich controls were evaluated, and on what evidence?
A score: 74, greenHow was that score derived?
An email: “agreed, proceed”Which legal entity was assessed?
A folder of documentsWho was accountable, under what authority?

The work was done. The decision was never recorded.

02 · The gap

Activity is not a decision.

Most vendor risk tools were built to collect answers. They record what a vendor claims. They cannot tell a claim from a proof, a brand from a legal entity, or last year's evidence from today's. So programmes fill up with activity, and at the moment of scrutiny, there is nothing to show but the activity.

Response completeness is not evidence sufficiency.
03 · Where trust breaks

Trust fails in three predictable places.

The wrong company.

The assessment is attached to a brand. The contract is with a legal entity. They are not the same.

The borrowed confidence.

A certificate is on file, but it does not cover the service you bought.

The vanished moment.

The approval was right when it was made. Nobody can now show what was known at the time.

04 · What we believe

Four things every decision owes the people who rely on it.

  1. 1

    Know who.

    A decision belongs to a registered legal entity, never a trading name.

    We resolve the entity before any risk work begins.

  2. 2

    Weigh the proof.

    A claim is not evidence, and evidence is not coverage.

    We test each document against the controls it is meant to support.

  3. 3

    Freeze the moment.

    What was known at the time of signing must survive everything that happens after.

    We seal the record at signature and never overwrite it.

  4. 4

    Show the working.

    Given the same evidence, the same method must reach the same signal.

    We version every rule and bind it to every decision.

06 · Don't take our word for it

The record answers for itself.

Every decision leaves as a Decision Report: the entity, the evidence, the rules in force, the conditions, the person who signed and the moment they signed, with a fingerprint of the sealed record printed on it. Auditors open it in their own read-only view. If a single fact changes, the fingerprint no longer matches.

Know what you've approved.

And be able to show it, to anyone, whenever they ask.

Request early access