+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
Direct ordering switched off while the billed scope is established. The capabilities described below really are this agent's. What remains to be established is exactly what the price covers: until the billed scope and its cost are shown to be consistent, we would rather not sell it online. We price it on quotation, after reviewing your need. The complementary agents named on this page can, however, be ordered separately today, each at its own price. Request a quote
● B2B offer — Publishing of books and periodicals

Third-party cyber risk — Publishing of books and periodicals: suppliers registered, evidence checked

Éditions Lauzanne routes embargoed manuscripts through eighteen providers, seven of whom have never signed a confidentiality clause, and two proof leaks have already occurred. The agent reads the editorial tool, the proofing platform and the distributor extranet: it follows each manuscript link by link, spots the missing clauses and prepares the amendments. The publishing director decides; general management signs. You arbitrate on dated facts: every file arrives with its factors, its counted unknowns and the document that will lift them — and the signature stays yours, handed back in minutes rather than in committee.

Hosted in France Evidence separated per tenant GDPR & AI Act: governed deployment Decision to the authorised manager

Updated on

Twelve modules included
Third-party cyber risk agent
Which of our suppliers should we look at first?
Relationships are ranked on visible factors, not an opaque score: function supported, data entrusted, access granted, substitutability.
Each file carries its unknowns and the date of its most recent evidence.
⛓ Sourced · supplier register, contract vault, access register
This supplier shows us a certification. Is that enough?
The certification is genuine and its scope is readable: it names three services, and the one you use is not among them.
The request pack is ready — statement of applicability and scope annex — and goes out as soon as you approve it.
✎ Framework · a certification covers its scope and its period
Local inference · no data outside the EU
Evidence hosted in France
Sovereign by designLocal inference or French hosting
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
Your managers decideThe agent prepares the file, never decides
✦ In brief

A Blue Lemon Agent third-party cyber risk agent registers the supplier relationship, derives criticality from the functions supported, checks evidence against its scope and period, unfolds the subcontracting chain, measures concentration across the aggregate of services and prepares treatment and exit plans. It runs on local inference or is hosted in France, with an architecture designed to reduce exposure to extraterritorial laws, location alone not guaranteeing immunity.

12
modules included in the core, at no extra cost
13
relationship states, each with its evidence, actor and timestamp
12
controls returned with their result and its justification
6
score dimensions, each with its factors kept

Reference points describing our offer, not results measured at a client. The gain on your supplier portfolio is confirmed by a pilot, on your own files.

Context

What does an AI agent bring to supplier assessment?

A relationship that is registered, quantified and dated is arbitrated in minutes; a file scattered between a contract, an attestation and three emails has to be rebuilt from scratch.

! The stake

Assessing a supplier means gathering what can be verified and naming what cannot. That reconciliation work is systematic and lends itself to automation; deciding to accept a risk commits the organisation.

Our answer

Your managers arbitrate across the whole portfolio rather than the suppliers someone remembers to check — and each file arrives already registered, quantified and dated. Every score keeps its factors, before and after the supplier’s rebuttal: your conclusion holds up in front of them, and it corrects itself when they produce the document. Local inference or an isolated resource hosted in France: your audit reports and dependency maps do not leave the organisation.

The decisive point

Audit reports, contracts and dependency maps: sovereignty & separation

The evidence your suppliers entrust to you describes their weaknesses as much as your dependencies: its confidentiality is a security matter in itself.

Local inference

The agent can run on a machine in your organisation: no audit report, contract or dependency map leaves the network.

Hosted in France

Otherwise a dedicated, isolated resource hosted in France under French law — your supplier evidence and assessments: processing and access operated in the European Union as targeted by the architecture.

Strict tenant separation

A report filed by one client is never readable by another, whoever issued the document. Sharing across tenants requires written, traceable permission.

Reduced extraterritorial exposure

For your audit reports and dependency maps, the architecture aims to reduce exposure to extraterritorial laws; location alone does not by itself guarantee immunity.

Named human gates

Accepting a risk, starting an exit, escalating an incident: three states only an authorised manager can open, with reason and timestamp.

Tamper-evident log

Every transition carries its evidence, actor and timestamp; refusals are logged just as passages are.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For supplier audit reports and dependency maps, SecNumCloud and hardened hosting options are available to match your requirement level. A single architecture is designed to address both the GDPR and extraterritorial exposure.
Demonstration

See the agent at work

4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Éditions Lauzanne — fictional publishing house, 240 titles a year

Sector
General and periodical publishing — 240 titles a year, 4 imprints
Headcount
96 employees, 1 IT manager and no dedicated security role
Who is served
1,900 points of sale, 34,000 subscribers to three magazines
Order of magnitude
240 titles a year, 61 manuscripts in progress, 18 graphic-chain providers
Tools in place
Editorial tool, proofing platform, distributor extranet, subscriber database
Who decides
The publishing director arbitrates; general management approves acceptances
Improvement points
18 providers, 7 with no written confidentiality clause; 2 proof leaks in two years

Éditions Lauzanne routes embargoed manuscripts through eighteen providers, seven of whom have never signed a confidentiality clause, and two proof leaks have already occurred. The agent reads the editorial tool, the proofing platform and the distributor extranet: it follows each manuscript link by link, spots the missing clauses and prepares the amendments. The publishing director decides; general management signs.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

Third-party cyber risk agent
Your third-party portfolio is registered, and here is what sums it up: 18 providers, 7 with no written confidentiality clause; 2 proof leaks in two years.
Registering, here, means linking each supplier to the SERVICE it provides and to the FUNCTION that service supports. Without that link no criticality can be computed — and that link was missing everywhere.
The first file I put on the table: The typesetter for the next embargoed title.
· State opened: assessment in preparation, priority P2, on the fact “criticité et substituabilité visibles”.
· 10 of 12 controls are not compliant, and I tell you which and why, one by one.
· 0 unknown factor(s) — displayed confidence drops to 100%, and the score does not rise by a single point for it.
What I propose: I show you how this ranking recomputes from your own data, factor by factor, with no opaque score in between. parc-recense_relations-et-services.pdf4 business objects linked, each to its owner
⛓ Sourced · supplier register, contract vault, directory
What does this ranking rest on? We have seen scores nobody could explain.
On six separately scored dimensions, each with its weight: criticality of the service supported, freshness and scope of evidence, access and data entrusted, chain and concentration, clauses and audit rights, continuity and exit.
For this file the fact retained is “criticité et substituabilité visibles”, and it comes from your inputs, not from an opinion: criticalFunction = yes, substitutability = low, evidenceFresh = yes.
The score is kept before AND after the supplier’s rebuttal. It never has the last word: it opens a review. The publishing director arbitrates; general management approves acceptances.
And the next step, if you want it: I run the same reading across the whole portfolio and hand you the ordered list, each line with its factors and its date. fiche-relation_facteurs-visibles.pdf6 dimensions, their weights, their factors and the confidence
✎ Framework · the score opens a review, it decides nothing
And what did you draw on to build all of this?
On the twelve modules of the core, and they work together on every file:
· Third-party and service register — Records the supplier, group, service, contract, sub-processors, countries, data, access, owners, dates and relationship status.
· Business criticality and data — Links the service to the functions it supports, target recovery times, volumes, data categories, privileges and substitutability.
· Adaptive questionnaires — Selects questions by criticality and applicable framework, reuses answers still in date, asks for justification and tracks non-responses.
· Evidence collection and checking — Checks period, scope, issuer, signature, qualifications, exceptions, corrective plans and the consistency of the attestations provided.
· Exposure and authorised vulnerability review — Aggregates security advisories, public incidents and the expressly authorised surface, with no intrusive testing and no unproven attribution.
· Risk scenarios — Structures feared events, sources, paths through the third party, existing measures, severity, likelihood and residual risk.
· Explainable scoring — Computes separate dimensions with their factors, weights, unknowns and confidence; keeps the score before and after the supplier’s rebuttal.
· Supply chain and concentration — Maps sub-processors, fourth parties, shared functions, common technologies, countries and substitutes.
· Contracts and requirements — Compares clauses on security, notification, audit, location, subcontracting, continuity, reversibility and deletion.
· Treatment plans — Turns each gap into a measure, with owner, deadline, expected evidence, any exception and a motivated temporary acceptance.
· Monitoring and incidents — Tracks changes, evidence deadlines, relevant vulnerabilities, declared incidents, service commitments and reassessments.
· Exit, evidence and steering — Prepares alternatives, extraction, transition, revocation, deletion and tests; keeps decisions, versions and indicators.
· Sovereign AI — the hosting and confidentiality foundation all of this rests on: local inference or an isolated resource hosted in France.
All twelve are included, at no extra cost: security, traceability, human validation and the demonstrators are never sold as options. modules-mobilises_douze-modules-du-socle.pdfthe twelve core modules and what each brings
✎ Framework · twelve modules included in the core, at no extra cost
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

Twelve modules, a single state machine. All of them work in support, under the approval of your authorised managers.

Included in your agent The 13 capabilities essential to this promise are included, at no extra cost.

Third-party and service register

Records the supplier, group, service, contract, sub-processors, countries, data, access, owners, dates and relationship status.

Business criticality and data

Links the service to the functions it supports, target recovery times, volumes, data categories, privileges and substitutability.

Boundary: qualifies data to size the security risk and the dependency. Lawfulness of the processing, its legal basis and the record of processing activities belong to the DPO/GDPR support agent, billed separately.

Adaptive questionnaires

Selects questions by criticality and applicable framework, reuses answers still in date, asks for justification and tracks non-responses.

Evidence collection and checking

Checks period, scope, issuer, signature, qualifications, exceptions, corrective plans and the consistency of the attestations provided.

Boundary: checks SECURITY evidence — scope, period, issuer. Documents already held by the DPO/GDPR support agent are reused as they are: the same supplier is neither re-surveyed nor billed twice.

Exposure and authorised vulnerability review

Aggregates security advisories, public incidents and the expressly authorised surface, with no intrusive testing and no unproven attribution.

Risk scenarios

Structures feared events, sources, paths through the third party, existing measures, severity, likelihood and residual risk.

Explainable scoring

Computes separate dimensions with their factors, weights, unknowns and confidence; keeps the score before and after the supplier’s rebuttal.

Supply chain and concentration

Maps sub-processors, fourth parties, shared functions, common technologies, countries and substitutes.

Contracts and requirements

Compares clauses on security, notification, audit, location, subcontracting, continuity, reversibility and deletion.

Boundary: carries security, reversibility and notification requirements into the contract. Drafting the Article 28 clauses and the data processing agreement remains the work of the DPO/GDPR support agent.

Treatment plans

Turns each gap into a measure, with owner, deadline, expected evidence, any exception and a motivated temporary acceptance.

Monitoring and incidents

Tracks changes, evidence deadlines, relevant vulnerabilities, declared incidents, service commitments and reassessments.

Exit, evidence and steering

Prepares alternatives, extraction, transition, revocation, deletion and tests; keeps decisions, versions and indicators.

Sovereign AI

The hosting and confidentiality foundation the agent runs on.

Compliance of the processing itself — lawfulness, record of processing activities, impact assessments — and the drafting of Article 28 clauses are NOT part of this core: they are carried by the DPO/GDPR support agent, billed separately. This core handles third-party security, dependency, concentration and exit. The supplier’s identity and the evidence common to both agents are reused: they are not collected twice, and they are not billed twice.

Controls and safeguards These 5 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Keep the evidence, the actor and the timestamp of every transition Refuse by default any sensitive action without an authorised owner Strictly separate tenants, entities and environments
The gain

How many relationships can a team review?

By taking on registration, evidence reconciliation and file assembly, the effort moves to arbitration. The size of the gain depends on your portfolio and remains to be confirmed by a pilot.

Registering a relationship and its chain
Today · done by hand
Relationship registered, chain unfolded
Checking the scope of an item of evidence
Today · done by hand
Scope matched against the service
Assembling the decision file
Today · done by hand
File quantified and reasoned
Illustrative, non-contractual reference points, to be confirmed by a pilot on your supplier portfolio. Accepting a risk, suspending a service, terminating a contract or exercising an audit right commits the organisation: those decisions belong to your authorised managers.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

One plan, one agent

A third-party cyber risk agent — twelve modules included — installed and operated for you. Prices excluding VAT, annual subscription. The twenty sector variants share this price: they change the content, never the engine or the price.

This agent is priced with you, not online. We are adjusting its scope at the moment, and online subscription stays closed while we do. Tell us what you need: we will come back to you with a price. Request a quote
Our commitment

Four guarantees that matter here

Your supplier evidence stays with youLocal inference or an isolated resource hosted in France; no report entrusted to a third party, no data used to train a model.
The decision returns to your managerThe score opens a review; it never selects, suspends or terminates. The file arrives complete, quantified and reasoned: signing takes minutes.
An unknown stays an unknownData that is missing, out of date or unreachable is never counted as a pass. It lowers the confidence shown; it does not raise the score.
No testing without a mandateActive testing on a third party’s system requires a contractual basis, a written scope and an agreed window. Without those three, the authorisation request is prepared and the review continues by permitted methods.
Frequently asked questions

Your questions, our answers

Does the agent certify that a supplier is safe?
It does something better: it lets you decide on documents. Criticality of the service supported, dated evidence matched against its scope, the subcontracting chain unfolded, concentration measured across the aggregate — each with its source and its date. No third party can certify a supplier on your behalf; what you get here is the file that makes your decision defensible, and it stays signed by you.
How does it check a certification or audit report?
It reads the issuer, the period, the scope covered, the statement of applicability and the qualifications. A certification only covers what it names: if the service under review falls outside its scope, the agent says so and opens an evidence review rather than concluding.
Can it scan a supplier without their agreement?
The analysis is non-intrusive and stays within the scope you authorise: nothing that exposes your supplier relationship or puts you in an awkward position. If you want to go as far as active testing, the agent prepares the mandate — contractual basis, written scope, agreed window — and the review moves forward without waiting for it.
How does it handle fourth-party suppliers?
It requests the named list from the supplier and reconciles it with observed flows and onward-subcontracting clauses. Anything not named is recorded as unknown, with the question asked and the date: an incomplete chain is a fact in the file, never a silence.
How does it compute criticality and concentration?
Criticality comes from the functions supported, the data, the access, the dependency and the substitutability — every factor is kept, never merged into an opaque score. Concentration is measured on the aggregate of services: taken one by one each looks replaceable; taken together they are not.
Can the score automatically block a purchase?
The score opens a review, it does not close a door: you keep control of selection, with the file already prepared. That is what makes it usable in procurement — an automatic block gets contested, a reasoned opinion holds. The authorised manager decides in minutes rather than in committee.
How does it track remediation and its evidence?
Each gap becomes a measure with an owner, a deadline and the expected evidence named in advance. The measure closes when that evidence is RECEIVED and validated, not when it is promised: remediation closed without a document stays open in the file.
How does it prepare an exit plan that can actually be tested?
It assembles the alternatives, the extraction format, the transition sequence, the access revocation, the expected deletion and the success criterion for the exercise. A plan that is written but never tested is a hypothesis: the agent says so, and prepares the exercise that would make it credible.
Let's talk

Let us size the potential on your supplier portfolio

15 minutes to scope your services, evidence and managers — hosted in France, supervised, no commitment.