Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Supplier assurance for the regulated mid-market

Most NIS2 obligations have a playbook. Supply chain security doesn't.

Vittnor — Supply Chain Assurance for the mid-market. It turns supplier proof into structured, audit-ready records — without the spreadsheet sprawl. Built for the buyers that bigger players ignored, in central Europe by a cybersecurity practitioner who's been in your shoes.

  • Pilot free for the first cohort
  • EU-built, EU-hosted
  • Audit-ready evidence records
  • No tracking cookies
PreviewVittnor dashboard — supplier posture overviewEnlarge
0.1 / Why this exists

Walk through the NIS2 obligations as a CISO or Head of IT. Awareness training has a playbook. Incident response has a runbook. Patch management is procedural. Supply chain security isn't. The evidence sits with external parties. It arrives in a dozen formats. It expires unevenly. And someone has to defend the decisions later. That's why Vittnor is its own product — because the obligation deserves its own tool.

1.0 / Platform

Structured supplier evidence — without the spreadsheet sprawl.

Vittnor turns supplier proof — certificates, audit reports, contract clauses, policy documents — into Evidence records with expiry context and a full decision trace. When a supplier has an incident, an auditor asks a hard question, or a regulator sends an inquiry, you have the answer in minutes, not hours.

  • Process-driven supplier scoping
  • Structured assessment with AI-assisted answer extraction — every suggestion cited
  • Evidence records with review history
  • NIS2-shaped audit exports — structured, hash-anchored, defensible
A supplier evidence record in VittnorOne supplier record — Vltavia Energy — with risk tier and four dated evidence artefacts on the left, and its decision trace on the right: questionnaire returned, evidence reviewed, approval with recorded rationale, ending in a hash-anchored export.Vltavia Energy a.s.2 services in scope · Next review · Jan 2027Tier 2 · ReviewedCURRENT EVIDENCEISO 27001 certificateValid · 2025–2028SOC 2 Type II reportAudit · Mar 2026Sub-processor listv2 · Apr 2026 · 7 disclosedDPASigned · Jan 2026Linked · dated · reviewer-attributedDECISION TRACEQuestionnaire returned12 Jun 2026Evidence reviewed08 Jul 2026Approved — rationale recordedReviewer-attributed · 14 Jul 2026 · 09:41Hash-anchored · RFC 3161 timestampedExport · JSON / PDF
One record per supplier — evidence, decision, export
2.0 / The same job, two workflows

When a supplier discloses an incident.

One scenario. Two ways it goes. The difference is what you signed up for the day before it happened.

01 / ThenThe familiar workflow

Open the supplier register spreadsheet. Search SharePoint for their last assessment, your inbox for the contract clauses, a different folder for the evidence files, your calendar for the last review date. Half a day per supplier. Longer if the original reviewer has left. By the time you've reconstructed who reviewed what and when, you're not sure you have the latest version of anything.

4–6 hrs / supplier5 systemsReviewer dependent
02 / NowThe Vittnor workflow

One record per supplier. Current evidence, review history, contract clauses, in-scope services — linked, dated, exportable. The CEO gets the answer the same morning. The auditor gets the same answer six months later, unchanged.

Minutes / supplierOne recordReviewer-attributed
↳ The working recordWhat builds up as you go
Supplier evidence becomes questionnaire answersFour supplier-provided evidence artefacts on the left — ISO 27001 certificate, SOC 2 Type II report, sub-processor list, DPA — each mapped to specific items in the buyer's supplier questionnaire on the right, with one item marked manual to show that AI never closes the loop.Supplier evidenceYour supplier questionnaireISO 27001 certificateValid · 2025–2028SOC 2 Type II reportAudit · Mar 2026Sub-processor listv2 · Apr 2026DPASigned · Jan 2026Are sub-processors disclosed?ISO 27001 certified — current?SOC 2 Type II in date?DPA in place with you?Incident notification SLA?BC/DR tests · last 12 mo?MANUALTheir certs.Your answers — with citations and a reviewer sign-off.
3.0 / What you get

What you actually get.

Evidence, decisions, exports — the three things an auditor actually asks for. We build supplier-assurance tooling and we're honest about what it's for: no 24/7 SOC, no managed endpoint agents.

How it fits together
Evidence records

Sub-processor lists, certificates, audit reports — linked, dated, hash-anchored, with reviewer attribution. Always the latest version.

Decision trace

Every approval, rejection, and escalation timestamped and signed. Auditor asks "why was that rejected" — you hand over the trace.

Audit-ready exports

Machine-readable export of every approved evidence record, every reviewer decision, every signed dossier — built to match the structure a NIS2 auditor expects.

Decision trace ready for the regulatorAuditor question answered by a signed, hash-anchored decision trace with five entries from risk tier through final approval.?Auditor question"How did you assess Cirrus Edge Networks for NIS2 21(2)(d)?"Decision traceEdge ingress · REV-2026-014Risk tier set: Tier 2 / HighApr 12 · You8/8 questionsISO 27001 + SoA approvedApr 18 · Yousha256:f1c…Sub-processor list v2 approvedApr 22 · Yousha256:7d2…Privileged access review approvedApr 22 · Yousha256:b8e…Approved · valid until Oct 26, 2026Apr 26 · YousealedEvery entry timestamped, signed, hash-anchored.Hand it over. Walk away.
Pavel Láska — founder of Shards Cybersecurity

Pavel Láska.

Founder · Bratislava

Built by the practitioner.

Shards Cybersecurity was founded by Pavel Láska — a CISSP- and CISM-certified cybersecurity practitioner with over a decade across banking, pharma, and education.

Eight years in the banking sector progressing from senior engineer to senior risk manager. Time on critical financial infrastructure. Then a global security services team in pharma across three continents. He was the one filling the spreadsheets, defending the supplier decisions, prepping for the audits. Vittnor is the tooling that should have existed back then.

The product was shaped by quiet conversations with practising CISOs and security leads across regulated industries — people who've sat in the audit chair, defended supplier decisions to boards, and lived with the consequences. They're not named on this page, but they're in the product.

Bratislava · CISSP · CISM · Microsoft Partner

Microsoft Partner
Microsoft Partner

Built on Microsoft Azure, with a Microsoft-first architecture and security model. Microsoft Marketplace listing goes live Q4 2026; V1 commercial launch Q1 2027.

EU-based

Bratislava-headquartered, EU-hosted. In pilot conversations with regulated buyers across the EU and UK.

NIS2-focused

Designed for NIS2 supply-chain obligations from day one — not retrofitted from a generic GRC suite.

4.0 / How it starts

Two ways to start. Both open today.

The pilot

Run your supplier register in Vittnor — free for the first cohort of design partners. You shape what ships; V1 lists on the Microsoft Marketplace Q4 2026.

Not ready to pilot software?

Start with the NIS2 Supplier Exposure Assessment — fixed scope, fixed deliverable, €3,900 one-off. A practitioner-written report on where your supplier risk actually sits, in two to three weeks.

The pilot, step by step
01
Apply

A ten-minute form about your company and suppliers. No sales team screens it — you hear back from the founder personally.

02
Scoping call

Thirty minutes on your supplier register and what the pilot should prove for you.

03
Go live

Your first suppliers in Vittnor within two weeks.

5.0 / Join the pilot

Pilot open today. Free for the first cohort.

We help you, you help us — the first cohort shapes what we build next. After the pilot: published prices, no quote calls. See pricing →

Nothing to install, no credit card, no procurement cycle — the pilot runs on your real supplier register in Vittnor.