KnightGrid

Regulated vendor decisions

Know what you’ve approved.

KnightGrid determines what must be verified for each vendor, evaluates the evidence against those requirements, and records the basis for every approval.

Decision Record · KG-2026-04-1184
Castor Payments
Company no. 12947013  ·  FRN 942188  ·  2026-04-22 · 14:08 UTC
Evaluating
Composite Score
0.00 / 1.00
Tier 1 threshold: 0.75 · Computing…
Tier Classification
1
Material outsourcing · SS2/21 scope
Controls Evaluated
0 of 22  ·  in progress
Control Breakdown
Security & access 0/8 Ops resilience 0/6 Data protection 0/5 Fin & gov 0/3
Evidence Basis
SOC 2 Type II (2026-Q1) · ISO 27001 cert · PCI DSS Level 1 · signed DPA · financials FY25
Reasoning
All 22 controls satisfied at evidence level 2 or above. No material gaps in resilience, data protection, or financial controls. Composite score exceeds Tier 1 threshold by 0.07.
Snapshot Hash
sha256: ··· ···· ···· ···· ···· ···· ···· ····
Pending cryptographic seal

Where approvals fail

An approval is not the same as a decision.

Most vendor files show that work was done. Few show what was decided, on what basis, and whether it still holds.

Failure 01

Wrong entity

The assessment is attached to a trading name, a parent or a lookalike, not the company you contract with.

ContractedCastor Payments
AssessedCastor Payments Group
Addressed at 01 · Intake →
Failure 02

Thin coverage

The evidence exists, but it doesn’t cover the controls the approval relies on.

EvidenceSOC 2 Type II
ScopeExcludes contracted service
Addressed at 03 · Evidence →
Failure 03

Stale approval

The decision was right when it was made; the evidence behind it has since expired.

ApprovedApr 2026
Pen testDated Dec 2025
Addressed at 05 · Lifecycle →
How KnightGrid works

From a legal entity to a defensible decision.

Five connected stages determine what must be checked, what the evidence proves, who owns the judgment, and when the decision must be revisited.

Vendor identity · E0 gate
Legal nameCastor Payments
Company no.KG-000041
JurisdictionGB · United Kingdom
Exposure pathFULL ASSESSMENT
Entity key
KG-000041
Identity confidence
0.94
Gate result
Full assessment →
01 / Intake

Start with the right legal entity.

Resolve who the vendor is, check prior history, and apply the E0 exposure gate before any control work begins.

Learn more
Exposure factors considered
Data17
Access22
Blast radius15
Regulatory10
Criticality15
Risk score
79
/ 100 maximum
Assigned tier
Tier 1
Controls scoped
22
of 29 controls
02 / Classification

Scope the assessment from exposure.

Five dimensions determine the tier and select only the controls that this vendor must prove.

Learn more
Evidence chain · accepted items
SOC 2 Type IIverified
Signed data processing agreementaccepted
Independent penetration testverified
Incident plan + exercise recordaccepted
MFA configuration evidenceverified
Entity match
Confirmed
Evidence coverage
Complete
Reviewer attention
1 flag
03 / Evidence

Verify controls—not answers.

Evidence is mapped to the controls it supports and evaluated for strength, coverage, freshness, entity match, and conflicts.

Learn more
Decision record · KG-2026-04-1184
Computed outcomeYellow
Scoped controls
DecisionCONDITIONAL APPROVAL
Snapshot hash7f4a…91c2
Tier
1
Approval owner
A. Morgan
Chief Operations (SMF24) · 16:42 UTC
Record state
Frozen
04 / Decision

Compute the outcome. Preserve the judgment.

Rules produce the traffic light. Named people own evidence acceptance, exceptions, overrides, and the final approval.

Learn more
05 / Lifecycle
Reassessment schedule · Castor Payments
22 APR 2026Initial decisionapproved · frozen
22 OCT 2026Scheduled reviewupcoming
14 FEB 2027Evidence expirySOC 2 renewal
15 SEP 2026Material changereassessment triggered
Lifecycle state
Active
Events logged
6
Next review
22 OCT 2026
Change signal
Monitored
Decision record
Exportable
05 / Lifecycle

Reassess when the facts change.

Scheduled reviews, evidence expiry, legal-entity changes, incidents, and material service changes bring the decision back into review.

Learn more

Sealed at sign-off

Take nobody’s
word for it.
Including ours.

A vendor approval is a chain of people relying on the one before: the vendor’s answers, the reviewer’s judgment, the approver’s signature. KnightGrid seals the decision when it is signed. Change one character afterwards and the seal no longer matches.

Try to alter it →
KnightGrid seal on a sealed decision record KNIGHTGRID · SEALED DECISION RECORD · SHA-256 · 41B027D7AAE7F7D5DE13C74D854E7776 ·
Castor Payments · Conditional approval
A. Morgan · 22 April 2026
SHA-256 · 41b027d7…98582fd3f
Who uses it

One decision record. Three accountable teams.

Security & CISO teams verify control outcomes. Internal Audit tests the decision trail. Risk and Compliance monitor the portfolio—without maintaining three different versions of the truth.

Tier 1 · 8 material controls shown
ControlOutcomeEvidence basis
MFA enforcementPassConfig + logs
Logging and monitoringPassSystem logs
Role-based accessPassAccess config
Vulnerability managementPassScan report
Independent pen testReviewReport · 9 mo.
Incident responsePassPlan + exercise
Scoped controls
22
of 29 evaluated
Reviewer queue
1 control
Hard gates
Satisfied
01 / Security & CISO

Review the control outcome and its evidence basis.

Security sees which controls passed automatically, which evidence supports them, and where human attention is still required.

See the Security & CISO workflow →
01Frozen classification inputsverified
02Control and question library versionsbound
03Evidence manifest and acceptance actionscomplete
04Exceptions, overrides and approval ownerlogged
05Decision replay from frozen snapshotidentical
Snapshot
7f4a…91c2
SHA-256 comparison
Active overrides
0
Record integrity
Verified
02 / Internal Audit

Replay the decision instead of reconstructing it.

Audit can trace the outcome from frozen inputs, evidence references, rule versions, reviewer actions, and the accountable approval.

See the audit workflow →
247 active vendors218 approved22 conditional7 in review
VendorTierConfidenceDecision expiryCurrent state
Castor Payments UK1Moderate22 OCT 2026Approved
Meridian Cloud Services20.7614 MAR 2027Approved
Halford Data20.6808 JUL 2026Conditional
Trentside Analytics30.9119 FEB 2027Approved
Holborn Risk Solutions20.7115 APR 2027Approved
Material-change signalDPA sub-processor list updated
ImpactDP-C5 evidence may be stale
System actionReassessment queued
Prior decisionPreserved · not overwritten
03 / Risk & Compliance

Monitor the portfolio without rewriting history.

Teams can find expiring evidence, active exceptions, material changes, and reassessments while every previous decision remains frozen and traceable.

See the risk & compliance workflow →