Our first product
Prove every vendor holds what they claim.
Vendra is Hatchify's first product: procurement intelligence and vendor assurance built for Australian enterprises that answer to APRA, the OAIC and the ACSC. It verifies vendor evidence against the register that issued it, maps the fourth parties sitting underneath your suppliers, and runs security, legal, privacy and finance review in parallel instead of in a queue.
Built in Australia. Hosted in Australia. Supported from Sydney.
No form, no sales call — the workspace runs a demonstration portfolio through the live scoring engine
It came out of the work.
A decade of putting AI and cloud into production inside regulated Australian businesses taught us where those projects actually die. Not in the build — in the review. Six approval lanes, each waiting on the last, and a stack of PDFs nobody checked against the register that issued them.
Vendra is what we built to fix that, and it is held to the standard we hold client work to: every risk score explains itself, every regulatory citation records the instrument it was verified against, and the things we have not finished are labelled as unfinished.
It is the Compliance & Governance practice turned into a product, and it is what the Govern stage of the Hatchify Flightpath looks like when you run it every day instead of once per engagement.
Why this makes the consultancy more credible, not less
When we tell a client we can put governed AI into production — with evals, audit trails and a regulator-ready evidence chain — Vendra is the thing we can point at. It runs in production, against the same regulation our clients answer to, and you can open it yourself without asking us.
What it does
Six modules. One evidence base.
These are usually bought as separate tools and stitched together afterwards. Vendra scores, routes and negotiates off the same verified evidence, so nothing has to be re-established at the next stage.
Assurance verification
Where a public register exists — a certification body register, the FedRAMP Marketplace, the CSA STAR registry, the Australian Business Register, the Modern Slavery Statements Register — Vendra checks the claim against it rather than accepting the PDF. Where no register exists, it says so and scores the confidence down.
- Verification method shown on every record
- Scope statement parsed and surfaced
- Confidence scored, never implied
Fourth-party graph
Your vendors have vendors. Vendra builds the dependency graph and finds the hubs — the storage provider sitting beneath six of your suppliers, the offshore support desk that appeared without notice, the subprocessor with no data agreement.
- Shared-dependency detection
- Subprocessor change monitoring
- CPS 230 material fourth parties
Parallel intake
One front door. Security, legal, privacy, finance and architecture all open at once rather than queuing behind each other, each with its own SLA clock. Low-risk purchases auto-clear on evidence Vendra already holds.
- Concurrent approval lanes, not a relay
- Risk-tiered routing from intake answers
- Full audit trail per lane
Contract intelligence
Extracts the terms that decide your exposure — liability caps and their carve-outs, notice windows, uplift ceilings, audit rights, data deletion, AI clauses — and flags where they fall short of your policy or your regulator.
- Clause-level risk flags with the reasoning
- Notice-window countdown before auto-renewal
- Liability tested against data at risk
Renewals and benchmarks
Every renewal opens automatically ahead of its notice deadline with utilisation data and a market position attached, so the conversation starts with evidence rather than a list price.
- Notice deadlines, not just end dates
- Seat utilisation over 90 days
- Category price benchmarks
Grounded copilot
Ask a question in plain English and get an answer computed from your portfolio, with the underlying records attached. Figures are computed, not generated; where a language model is used it narrates those computed facts and is instructed not to introduce anything absent from them.
- Answers cite the records they used
- Runs against live scoring
Australia, properly
The obligations that actually apply here.
Australian regulation tends to show up in global platforms as a compliance-pack line item, if at all. Vendra was built here, for entities that answer to APRA, the OAIC, the ACSC and the Cyber and Infrastructure Security Centre — with the clause references in the product, each one recorded against the instrument it was verified from.
APRA CPS 230
Material service provider register submitted to APRA annually, due diligence and a documented selection process before engagement, and mandated contract provisions including APRA access rights and executable exit plans.
Operational Risk ManagementAPRA CPS 234
Third-party control design evaluated, not just certified. Contractual incident notification tight enough to meet your own 72-hour APRA obligation, with a route to hear about material control weaknesses inside 10 business days.
Information SecurityASD Essential Eight
A maturity level per strategy, scored 0 to 3, with self-assessment clearly separated from independent assessment. A single overall claim tells you nothing.
ASD Maturity ModelIRAP
Classification level, in-scope services and regions, assessor endorsement, and the residual risk register — because IRAP documents risk, it does not remove it.
ISM AssessmentAustralian Privacy Principles
APP 8 accountability for overseas recipients and APP 11 security steps, with storage location and staff access location tracked as the separate questions they are.
Privacy Act 1988Notifiable Data Breaches
A 30-day assessment window that starts when you become aware. Vendra pushes for notification of suspicion within 24 hours, not "without undue delay".
NDB Scheme · OAICModern Slavery
Statements checked against the public register, with the six-month lodgement deadline tracked and overdue suppliers flagged before they land in your own statement.
Modern Slavery Act 2018 (Cth)SOCI Act
Supply chain hazards mapped into your risk management programme across all four hazard categories, with contracts that support 12 and 72-hour reporting.
Critical InfrastructureVendra is not a law firm and does not provide legal advice; the regulatory detail in the registry is a procurement aid, not a legal opinion.
How Hatchify supports it
Australian-owned, and in the room.
Hatchify Pty Ltd has been building for regulated Australian businesses since 2014. Vendra is deployed and supported by the same senior engineers who build our clients' platforms — not a separate support organisation.
Sydney-based, on the ground in Melbourne
We work from Sydney and our engineers are regularly in Melbourne — for the workshop, the architecture review and the conversation with your regulator. Your timezone, and in the room when it matters.
Senior engineers only
No offshore delivery pods and no juniors learning on your engagement. The people who scope your deployment are the people who deliver it.
Onshore by construction
Vendra runs in ap-southeast-2. Customer data does not leave Australia, and neither does support access. No customer data is used to train any model. Subprocessors are published, with 30 days notice and a right to object.
Australian-owned
Hatchify Pty Ltd, ABN 87 600 809 167, established 2014. An AWS Partner Network member, Australian-owned and Australian-operated.
We live in the same regulation
Our consulting clients are in wagering, insurance and financial services. The obligations Vendra tracks are the ones we already build against every day.
Deployment and integration
Identity, data migration and integration into your existing procurement and ticketing stack, delivered as a Hatchify engagement on the Flightpath.
How it is packaged
Three tiers, scoped to your estate.
Annual subscription in Australian dollars, with no percentage of managed spend, no per-request metering, and no charging extra for single sign-on — it is a security control, not a feature. Uplift is capped at CPI for the first three years, written into the order form.
Assess
For teams that need the evidence layer right now.
Full assurance registry, register-backed verification, explainable risk scoring with contributor breakdown, certificate expiry tracking, contract term extraction, grounded copilot, SSO included.
Operate
For a procurement function running the whole lifecycle.
Everything in Assess, plus parallel intake with configurable approval lanes, the fourth-party dependency graph with hub detection, and renewal automation with category benchmarks.
Regulated
For APRA-regulated entities and critical infrastructure.
Everything in Operate, plus a CPS 234 control-testing evidence chain, a named Australian assurance lead, custom frameworks and internal control libraries, and contractual audit rights extending to your regulator.
Said plainly: some tier features are marked "(in build)" on vendra.com.au — they are on the roadmap and not in the workspace yet, and we would rather say so than let you find out after signing. Data export is complete, machine-readable and self-service: leaving should be easy. Current pricing for each tier is published at vendra.com.au, or talk to us about a deployment scoped to your estate.
Our own posture
We hold ourselves to the registry.
It would be absurd to sell vendor assurance and be vague about our own. Where we are still working toward a certification, we say so with a stage rather than implying we already have it.
ap-southeast-2
Customer data does not leave Australia, and neither does support access.
No training on your data
Figures are computed from your portfolio, not generated. Where a model narrates them, the provider is disclosed on the subprocessor register and changes on notice.
In progress Stage 1 complete
Published honestly, dated, and updated as it lands — not implied.
In progress Observation open
The observation window is open. We will say when it closes, not before.
Subprocessors are published with 30 days notice and a right to object. The portfolio in the live workspace is a demonstration dataset and is entirely fictional — no assurance claim in it refers to a real company.
Two ways in
Look at it before you talk to anyone.
The workspace is open — no form, no gate. When you want it against your own portfolio, that is a conversation with us.
Product site: vendra.com.au