It's in the data you shared, the network paths you opened, the assets you entrusted, the people you let inside. Only your side of the relationship knows — so that's where Polestead begins.
Data. Network. Facilities. Blueprints. People. Supply. Your exposure across these six decides how hard we look at each vendor — full-depth scrutiny for the few who could hurt you, a signed attestation for the print shop.
Depth follows exposure. Not vendor count.
Traditional per-vendor licensing prices each assessment like a luxury — so teams ration coverage to the vendors they already suspect, and hope they guessed right. But exposure — what a vendor holds, reaches, or walks through — doesn't follow anyone's picklist. Polestead's license is built so classifying the entire register is simply what the platform does, so a misclassified vendor can't quietly become next quarter's incident.
Risk review should be a culture — not a procurement decision.
Priced so full coverage is the default — never a line item to defend.
DORA wants first word in ~4 hours. NIS2 gives you 24. GDPR, 72. CIIC already knows which regulators bind you — and on incident it hands you the plan, the clock schedule, and every regulator-ready report at once. Before you've finished the first call.
Your trust center is built to be found. Your risk data is built to stay yours. Two different jobs — deployed two different ways.
Your security story, reachable by every prospect, customer, and auditor — NDA gates, subprocessor lists, your own domain. Nothing held back for a paid tier. Answer once — and the library is yours to keep.
Your register, your assessments, your incidents — on-premises, air-gapped, or single-tenant EU cloud. The US CLOUD Act reaches US platforms wherever the server sits. Self-hosted Polestead ends that question — deployed by your team, on your ground, inspectable by your auditors.
Single-tenant, EU-resident, transparent about its operating entity. And when you're ready to bring it inside your walls, the deployment moves with you — nothing to re-buy, nothing to migrate away from.
Every other platform runs your vendor intelligence through their models, on their infrastructure, under their terms. Polestead inverts it: the AI works for you because it literally runs as you.
Any provider. Any model. Your spend caps, your billing relationship, your audit trail. Switch models the day a better one ships — no waiting on our roadmap.
Your data never trains our models — not as a policy promise, but structurally. Inference never touches our infrastructure, so there is nothing to opt out of.
For estates where no external inference is acceptable, the platform runs without AI entirely — a supported configuration, not a degraded one.
*In zero-AI mode, vendor-name resolution falls back to deterministic matching, with lower match accuracy than AI-assisted resolution.
Ratings platforms score vendors from external scans; context adjusts the score. In Polestead, your classification is the architecture: vendors are tiered by your exposure, and the tier decides how deep the assessment goes. External signals are optional evidence — never the verdict.
Traditional per-vendor licensing prices each assessment slot so high that teams ration coverage to a shortlist. Polestead's license is built the other way: classifying your entire register is the default behavior of the platform, at a per-vendor economics that makes rationing pointless. You never have to justify covering a vendor.
Yes. The register, assessments, incidents, and the platform itself deploy on-premises, air-gapped, or in single-tenant EU cloud. For teams that can't host, a managed single-tenant SaaS runs the same platform. The trust center is always SaaS, by design: it exists to be reachable.
Publishing is — NDA-gated documents, subprocessor lists, a reusable answer library, custom domain, access controls with a visitor log, unlimited imports, all free with no caps or expiry. Paid capabilities start where the trust center starts working for you: answering inbound questionnaires with human-in-the-loop workflows and pushing regulatory data.
No — structurally. Inference runs on your own keys, with your spend caps and whatever model you choose. There is nothing for us to train on. A zero-AI configuration is supported too — vendor-name resolution then falls back to deterministic matching, at lower accuracy.
No. CIIC — the Critical Incident Intelligence Center — is an operational control plane. Its regulatory dataset is verified against primary statutory sources and carries last-verified dates — and national transposition should always be verified with counsel.
Bring a vendor-master export. Leave with your exposure mapped.
Polestead is a third-party risk management platform for regulated enterprises worldwide. It ingests the entire ERP vendor master, classifies every vendor by the buyer's own exposure across six access vectors (Internal Risk Classification), and scopes assessment depth by tier. CIIC (Critical Incident Intelligence Center), its regulatory incident-response control plane, maps sectors and jurisdictions to binding frameworks such as DORA, NIS2, and GDPR, and produces regulator-ready reports against statutory clocks. The platform deploys on-premises, air-gapped, in single-tenant EU cloud, or as managed single-tenant SaaS for teams that cannot self-host; the trust center is free at full depth and SaaS by design. AI runs on customer-supplied keys — any provider, any model; a zero-AI configuration is supported with deterministic name-matching at lower accuracy. Licensing is built so classifying the entire register is the default, rather than rationing coverage to a per-vendor shortlist.