Hatchify

Our first product

Prove every vendor holds what they claim.

Vendra is Hatchify's first product: procurement intelligence and vendor assurance built for Australian enterprises that answer to APRA, the OAIC and the ACSC. It verifies vendor evidence against the register that issued it, maps the fourth parties sitting underneath your suppliers, and runs security, legal, privacy and finance review in parallel instead of in a queue.

Built in Australia. Hosted in Australia. Supported from Sydney.

No form, no sales call — the workspace runs a demonstration portfolio through the live scoring engine

Why we built it

It came out of the work.

A decade of putting AI and cloud into production inside regulated Australian businesses taught us where those projects actually die. Not in the build — in the review. Six approval lanes, each waiting on the last, and a stack of PDFs nobody checked against the register that issued them.

Vendra is what we built to fix that, and it is held to the standard we hold client work to: every risk score explains itself, every regulatory citation records the instrument it was verified against, and the things we have not finished are labelled as unfinished.

It is the Compliance & Governance practice turned into a product, and it is what the Govern stage of the Hatchify Flightpath looks like when you run it every day instead of once per engagement.

Why this makes the consultancy more credible, not less

When we tell a client we can put governed AI into production — with evals, audit trails and a regulator-ready evidence chain — Vendra is the thing we can point at. It runs in production, against the same regulation our clients answer to, and you can open it yourself without asking us.

32standards and statutory obligations verified
163reviewer checks across them
6modules on one evidence base

What it does

Six modules. One evidence base.

These are usually bought as separate tools and stitched together afterwards. Vendra scores, routes and negotiates off the same verified evidence, so nothing has to be re-established at the next stage.

The core

Assurance verification

Where a public register exists — a certification body register, the FedRAMP Marketplace, the CSA STAR registry, the Australian Business Register, the Modern Slavery Statements Register — Vendra checks the claim against it rather than accepting the PDF. Where no register exists, it says so and scores the confidence down.

  • Verification method shown on every record
  • Scope statement parsed and surfaced
  • Confidence scored, never implied
Rarely done well

Fourth-party graph

Your vendors have vendors. Vendra builds the dependency graph and finds the hubs — the storage provider sitting beneath six of your suppliers, the offshore support desk that appeared without notice, the subprocessor with no data agreement.

  • Shared-dependency detection
  • Subprocessor change monitoring
  • CPS 230 material fourth parties

Parallel intake

One front door. Security, legal, privacy, finance and architecture all open at once rather than queuing behind each other, each with its own SLA clock. Low-risk purchases auto-clear on evidence Vendra already holds.

  • Concurrent approval lanes, not a relay
  • Risk-tiered routing from intake answers
  • Full audit trail per lane

Contract intelligence

Extracts the terms that decide your exposure — liability caps and their carve-outs, notice windows, uplift ceilings, audit rights, data deletion, AI clauses — and flags where they fall short of your policy or your regulator.

  • Clause-level risk flags with the reasoning
  • Notice-window countdown before auto-renewal
  • Liability tested against data at risk

Renewals and benchmarks

Every renewal opens automatically ahead of its notice deadline with utilisation data and a market position attached, so the conversation starts with evidence rather than a list price.

  • Notice deadlines, not just end dates
  • Seat utilisation over 90 days
  • Category price benchmarks

Grounded copilot

Ask a question in plain English and get an answer computed from your portfolio, with the underlying records attached. Figures are computed, not generated; where a language model is used it narrates those computed facts and is instructed not to introduce anything absent from them.

  • Answers cite the records they used
  • Runs against live scoring

Australia, properly

The obligations that actually apply here.

Australian regulation tends to show up in global platforms as a compliance-pack line item, if at all. Vendra was built here, for entities that answer to APRA, the OAIC, the ACSC and the Cyber and Infrastructure Security Centre — with the clause references in the product, each one recorded against the instrument it was verified from.

APRA CPS 230

Material service provider register submitted to APRA annually, due diligence and a documented selection process before engagement, and mandated contract provisions including APRA access rights and executable exit plans.

Operational Risk Management

APRA CPS 234

Third-party control design evaluated, not just certified. Contractual incident notification tight enough to meet your own 72-hour APRA obligation, with a route to hear about material control weaknesses inside 10 business days.

Information Security

ASD Essential Eight

A maturity level per strategy, scored 0 to 3, with self-assessment clearly separated from independent assessment. A single overall claim tells you nothing.

ASD Maturity Model

IRAP

Classification level, in-scope services and regions, assessor endorsement, and the residual risk register — because IRAP documents risk, it does not remove it.

ISM Assessment

Australian Privacy Principles

APP 8 accountability for overseas recipients and APP 11 security steps, with storage location and staff access location tracked as the separate questions they are.

Privacy Act 1988

Notifiable Data Breaches

A 30-day assessment window that starts when you become aware. Vendra pushes for notification of suspicion within 24 hours, not "without undue delay".

NDB Scheme · OAIC

Modern Slavery

Statements checked against the public register, with the six-month lodgement deadline tracked and overdue suppliers flagged before they land in your own statement.

Modern Slavery Act 2018 (Cth)

SOCI Act

Supply chain hazards mapped into your risk management programme across all four hazard categories, with contracts that support 12 and 72-hour reporting.

Critical Infrastructure

Vendra is not a law firm and does not provide legal advice; the regulatory detail in the registry is a procurement aid, not a legal opinion.

How Hatchify supports it

Australian-owned, and in the room.

Hatchify Pty Ltd has been building for regulated Australian businesses since 2014. Vendra is deployed and supported by the same senior engineers who build our clients' platforms — not a separate support organisation.

Sydney-based, on the ground in Melbourne

We work from Sydney and our engineers are regularly in Melbourne — for the workshop, the architecture review and the conversation with your regulator. Your timezone, and in the room when it matters.

Senior engineers only

No offshore delivery pods and no juniors learning on your engagement. The people who scope your deployment are the people who deliver it.

Onshore by construction

Vendra runs in ap-southeast-2. Customer data does not leave Australia, and neither does support access. No customer data is used to train any model. Subprocessors are published, with 30 days notice and a right to object.

Australian-owned

Hatchify Pty Ltd, ABN 87 600 809 167, established 2014. An AWS Partner Network member, Australian-owned and Australian-operated.

We live in the same regulation

Our consulting clients are in wagering, insurance and financial services. The obligations Vendra tracks are the ones we already build against every day.

Deployment and integration

Identity, data migration and integration into your existing procurement and ticketing stack, delivered as a Hatchify engagement on the Flightpath.

How it is packaged

Three tiers, scoped to your estate.

Annual subscription in Australian dollars, with no percentage of managed spend, no per-request metering, and no charging extra for single sign-on — it is a security control, not a feature. Uplift is capped at CPI for the first three years, written into the order form.

Tier one

Assess

For teams that need the evidence layer right now.

Up to 75vendors under management

Full assurance registry, register-backed verification, explainable risk scoring with contributor breakdown, certificate expiry tracking, contract term extraction, grounded copilot, SSO included.

Tier three

Regulated

For APRA-regulated entities and critical infrastructure.

Unlimitedvendors · scoped to your estate

Everything in Operate, plus a CPS 234 control-testing evidence chain, a named Australian assurance lead, custom frameworks and internal control libraries, and contractual audit rights extending to your regulator.

Said plainly: some tier features are marked "(in build)" on vendra.com.au — they are on the roadmap and not in the workspace yet, and we would rather say so than let you find out after signing. Data export is complete, machine-readable and self-service: leaving should be easy. Current pricing for each tier is published at vendra.com.au, or talk to us about a deployment scoped to your estate.

Our own posture

We hold ourselves to the registry.

It would be absurd to sell vendor assurance and be vague about our own. Where we are still working toward a certification, we say so with a stage rather than implying we already have it.

RESIDENCY

ap-southeast-2

Customer data does not leave Australia, and neither does support access.

AI PROCESSING

No training on your data

Figures are computed from your portfolio, not generated. Where a model narrates them, the provider is disclosed on the subprocessor register and changes on notice.

ISO 27001

In progress Stage 1 complete

Published honestly, dated, and updated as it lands — not implied.

SOC 2 TYPE II

In progress Observation open

The observation window is open. We will say when it closes, not before.

Subprocessors are published with 30 days notice and a right to object. The portfolio in the live workspace is a demonstration dataset and is entirely fictional — no assurance claim in it refers to a real company.

Two ways in

Look at it before you talk to anyone.

The workspace is open — no form, no gate. When you want it against your own portfolio, that is a conversation with us.

Product site: vendra.com.au