For Procurement & Panel Evaluators
You'll find the gaps anyway. Here they are up front.
You evaluate vendors for a living — you know the difference between a capability statement and a capability. This page is the due-diligence table we'd want to receive: what's verified, what's in progress, and how the engagement is structured so a young vendor is a bounded risk, not a leap of faith.
"Every response says 'enterprise-grade' and 'bank-level security'. My job is to find out which claims survive a document request — and the vendors who volunteer their gaps before I find them are the ones I shortlist."
— How evaluation actually works. So: the matrix, unvarnished.The credibility matrix, SCM0020-style
| Criterion | Status | Evidence |
|---|---|---|
| Technical capability — working product | Verified | Deployed and operating on SAP BTP; 7 asset-class risk engines, 6 regulator packs, optimisation and evidence tooling. Live demonstration on your data available within two weeks. |
| Security posture — application | Verified | OAuth2/XSUAA, role-based scopes, tenant + project/contract row-level security, CSP/HSTS/nosniff headers, rate limiting, field-level audit logs, soft-delete only, no secrets in code. Automated conformance check: 13/13. |
| Quality assurance | Verified | 190+ automated checks in CI (unit, mutation-tested, end-to-end, security, chaos), coverage gates, WCAG 2.2 AA accessibility pass. |
| Data sovereignty | Plan stated | Current environment is SAP BTP US (trial). Production deployments target the SAP Sydney region (AU data residency). IRAP pathway documented; sovereignty requirements addressed contractually per engagement. |
| IRAP / SOC 2 / ISO 27001 | In progress | Not yet certified — control mapping and evidence pack prepared (ISM/Essential Eight, SOC 2 TSC). External assessments are sequenced post-first-revenue. We will not claim these until issued. |
| SAP certification | Submission-ready | Technical conformance self-assessment 13/13 (released APIs, clean core, destinations); ICC submission pack prepared; certificate pending SAP's review process. |
| Insurances (PI / cyber) | Pre-binding | Requirements brief prepared to AU public-sector norms; policies bound before contract execution — evaluators receive certificates of currency at contract, not promises at tender. |
| References | Building | Early-stage vendor: no referenceable production customers yet. Mitigation is structural — see the engagement model below. We'd rather tell you this than have you discover it. |
| Financial viability | Bounded exposure | Fixed-fee, pay-on-acceptance pilots; no long lock-in; your data exportable at any time; solution runs on your SAP BTP subaccount, so continuity does not depend on our infrastructure. |
The engagement model that bounds the risk
Why publish this? Because you'd find it in due diligence anyway, and a vendor who wastes your evaluation time on discoverable gaps is telling you how they'll behave under contract. The gaps above close in sequence; the product you can test today.
Documents on request
The evaluator's evidence pack
Architecture & security
Solution architecture, data model, security controls mapping, conformance-check output, test and coverage reports.
Standards & readiness
IRAP/SOC 2 control mapping, SAP ICC submission pack, standards provenance register, production-readiness report with the open items listed.
Engagement terms
Pilot agreement template with acceptance criteria, published pricing, insurance requirements brief, exit and data-return provisions.
Send us your evaluation template
We'll return it completed, with evidence attached and the gaps marked as gaps — usually within five business days.