GIPR Technologies · The assessment
Send what you already export. Find out what is in it.
Fixed fee, agreed before we start.
There is no install, no API credentials, no integration work and nothing to migrate. You send an export of data you already have; we run it and show you what the systems disagree about, where controls did not hold, and how each number was arrived at. This page tells you exactly what that involves before you ask for a price.
01 — What you send
Three exports and a period. That is the setup.
Spreadsheets or CSVs, in whatever layout your system produces — sent once, or delivered automatically on a feed if you would rather not repeat it. We map them; you confirm the mapping once. Column names do not need to match anything, and you do not need to clean the data first — the state it is in is part of what we are looking at.
An accounts-payable extract
Invoices and payments for the period, with whatever supplier, purchase-order, department and date fields your export carries. A single file or a zipped bundle.
A card feed
Your P-card, ghost-card or virtual-card transactions for the same period. This is the half that most reviews never see beside the other one.
A purchase-order extract
Commitments for the same period, with whatever supplier, line, amount and date fields your export carries. Eleven of the nineteen checks read purchase orders — without them, those checks stay locked and say so rather than returning a zero.
A vendor master
From a second system if one exists — an eProcurement suite, a CLM, anything that also describes your suppliers. Two systems describing the same supplier is what makes disagreement visible at all.
Contracts, and an approval log
A contract register unlocks contract-coverage analysis. An approval log unlocks the approval checks — without it those rules stay locked and say so rather than returning a zero.
A period of twelve months is usually right. Long enough for the patterns to be real, short enough that the export is something a person can produce in an afternoon. If your fiscal year is the natural boundary, use it.
02 — What comes back
Findings with their working shown.
Three kinds of number, kept apart
What the run found and traced to records on both sides; what it flags as exposure, where a control did not hold; and what it models as an opportunity range. They are reported separately and never blended into a single headline, and a test in our build fails if one is ever absorbed into another.
The method on every row
Each finding prints the method that produced it, in a form a person can recompute by hand against your own records. Nothing asks you to take a number on faith, and nothing is presented as a conclusion you should act on without checking.
Where your systems disagree
Every field where two of your sources describe the same record differently, with both values kept, and any finding whose figures rest on a contested value flagged as such.
What could not be checked, and why
Rules that could not run on your data stay locked and name the specific coverage, volume or field they needed — rather than returning a zero that reads like a clean result. The same report lists what would unlock further analysis.
A record your auditor can verify without us
Every observation that crossed our ingestion boundary is content-hashed, logged and attested to its source in an append-only record. Your auditor verifies it offline with one script — no database, no network, no trust in us.
03 — What it costs, and how it is priced
Fixed fee. Agreed before we start.
One fixed fee
Priced from the scope — how many sources, roughly what volume, and what period. You see the number before anything begins, and it does not move because of what we find.
Credited if you continue
If the assessment leads to a subsequent engagement, the fee is credited against it. The assessment is meant to be the cheapest way to find out whether there is anything here.
Scope and duration are set in the order form, before the work starts — the delivery window is written down and agreed rather than left open. Ask us and we will price your scope; we would rather quote your actual estate than publish a number that turns out not to apply to it.
04 — What happens to your file
The question your security office will ask first.
It never touches your systems
Nothing is installed in your estate, no API credentials are issued, and no agent runs on your network. The data arrives as a file you send. GIPR Core performs no write into any source system — it produces findings, an evidence record and a verdict, and what you do with them is your decision.
When it is over, it is gone
At the end we destroy the encryption and signing keys first, so every record sealed under them becomes permanently unreadable — including any copy that exists inside a backup. Then the graph and the files you sent are deleted. The guarantee is key destruction over encrypted-at-rest data, not an overwrite we cannot verify on modern storage. You get an erasure report naming what was destroyed, what remains, and why.
Paper first, if you prefer. A mutual NDA before you send anything is normal and we will sign one. Our security documentation, shared-responsibility matrix and data-processing terms are available on request — and we will complete whatever questionnaire your organization uses, including the rows where the honest answer is “not yet.”
Next — Scope it
Tell us what you can export. We will price it.
Which systems, roughly what volume, and what period. That is enough for us to come back with a fee and a delivery window.
Scope an assessmentOr write to us: hello@giprtechnologies.com