ISO 27001 · STAGE 2 IN SEPTEMBERISO/IEC 27001:2022Certification in progress.
Stage 1 completed.
Stage 2 audit scheduled for September 2026.
European SovereigntyEuropean InfrastructureHosted on Bounded-operated Hetzner
infrastructure in Germany.
Supply Chain Security
for Critical Infrastructure
Takecontrolofcritical suppliersanddependencies.
Bounded connects supplier data, contracts, access, and risks into a live map of your most critical dependencies, providing traceable evidence for NIS2 / Cyber Resilience Act compliance.
Securityinthesupplychain.
Critical suppliers and subcontractors can affect security, continuity, and compliance. NIS2 requires systematic risk management and follow-up.
Manual review is not enough.
The supplier landscape changes continuously. New subcontractors, accesses, terms, and incidents mean static lists and assessments quickly become outdated.
Automation & Expertise.
We automate continuous monitoring, and our legal experts secure your contracts. You get in-depth control and verified compliance during audits.
From analysis to verified compliance.
Mapping
Our system establishes and maintains a register of suppliers, including identified SaaS and AI used in operations. Subcontractors, contractual risks, and third-country exposure are mapped as relevant information becomes available.
Contract Review
Our legal experts review your existing contracts. We propose amendments to ensure compliance with the new requirements in NIS2 and the Cyber Resilience Act.
Continuous Monitoring
Security is perishable. Our system monitors relevant supply-chain signals and alerts you when new vulnerabilities or changes to risk profiles are identified.
Incident Reporting
When a significant incident occurs, we support you through the reporting steps to the authorities, ensuring reporting takes place within regulatory deadlines.
Documentation
Mappings, contract assessments, risks, and actions are gathered into a cohesive chain of evidence. The documentation for annual evaluations is always available.
Sanitized
Contracts.
Weparsevendoragreementstoidentifyclausesthatmayexposeyoutounauthorizedthird-countrydatatransfersorforeignintelligencelawssuchasFISA702andtheCLOUDAct.Theresultingexposureissurfacedforreviewandremediation.
DATA PROCESSING ADDENDUM
Vendor Agreement v3.4
This Data Processing Agreement ("Agreement") is entered into by and betweenSvea Energi AB(Reg. No.556000-1111) and the Supplier.
The total compensation for the Services amounts to€1,500,000per quarter. The designated representative for this Agreement isAnna Andersson, Chief Security Officer.
The Parties hereby agree that all data shall be processed exclusively within the EU/EEA. The Supplier's systems are covered by an SLA with99.9% uptime.
Hard EU
Borders.
Customer documents and permanent platform data are stored on Bounded-operated infrastructure in the European Union. Where external services are used, processing is minimized, limited to what is necessary, and disclosed. Bounded maps non-European sub-processors so jurisdictional exposure can be reviewed and acted on.
DEFENSIVE ARCHITECTURE
TheInfrastructureSchematic
Your organization rests on a stack of third-party code. NIS2 Article 21 mandates supply chain security.
Quantify External Risk
Your vendors extend your perimeter. Their vulnerabilities are your liabilities. Bounded is the checkpoint.
Market Focus
Defense & Gov
Enabling European sovereignty
Critical Infrastructure
Safeguarding operational continuity
NIS2, AI ACT & CRA
Automating enterprise compliance
Compliance Ready
Designed for NIS2, CRA, and AI Act compliance



News & Insights
Latest Updates

When AI finds a zero day, trusting the cloud is not enough
OpenAI's models found a previously unknown vulnerability, broke out of an isolated test environment and reached parts of Hugging Face's production infrastructure. The incident shows why a supplier list is not the same thing as a map of the digital supply chain, and why "it runs in Microsoft's cloud" is not a security assurance.

When AI tools become part of the supply chain
On 12 June 2026, Anthropic restricted access to two models following a US export control directive. For European critical infrastructure, the lesson is not about data access. It is about uncontrolled dependency on the tools an organisation is starting to rely on.

We can't sell control if we don't build with control
We've chosen not to build Bounded on Amazon, Google or Microsoft. Not because we're against American technology, but because we help customers understand and manage their digital dependencies. That means we can't build in dependencies of our own that would make it hard to act if the conditions change.
Contact
Request Access
Enterprise deployment. EU infrastructure. For critical and regulated entities.