//Compliance autopilot · EU-hosted

Compliance questionnaires, answered with their source.

Attestria drafts audit-ready answers to TISAX, EcoVadis, LkSG, NIS2 and more — grounded in your own documents, reviewed by your team.

One inbox, every format
TISAX / VDA-ISA EcoVadis LkSG NIS2 ISO 27001 BSI GDPR / DPA Custom formats
SYSTEM · READOUT EU · Frankfurt
Coverage
8 regimes
Evidence
Citation + confidence
Review
Human decides
Hosting
EU · Frankfurt
LAT 49.142 · LON 9.211 · HEILBRONN ATTESTRIA · COMPLIANCE KERNEL v0.1.0 · PRE-SEED
01Problem

Suppliers are drowning in recurring questionnaires.

If you supply Bosch, ZF, Daimler, Audi or Porsche, your buyers send a constant stream of compliance questionnaires — each in its own format, asking similar things again and again.

Inbox pressure Signal route · live Manual loop
Repeats for every questionnaire
Workload profile 04 indicators
METRIC_01 Attestria research

20–80forms / yr

questionnaires per supplier

METRIC_02 Operational range

8–60h / form

manual work per questionnaire

METRIC_03 Operational range

200–400h / yr

annual effort at 200 employees

METRIC_04 IHK Osnabrück, 2024

67%

of firms >250 staff already get LkSG forms

Today it is done by hand — Excel, Outlook, SharePoint, old answers. Slow, repetitive and audit-risky: one inconsistent answer can affect an audit or a customer relationship.

02Inbox to output

From inbound questionnaire to buyer-ready response.

Attestria follows the same workflow a compliance team would, but turns it into a repeatable agentic process with citations, confidence scoring, and human control.

PROC_01 PARSE

Detect and parse the format.

The agent monitors a compliance inbox or uploaded file, identifies whether the request is EcoVadis, IntegrityNext, VDA-ISA TISAX, BSI-Grundschutz, ISO 27001, LkSG, NIS2, AVV/DPA, or a custom Excel/PDF, then decomposes it into structured questions.

PROC_02 GROUND

Retrieve grounded company evidence.

For every question, Attestria searches the supplier's own documents: ISO certificates, ISMS policies, prior responses, VSME reports, AVV templates, privacy policies, audit reports, incident plans, and supplier codes of conduct.

PROC_03 RENDER

Draft, review, and render back.

The system drafts answers with source citations and confidence scores, routes low-confidence or legally risky responses to human reviewers, then fills the original Excel, Word, PDF, or portal format the buyer requires.

03How it works

Attestria drafts. The human decides.

Six steps from inbox back to the original format — with a source and a confidence level on every answer.

Live

See source-backed answers across different documents.

Five real questionnaire patterns — each with a question, source, draft, confidence score, and human review path.

Document scenario · 5 Cases · Citation mode
Agent live Eval · 32MS
Source from your documents Parsed
01 TISAX Do you enforce multi-factor authentication for remote access to systems processing customer data?
02 SRC-01 Remote access to production systems requires MFA via the central identity provider — mandatory for all employees and contractors.
03 ECOVADIS Does the company track energy use, Scope 1 and Scope 2 emissions, waste, and water consumption?
04 SRC-02 Energy consumption, Scope 1 and Scope 2 emissions, waste volumes, and water usage are recorded quarterly in the sustainability register.
05 AVV List sub-processors and describe how customers are notified before changes.
06 SRC-03 Current sub-processors are maintained in the vendor register. Customers are notified before material changes and may object within 30 days.
07 NIS2 Within what timeframe do you report significant security incidents to the competent authority?
08 SRC-04 Significant incidents are reported to the BSI as an early warning within 24 hours of detection; a full report follows within 72 hours.
09 LKSG Do you operate a grievance mechanism that is also open to the employees of your direct suppliers?
10 SRC-05 An internal whistleblower system is open to all own employees. Whether it also reaches suppliers’ employees is not stated in the documents.
Draft with evidence Citation mode + Faithfulness
Do you enforce multi-factor authentication for remote access to systems processing customer data?
TISAX · XLSX ISMS Policy v3.2 · §4.1
Confidence 92%
TISAX · XLSX · Ready for sign-off
Yes. MFA is enforced for all remote access to systems that process customer data — via the central identity provider, for employees and contractors. ISMS Policy v3.2 · §4.1
TISAX · XLSX · EcoVadis · PDF · DPA · DOCX · NIS2 · XLSX · LkSG · PDF
0% · 0 / 5
Question · ISO 27001 / TISAX

Do you enforce multi-factor authentication for remote access to systems processing customer data?

Source from your documents
ISMS Policy v3.2 · §4.1

Remote access to production systems requires MFA via the central identity provider — mandatory for all employees and contractors.

Draft with evidence

Yes. MFA is enforced for all remote access to systems that process customer data — via the central identity provider, for employees and contractors. ISMS Policy v3.2 · §4.1

Confidence 92%
Ready for sign-off
Multi-format coverage

One response layer for the compliance formats hitting the same inbox.

Attestria is not another single-format ESG tool. The product is designed around the convergence of supplier questionnaires across sustainability, supply-chain due diligence, cybersecurity, data protection, and buyer-specific templates.

04Why it works

The hard part is trust, not text.

Writing an answer is easy. The valuable — and difficult — part is making it reliable enough for an audit.

05Sovereignty

Built where your data lives. Routed how you choose.

Keep inference inside the EU or explicitly opt into another model per workspace. Stored documents and audit history stay tenant-isolated in Europe either way.

MODEL ROUTE · CHANGE ANY TIME
US · BLOCKED

Sovereign by default.

Paris → Frankfurt → Germany → Paris. Customer context stays on the EU processing path; no US model receives it.

  • Mistral La Plateforme · EU inference
  • Hetzner + IONOS · German infrastructure
  • Tenant-isolated storage remains in Europe
INFRASTRUCTURE · EU-HOSTED
  • Compute Hetzner · Germany
  • Inference Mistral · Paris
  • Fallback IONOS · Germany
  • Data Postgres, tenant-isolated

Default route: Mistral EU. Every external provider route requires tenant opt-in and the corresponding contract and retention controls.

Next step

One real questionnaire. Your real documents.

Let’s talk for 20 minutes. We’ll listen to how compliance works for you today — and whether Attestria can take the repetitive part off your plate.

// UPLINK · EU-FRANKFURT · READY