#48
Monthly Rank
#108
Lifetime Rank
Share
11 September 2026
Fiducia

Fiducia

Trust Before Transfer

Gallery

About the Project

Fiducia is an AI-powered vendor due-diligence and compliance assessment platform designed to help legal, privacy, compliance, security, and procurement teams make faster and more defensible decisions when onboarding third-party vendors.

When an organisation shares personal or sensitive data with a vendor, the review process is often fragmented across contracts, security documentation, privacy policies, regulatory requirements, and cross-border transfer considerations. Fiducia brings these elements into a single evidence-driven workflow.

Users can upload vendor documents and assess them against frameworks including India’s DPDP Act, GDPR, UK GDPR, CCPA/CPRA, ISO 27001, SOC 2, NIST, and Bahrain requirements. Fiducia identifies gaps, links findings back to supporting evidence, highlights areas requiring human review, and provides remediation recommendations.

A key focus is cross-border data transfers. Rather than simply assigning a country-risk score, Fiducia helps identify the relevant transfer mechanism, the evidence supporting that mechanism, and issues such as missing safeguards or onward-transfer controls.

Fiducia is designed as decision support rather than a replacement for legal judgment. Its outputs are evidence-linked and accompanied by confidence indicators, limitations, audit trails, and a mandatory human sign-off step.

The goal is simple: help organisations answer one practical question before onboarding a vendor:

“Can we safely and defensibly onboard this vendor?”

Practice Areas

Key Features

  1. AI-Powered Vendor Due Diligence — Analyse vendor privacy, security, and compliance documentation in one workflow.

  2. Evidence-Linked Risk Findings — Identify compliance gaps and connect findings to supporting vendor evidence.

  3. Cross-Border Transfer Assessment — Assess international data transfers and identify applicable legal transfer mechanisms and gaps.

  4. Multi-Framework Compliance — Assess vendors against DPDP, GDPR, UK GDPR, CCPA/CPRA, ISO 27001, SOC 2, NIST, and Bahrain requirements.

  5. Risk Scoring & Prioritisation — Surface Critical, High, Medium, and Low-risk issues to focus review efforts.

  6. Remediation Copilot — Turn identified gaps into practical remediation actions.

  7. Human-in-the-Loop Approval — Require human review and sign-off before an assessment is finalised.

  8. Audit Trail — Track AI-generated findings, human review, changes, and approval decisions.

  9. Regulatory & Enforceability Tracking — Distinguish current requirements from upcoming regulatory obligations.

About the Creator

JJ
Joshua Joseph
LinkedIn