Know who controls your data stack.
Map every supplier touching your data. Prove what you know. Spot what is missing. Plan your exit before it becomes political.
Every status describes the evidence on record — found, declared, missing or needs review — never a verdict about any supplier.
The questions have started. The register is the answer.
The Procurement Act 2023 duties are live
Contract-management and transparency duties now expect public bodies to actively manage supplier contracts — with records, not memories.
Supplier sovereignty is being scrutinised
Committees, journalists and residents ask who owns the platforms handling public data and what the exit plan is. The answer should come from a register, not a scramble.
Exit options expire quietly
Auto-renewing contracts with notice windows make doing nothing a decision. Recorded dates turn exit options into choices you actually get to make.
From supplier map to Sovereignty Pack.
Control Room composes your Trustfile register — vendors, documents, contract terms and declared facts — into the supplier-assurance view a public body is expected to have.
The supplier map
Every supplier that touches your data in one table — country, ownership, hosting, criticality and the systems that depend on it. Unknowns show as gaps to close, never guesses.
The evidence checklist
A fixed 10-item checklist per supplier — DPA on file, hosting declared, break clause known, portability recorded and more. Each item is found, declared, missing or needs review.
Contract terms & exit windows
End dates, auto-renewals, notice windows and break clauses on record, feeding your review calendar — so a renewal is a decision you make, not a deadline you discover.
Supplier questionnaires
Send a sovereignty questionnaire from the supplier's page. Answers land as declarations awaiting your review — external input never overwrites what you have confirmed.
The Sovereignty Pack
One download for scrutiny: the supplier summary, contract status and evidence gaps as CSVs plus an exit-readiness report, sealed with a per-file integrity manifest.
The public suppliers block
Opt in to publish the suppliers you have declared on your trust page — names, countries and hosting only. What you have not verified stays unpublished.
Evidence, never verdicts.
Control Room never marks a supplier “safe” or “approved”. Statuses come from deterministic checks over what your register holds; a supplier’s own answers stay “declared” until a person confirms them; and AI never sets a status, score or deadline. Gaps are shown honestly as gaps — that is what makes the record credible under scrutiny.
Included in Trustfile Pro.
Control Room ships as part of Trustfile Pro — no separate product to buy. Public-sector supplier and consultant pricing on request, and a one-off Sovereignty Audit is available as a fixed-scope engagement.
When someone asks “how would we leave?”, have the answer on file.
Start with your supplier map — the gaps it shows you are the work.