Boardroom Answers · Strategic Command · Risk Management & Governance
Our vendor-risk policy would normally screen out a company your size. Escrow, data portability, continuity — walk me through why engaging you is a governable risk rather than a policy exception.?
The question a Board Member / Non-Executive Director (NED) asks.
The short answer
Your exit is provisioned before you enter: standard Postgres, shipped export and executed erasure, continuous PPTX/XLSX/PDF output, escrow on enterprise terms with triggers your counsel drafts. The open risks — certification, operating history — go in the contract as milestones, not into a trust fall.
The full executive answer
Your policy is right to be suspicious of small vendors, so let me address its three standard tests in order. Portability, which is the strongest today: your data lives in standard PostgreSQL — no proprietary format — and full structured export is shipped, working code, built to GDPR Article 20 and DPDP Act 2023 portability standards; alongside it, erasure is executed code, not a promise: when you leave and instruct deletion, deletion demonstrably happens. Board packs and analyses additionally export to PowerPoint, Excel and PDF continuously, so at any moment your accumulated work product already exists outside our systems in usable form. On day one of an engagement, your exit is already provisioned.
Continuity: the resilience architecture is real — dual AI providers, managed database with point-in-time recovery, incident management with a public status page — but I will not dress it as more than it is: we have not yet executed the full disaster-recovery drill or obtained third-party certification, so continuity assurance today rests on architecture plus contract rather than on audited evidence. Which brings me to escrow: source-code escrow with defined release triggers — insolvency, sustained service failure, sunset after change of control — is available on enterprise agreements, and I would encourage your counsel to draft the triggers aggressively. For a founder with nothing to hide, escrow is cheap; treat willingness to grant it as the diligence signal it is.
Frame it through your own third-party-risk methodology and the residual risk profile is unusual for our size: the catastrophic vendor-failure scenarios — data loss, data hostage, evidence-trail destruction — are each mitigated technically, not just contractually: exports and erasure are shipped code, the audit chain is append-only and hash-verifiable, tenant isolation is enforced and CI-tested at the database layer. The genuinely open risks are certification and operating history, both of which are on a dated roadmap — SOC 2 Type I and an external penetration test ahead of enterprise general availability — and both of which your contract can carry as conditions or milestones rather than as blind trust.
Grounded in: Third-party risk management (TPRM) · GDPR Art. 20 / DPDP Act 2023 · SOC 2 (roadmap milestone)
The natural next questions
Related governed answers
- As a director I see risk through a heat map twice a year, and I know it is theatre. What does board-level risk reporting look like out of your platform, and how is it less theatrical?
- The EU AI Act is now enforcing. Where does your platform sit under it — and is any of it high-risk?
- Let me be blunt. If this board approves a major decision based on your AI’s analysis, the analysis turns out to be hallucinated, and the company takes a nine-figure loss — who is liable, what happens to my name, and why did your product not prevent it?
Want this answered live, on your data?