ISO LogoISO 27001 · STAGE 2 IN SEPTEMBER
European Sovereignty ShieldEuropean Sovereignty

Supply Chain Security
for Critical Infrastructure

Takecontrolofcritical suppliersanddependencies.

Bounded connects supplier data, contracts, access, and risks into a live map of your most critical dependencies, providing traceable evidence for NIS2 / Cyber Resilience Act compliance.

COORD: 55.6050° N, 13.0038° E
NET_OP: MONITORED

Securityinthesupplychain.

Critical suppliers and subcontractors can affect security, continuity, and compliance. NIS2 requires systematic risk management and follow-up.

Manual review is not enough.

The supplier landscape changes continuously. New subcontractors, accesses, terms, and incidents mean static lists and assessments quickly become outdated.

Automation & Expertise.

We automate continuous monitoring, and our legal experts secure your contracts. You get in-depth control and verified compliance during audits.

From analysis to verified compliance.

01

Mapping

Our system establishes and maintains a register of suppliers, including identified SaaS and AI used in operations. Subcontractors, contractual risks, and third-country exposure are mapped as relevant information becomes available.

02

Contract Review

Our legal experts review your existing contracts. We propose amendments to ensure compliance with the new requirements in NIS2 and the Cyber Resilience Act.

03

Continuous Monitoring

Security is perishable. Our system monitors relevant supply-chain signals and alerts you when new vulnerabilities or changes to risk profiles are identified.

04

Incident Reporting

When a significant incident occurs, we support you through the reporting steps to the authorities, ensuring reporting takes place within regulatory deadlines.

05

Documentation

Mappings, contract assessments, risks, and actions are gathered into a cohesive chain of evidence. The documentation for annual evaluations is always available.

Sanitized Contracts.

Weparsevendoragreementstoidentifyclausesthatmayexposeyoutounauthorizedthird-countrydatatransfersorforeignintelligencelawssuchasFISA702andtheCLOUDAct.Theresultingexposureissurfacedforreviewandremediation.

DATA PROCESSING ADDENDUM

Vendor Agreement v3.4

This Data Processing Agreement ("Agreement") is entered into by and betweenSvea Energi AB(Reg. No.556000-1111) and the Supplier.

The total compensation for the Services amounts to€1,500,000per quarter. The designated representative for this Agreement isAnna Andersson, Chief Security Officer.

The Parties hereby agree that all data shall be processed exclusively within the EU/EEA. The Supplier's systems are covered by an SLA with99.9% uptime.

Hard EU Borders.

Customer documents and permanent platform data are stored on Bounded-operated infrastructure in the European Union. Where external services are used, processing is minimized, limited to what is necessary, and disclosed. Bounded maps non-European sub-processors so jurisdictional exposure can be reviewed and acted on.

TheInfrastructureSchematic

Your organization rests on a stack of third-party code. NIS2 Article 21 mandates supply chain security.

Quantify External Risk

Your vendors extend your perimeter. Their vulnerabilities are your liabilities. Bounded is the checkpoint.

Market Focus

Defense & Gov

Enabling European sovereignty

Critical Infrastructure

Safeguarding operational continuity

NIS2, AI ACT & CRA

Automating enterprise compliance

Compliance Ready

Designed for NIS2, CRA, and AI Act compliance

NIS2 Compliance
NIS2
Network Security
CRA Compliance
CRA
Cyber Resilience
AI Act Compliance
AI Act
Artificial Intelligence

Contact

Request Access

Enterprise deployment. EU infrastructure. For critical and regulated entities.