Skip to main content
BS

Bounded Systems

Bounded Systems provides a SaaS platform that continuously translates NIS2, DORA, and AI Act regulations into executable controls and monitors the full dependency graph of an enterprise’s digital supply chain. The system uses recursive AI to map multi‑tier vendor relationships, delivers real‑time risk scores and cryptographic audit evidence, and integrates with GRC and SIEM tools via FHIR‑compatible APIs.

Updated 2 months ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Organizations subject to NIS2, DORA, and the AI Act must continuously assess the security and compliance posture of every third‑party software component and AI service they rely on. Traditional risk registers are static, jurisdictional exposure is hidden, and periodic questionnaires fail to provide real‑time assurance.

Solution

Bounded Systems delivers a SaaS platform that translates regulatory texts into executable compliance controls and continuously monitors the full dependency graph of an enterprise’s digital supply chain. Recursive AI inference maps tier‑N vendor relationships, evaluates jurisdictional risk, and generates cryptographic proof of control execution. A secure EU‑hosted dashboard presents real‑time compliance evidence, risk scores, and alerts on regulatory events such as bans or policy shifts. The solution integrates with existing GRC and SIEM tools via FHIR‑compatible APIs, enabling automated evidence collection for audits. Continuous verification replaces quarterly questionnaires, providing audit‑ready logs and role‑based access controls that satisfy GDPR, NIS2, and AI Act requirements.

Target Audience

Primary customers are operators of EU‑critical infrastructure, public‑sector agencies, and large enterprises that must demonstrate continuous compliance with NIS2, DORA, and the AI Act.

Features

  • Recursive AI engine that discovers and visualizes multi‑level third‑party dependencies across SaaS, IaaS, and AI model providers.
  • Automated mapping of NIS2, DORA, and AI Act clauses to enforceable controls (e.g., encryption‑at‑rest, token rotation, access‑matrix validation).
  • Real‑time regulatory intelligence feed that flags sovereignty‑related events (bans, jurisdictional policy changes) and updates risk scores instantly.
  • Continuous compliance verification pipeline (bounded_verify.sh) that produces immutable logs and cryptographic attestations for audit trails.
  • Secure EU‑hosted architecture with end‑to‑end encryption, role‑based access, and compliance‑ready data residency on Hetzner Germany.
  • Open APIs (FHIR/REST) for seamless integration with GRC platforms, SIEMs, and incident‑response workflows.
  • Vendor risk matrix dashboard highlighting high‑risk jurisdictions, exposure levels, and remediation status in a single view.
This profile is AI-generated and may contain inaccuracies.