Bounded provides a cloud platform that continuously aggregates and visualizes critical supplier data, contracts, access rights, and risk metrics for organizations subject to the EU Cybersecurity Act and NIS2.
Funding
Funding not disclosed
Founders
Product
Problem
Organizations subject to the EU Cybersecurity Act and NIS2 must continuously monitor and document the security posture of critical suppliers and sub‑suppliers. Manual collection of supplier data, contracts, access rights and risk indicators quickly becomes outdated, leading to non‑compliant reporting and increased exposure to supply‑chain cyber incidents.
Solution
Bounded offers a cloud platform that aggregates supplier information, contractual documents, access permissions and risk metrics into a live, visual map of an organization’s most critical dependencies. The system automates data collection from vendors, encrypts all contracts within the EU, and applies AI to extract only the relevant risk clauses while masking personal and sensitive data. Results are stored in a secure, access‑controlled environment and can be exported as traceable evidence for regulatory reporting under the Cybersecurity Act and NIS2. Continuous monitoring and automated alerts help organizations maintain up‑to‑date compliance and reduce the likelihood of supply‑chain cyber incidents.
Target Audience
Primary customers are public‑sector agencies, utilities and other operators of essential services in Europe that must comply with NIS2 and the EU Cybersecurity Act, as well as large enterprises managing extensive third‑party supply chains.
Features
- Automated onboarding workflow that requests and receives supplier data and contracts via secure channels
- End‑to‑end encryption of all contractual documents with storage on EU‑based servers and strict access controls
- AI‑driven clause extraction that isolates required risk provisions while redacting personal data, amounts and other sensitive information
- Dynamic dependency graph that visualizes critical suppliers, sub‑suppliers, access rights and associated risk indicators in real time
- Continuous compliance dashboard with built‑in NIS2 and Cybersecurity Act checklists and exportable audit trails
- Alert engine that notifies stakeholders of changes in supplier risk status, new contracts, or missing documentation