Home › Platform
Platform

One engine that turns documents into reviewable findings.

Leapfacto reads the documents, ties every data point to its source and proposes an assessment. Your team decides. This page shows how the engine is built; the interface and the eight views shown here are the planned state, not a customer project.

Process

Document in, scored proposal out, approval stays with you

Four steps. The system does the groundwork, your team assesses and decides.

1 · Upload the documents

You upload your vendor's documents: questionnaires, certificates, audit reports, contracts.

2 · Extraction

Leapfacto reads the documents and pulls out the facts that matter for the assessment. Every fact stays linked to its source.

3 · Scored proposal

The system proposes a score and shows which passage supports it.

4 · Review and approval

Your team checks, corrects and approves. Only the approval makes the assessment valid.

Architecture

What happens between your documents and your decision

The path from file to reviewable finding: read, evidenced, proposed. What the system is meant to do is defined. What it is not meant to do is stated below the diagram.

Schematic of the planned setup.

Your documents
SOC2 report Security questionnaire Certificates Contract and DPA Policy documents
upload only, no access to your systems
Leapfacto harness
Extraction with source reference
Scored proposal with confidence
Control loop until every item is sourced
Gaps are flagged, not filled
Evidence archive
every source stays retrievable
↑ access, not training
Your decision
Review and approve Correct Report export Decision log
only the approval makes the assessment valid
No automated verdictAssessments are submitted, not imposed. Approval stays with a person.
No write accessThe system reads the uploaded documents. It does not touch your systems.
No model trainingYour content is not used for training. Processing takes place in the EU.
Views

Eight views. From the portfolio down to the source.

Jump to the role that matters to you, or scroll through. The views show the planned interface, not live data from a customer project.

Figures and names in the views are examples, not customer data.

Your role:
01

Your vendor portfolio at a glance.

One view of the open state: running assessments, overdue reviews and what needs a decision this week.

  • Counters for open and critical vendors
  • Distribution of scores across the portfolio
  • Upcoming review dates with status

Input: your vendor list · System: bundles scores and deadlines · Person: sets the priority

02

Every document becomes a file, not a pile.

You upload the documents for one vendor. Leapfacto reads them and keeps every item it finds together with its source, so you do not have to search.

  • Document list with the status of each file
  • Items found with a reference to page and section
  • What is missing is flagged as a gap

Input: questionnaire, certificates, contract · System: extracts and links every item · Person: sees what is missing

03

The finding sits next to its source.

An assessment here is not an assertion. For every finding, Leapfacto shows the passage it came from and how certain the reading is.

  • Finding in plain language, not rule code
  • Source with document, section and page
  • Confidence visible next to the proposal

Input: the document as read · System: proposes a score with its source · Person: checks the passage

04

Review, correct, approve.

Open findings sit in a list, not in an inbox. You confirm, correct or discard, and only the approval makes the assessment valid.

  • One queue for all open findings
  • Confirm, correct or dismiss per finding
  • Every correction stays traceable

Input: scored proposal · System: puts findings up for review · Person: decides per finding

05

Deadlines in view before they bite.

Certificates expire, contracts are renewed, vendors change their subcontractors. The vendor file records when the next review falls due.

  • Last and next review per vendor
  • Expiry dates of the evidence on file
  • Due reviews as a list, not as a calendar reminder

Input: contract and certificate data · System: computes review dates · Person: decides what to bring forward

06

Every decision with an author.

In an audit it is not enough that a review happened. What counts is who decided what, when, and what it rests on. The log is written while you work, not afterwards.

  • Who, when, what and on what basis
  • Reference to the document the decision rests on
  • Exportable as a list for the review

Input: approvals from the review · System: keeps the log going · Person: owns the decision

07

Under the hood: the harness.

A language model on its own does not answer an audit question. The work sits in the layer around it, the harness: fixed instructions, defined tools, a review loop and rules that set the frame.

  • Prompt management: fixed instructions and context per review job
  • Tool connection: read, compare, map the source
  • Control loop: checks again until every item is sourced
  • Error handling and guardrails: gaps and contradictions are flagged

Input: a review job · System: runs the loop under fixed rules · Person: receives a proposal with sources

08

The data path, laid open.

Before your IT agrees, the path of the data counts: upload, processing, storage and deletion. These four points are agreed in writing before a pilot starts.

  • Access only to the documents you upload
  • Processing in the EU, no model training on your content
  • No write access to your systems

Input: your approval to upload · System: processes and stores where you set it · Person: defines retention and access

FAQ

Common questions

Do I have to install anything?

No. You upload the documents into the application. Leapfacto does not access your systems; there is no write access and no agent running on your side.

What happens when a data point is missing?

It is reported as a gap, not estimated. The finding stays open until a person assesses it. The system does not fill gaps with probabilities.

How do I know how solid a proposal is?

Every proposal comes with the passage it is based on and a confidence value. You check the evidence, not just the result.

Which risk domains is the engine built for?

The engine is domain neutral: read documents, cite data points, propose an assessment, obtain approval. There is no interface available outside vendor risk today; it follows once a second domain runs in a pilot.

Contact

See the engine on your own documents.

One appointment, your documents, one run with sources. After that you know what the system recognises and where its limits are.

Book a demo →
Or email us: info@leaplytics.de
First call is non-binding, remote or on site.