Skip to content

Latest commit

 

History

History
651 lines (570 loc) · 99.6 KB

File metadata and controls

651 lines (570 loc) · 99.6 KB

Hack23 Logo

🔗 Hack23 AB — Supplier Security Posture

Third-Party Risk Management Through Comprehensive Assessment
Demonstrating Supply Chain Security Excellence

Owner Version Effective Date Review Cycle

📋 Document Owner: CEO | 📄 Version: 1.3 | 📅 Last Updated: 2026-01-25 (UTC)
🔄 Review Cycle: Quarterly | ⏰ Next Review: 2026-04-25


🎯 Purpose Statement

This document provides comprehensive security posture assessment of all critical suppliers to Hack23 AB, demonstrating our commitment to supply chain security excellence. All active suppliers from our Asset Register are assessed and monitored.


🏢 Hack23 Supplier Management & Strategic Assessment

See governance process: Third Party Management

📊 **Supplier Classification Matrix

Document Owner: CEO | Last Updated: 2026-01-25 09:00:00 UTC | Total Monthly Spend: $360 | Active Suppliers: 12 | Planned: 2


Supplier Services & Processes Status & Cost Porter's Five Forces Security Classification Business Continuity Business Impact Strategic Value
🔴 AWS Cloud Infrastructure
Lambda
API Gateway
DynamoDB
S3
CloudFront
WorkMail
Website Hosting

Processes:
Operations
Marketing
Sales
Active
$50/month
Pay-as-you-go
3+ years
Buyer Power: Minimal
Supplier Power: Extreme
Entry Barriers: Insurmountable
Substitute Threat: Minimal
Rivalry: Dominant
Confidentiality: Extreme
Integrity: Critical
Availability: Mission Critical
ISO 27001
SOC 2
PCI DSS
GDPR
RTO: Instant
RPO: Zero Loss
SLA: 99.99%
Support: 24/7
Lock-in: Very High
Switch Cost: $50K+
Switch Time: 3-6mo
Financial: >$10K/day
Operational: Critical
Reputational: High
Regulatory: High
ROI: Exceptional
Position: Market Leader
Type: Infrastructure
Alternatives: 2-3
Risk: Critical
🟠 GitHub Version Control
Copilot AI
Actions CI/CD
Codespaces
Security
Packages
Projects
Documentation

Processes:
Operations
Executive
Active
$50-200/mo
Annual
2+ years
Buyer Power: Reduced
Supplier Power: High
Entry Barriers: Very High
Substitute Threat: Low
Rivalry: Dominant
Confidentiality: Very High
Integrity: Critical
Availability: High
SOC 2
ISO 27001
SLSA 3
RTO: Critical
RPO: Near RT
SLA: 99.9%
Support: Business
Lock-in: High
Switch Cost: $20K+
Switch Time: 1-2mo
Financial: $1-5K/day
Operational: High
Reputational: Moderate
Regulatory: Moderate
ROI: High
Position: Market Leader
Type: Dev Tools
Alternatives: 3-4
Risk: High
🟠 SEB Banking
SEPA
Wire
Payroll
Cards
Mobile

Processes:
Finance
HR
Legal
Active
$15/month
Ongoing
5+ years
Buyer Power: Moderate
Supplier Power: High
Entry Barriers: Very High
Substitute Threat: Low
Rivalry: Parity
Confidentiality: Very High
Integrity: Critical
Availability: High
PSD2
FSA
SWIFT
RTO: High
RPO: Minimal
SLA: 99.5%
Support: 24/7
Lock-in: High
Switch Cost: $5K
Switch Time: 1mo
Financial: $5-10K/day
Operational: Critical
Reputational: High
Regulatory: Very High
ROI: High
Position: Premium
Type: Banking
Alternatives: 3-4
Risk: High
🟡 Bokio Accounting
Bookkeeping
VAT
Tax
Invoicing
Receipts

Processes:
Finance
Legal
Active
$55/month
Annual
1+ year
Buyer Power: Moderate
Supplier Power: Moderate
Entry Barriers: Moderate
Substitute Threat: Moderate
Rivalry: Parity
Confidentiality: High
Integrity: High
Availability: Moderate
GAAP
K2/K3
GDPR
RTO: Medium
RPO: Hourly
SLA: 99%
Support: Business
Lock-in: Low
Switch Cost: $1K
Switch Time: 1wk
Financial: $1-5K/day
Operational: Moderate
Reputational: Low
Regulatory: High
ROI: Moderate
Position: Competitive
Type: Accounting
Alternatives: 5+
Risk: Medium
🟠 Google Identity Provider
OAuth2/OIDC
Search Console
Workspace

Processes:
Operations
Marketing
Active
Free
Free Tier
5+ years
Buyer Power: Reduced
Supplier Power: High
Entry Barriers: Very High
Substitute Threat: Low
Rivalry: Dominant
Confidentiality: High
Integrity: High
Availability: High
ISO 27001
SOC 2
RTO: Critical
RPO: Near RT
SLA: 99.9%
Support: Community
Lock-in: Medium
Switch Cost: $5K
Switch Time: 2wk
Financial: $1-5K/day
Operational: High
Reputational: Moderate
Regulatory: Moderate
ROI: High
Position: Market Leader
Type: Identity
Alternatives: 3-4
Risk: High
🟡 SonarSource Static Analysis
Code Quality
Security Scanning
Technical Debt

Processes:
Operations
Active
Free
Free Tier
2+ years
Buyer Power: High
Supplier Power: Reduced
Entry Barriers: Moderate
Substitute Threat: High
Rivalry: Parity
Confidentiality: Moderate
Integrity: Moderate
Availability: Standard
SOC 2
RTO: Medium
RPO: Daily
SLA: Best Effort
Support: Community
Lock-in: Very Low
Switch Cost: $500
Switch Time: 1day
Financial: <$500/day
Operational: Low
Reputational: Low
Regulatory: Low
ROI: Moderate
Position: Competitive
Type: DevSecOps
Alternatives: 5+
Risk: Low
🟢 StepSecurity Workflow Security
Supply Chain
SLSA
Active
Cost
Contract
Low Power
Market Share
Lock-in
Medium
SOC2
GitHub
RTO
RPO
SLA
Impact
Criticality
Value
Innovation
🟡 FOSSA License Compliance
OSS Analysis
Vulnerability Scanning
SBOM Generation

Processes:
Operations
Active
Free
Free Tier
1+ year
Buyer Power: High
Supplier Power: Reduced
Entry Barriers: Moderate
Substitute Threat: High
Rivalry: Parity
Confidentiality: Moderate
Integrity: Moderate
Availability: Standard
SOC 2
RTO: Medium
RPO: Daily
SLA: Best Effort
Support: Community
Lock-in: Very Low
Switch Cost: $500
Switch Time: 1day
Financial: <$500/day
Operational: Low
Reputational: Low
Regulatory: Moderate
ROI: Moderate
Position: Competitive
Type: Compliance
Alternatives: 3-4
Risk: Low
⏳ OpenAI GPT-4
DALL-E
Sora
Embeddings
Assistants

Processes:
Operations
Marketing
Planned
On-demand
Pay-per-use
Evaluation
Buyer Power: Reduced
Supplier Power: High
Entry Barriers: Very High
Substitute Threat: Moderate
Rivalry: Strong
Confidentiality: High
Integrity: High
Availability: Moderate
SOC 2
RTO: Medium
RPO: Hourly
SLA: Best Effort
Support: Self-service
Lock-in: Low
Switch Cost: $2K
Switch Time: 1wk
Financial: $500-1K/day
Operational: Moderate
Reputational: Low
Regulatory: Low
ROI: Moderate
Position: Market Leader
Type: AI/Analytics
Alternatives: 5+
Risk: Medium
🟢 Suno AI Music
Soundtracks
Marketing
Background
Credits

Processes:
Marketing
Active
$25/month
Monthly
6 months
Buyer Power: High
Supplier Power: Reduced
Entry Barriers: Moderate
Substitute Threat: High
Rivalry: Disadvantage
Confidentiality: Low
Integrity: Moderate
Availability: Standard
Terms
RTO: Low
RPO: Daily
SLA: None
Support: Community
Lock-in: Very Low
Switch Cost: $500
Switch Time: 1day
Financial: Negligible
Operational: Low
Reputational: Negligible
Regulatory: Negligible
ROI: Minimal
Position: Follower
Type: Content
Alternatives: 10+
Risk: Low
🟢 ElevenLabs Voice AI
Voice Clone
SFX
Languages
Characters

Processes:
Marketing
Active
$25/month
Monthly
4 months
Buyer Power: High
Supplier Power: Reduced
Entry Barriers: Moderate
Substitute Threat: High
Rivalry: Disadvantage
Confidentiality: Low
Integrity: Moderate
Availability: Standard
Terms
RTO: Low
RPO: Daily
SLA: None
Support: Community
Lock-in: Very Low
Switch Cost: $500
Switch Time: 1day
Financial: Negligible
Operational: Low
Reputational: Negligible
Regulatory: Negligible
ROI: Minimal
Position: Follower
Type: Content
Alternatives: 10+
Risk: Low
🟡 Ludo.ai (Jet Play, Inc.) AI
Sprites
Concept

Processes:
Development
Innovation
Active
Cost: SaaS
Billing: Subscription
Duration: Ongoing
Buyer Power: Medium
Supplier Power: Medium
Entry Barriers: Low
Substitute Threat: High
Rivalry: Strong
Confidentiality: Medium
Integrity: Medium
Availability: High
RTO: 24-72h
RPO: Daily
SLA: Best Effort
Support: Email+Community
Lock-in: Low
Financial: <$1k/month
Operational: Medium
Reputational: Low
Regulatory: Low
ROI: High
Position: Supplier
Type: Development
Alternatives: 5+
Risk: Medium
⏳ Stripe Payments
Subscriptions
Invoicing
Global
Fraud
Radar

Processes:
Sales
Finance
Operations
Active
Usage-based
Usage-based
Operational
Buyer Power: Minimal
Supplier Power: High
Entry Barriers: Very High
Substitute Threat: Low
Rivalry: Strong
Confidentiality: Very High
Integrity: Critical
Availability: Mission Critical
PCI DSS
SOC 2
ISO 27001
RTO: Instant
RPO: Zero Loss
SLA: 99.99%
Support: 24/7
Lock-in: High
Switch Cost: $10K
Switch Time: 2-4wk
Financial: >$10K/day
Operational: Critical
Reputational: High
Regulatory: Critical
ROI: Exceptional
Position: Market Leader
Type: Payment
Alternatives: 3-4
Risk: Critical
🟢 Trygg Hansa Insurance: Cyber liability • Key person • Business interruption

Processes:
Legal
Executive
Active
Cost: Policy
Annual
Duration: Active
Buyer Power: Moderate
Supplier Power: High
Entry Barriers: High
Substitute Threat: Low
Rivalry: Parity
Confidentiality: High
Integrity: High
Availability: High
ISO 27001
RTO: Medium
RPO: Hourly
SLA: Policy Terms
Support: Business
Lock-in: Annual
Financial: $1-5K/day
Operational: Low
Reputational: Low
Regulatory: High
ROI: Moderate
Position: Established
Type: Insurance
Alternatives: 3-4

📈 Supplier Comparative Analysis Table

Criteria AWS GitHub SEB Bokio Google SonarSource FOSSA StepSecurity Suno ElevenLabs Ludo.ai Trygg Hansa OpenAI Stripe
Criticality 🔴 Critical 🟠 High 🟠 High 🟡 Medium 🟠 High 🟡 Medium 🟡 Medium 🟡 Medium 🟢 Low 🟢 Low 🟡 Medium 🟠 High 🟡 Medium 🔴 Critical
Monthly Cost $50 $125 $15 $55 Free Free Free Free $25 $25 ~$30 ~$35 Planned Planned
Contract Type Pay-as-go Annual Ongoing Annual Free Tier OSS Free OSS Free OSS Free Monthly Monthly Monthly Annual Usage Usage
Lock-in Risk ⚠️ Very High ⚠️ High ⚠️ High ✅ Low ⚠️ Medium ✅ None ✅ None ✅ None ✅ Very Low ✅ Very Low ✅ Low ⚠️ Annual ✅ Low ⚠️ High
Alternative Options 2-3 viable 3-4 viable 3-4 viable 5+ viable 3-4 viable 5+ viable 3-4 viable 3-4 viable 10+ viable 10+ viable 5+ viable 3-4 viable 5+ viable 2-3 viable
Switching Cost $50K+ $20K+ $5K $1K $5K $0 $0 $0 $500 $500 $500 €1K $2K $10K
Switching Time 3-6 months 1-2 months 1 month 1 week 2 weeks Instant Instant Instant 1 day 1 day 1 day 2 weeks 1 week 2-4 weeks
SLA Guarantee 99.99% 99.9% 99.5% 99% 99.9% Best effort Best effort Best effort None None Best effort Policy terms Best effort 99.99%
Compliance Level ✅ Full ✅ Full ✅ Full ✅ Full ✅ Full ⚠️ Partial ⚠️ Partial ⚠️ Partial ❌ Basic ❌ Basic ❌ Basic ✅ Full ⚠️ Partial ✅ Full
Support Level 24/7 Business 24/7 Business Community Community Community Community Community Community Email Business Self-service 24/7
Strategic Value Exceptional High High Moderate High High High High Minimal Minimal Moderate Moderate Moderate Exceptional

🎯 Strategic Classification

mindmap
  root((🎯 Supplier Tiers))
    Tier 1 Mission Critical
      AWS
        RTO under 5 min
        RPO under 1 min
        99.99 pct SLA
        No viable alternative
        10K+ daily impact
      Stripe
        RTO under 5 min
        RPO under 1 min
        99.99 pct SLA
        Payment critical
        10K+ daily impact
    Tier 2 Business Essential
      GitHub
        RTO under 60 min
        RPO under 15 min
        99.9 pct SLA
        High switching cost
        5K+ daily impact
      SEB
        RTO under 4 hours
        RPO under 60 min
        Payment processing
        Payroll critical
        5 to 10K daily impact
    Tier 3 Operational Support
      Bokio
        RTO under 24 hours
        RPO under 4 hours
        Tax compliance critical
        Swedish regulations
        1 to 5K daily impact
      OpenAI
        RTO under 24 hours
        RPO under 4 hours
        Innovation driver
        Competitive advantage
        500 to 1K daily impact
      SonarSource
        RTO under 24 hours
        RPO under 4 hours
        Code quality assurance
        Security compliance
        500 daily impact
      FOSSA
        RTO under 24 hours
        RPO under 4 hours
        License compliance
        Legal risk mitigation
        500 daily impact
      StepSecurity
        RTO under 24 hours
        RPO under 12 hours
        Supply chain security
        CI and CD hardening
        100 daily impact
    Tier 4 Supporting Services
      Google Identity
        RTO under 60 min
        RPO under 15 min
        99.9 pct SLA
        Identity provider
        1 to 5K daily impact
      Trygg Hansa
        RTO under 24 hours
        RPO under 4 hours
        Policy terms SLA
        Insurance coverage
        1 to 5K daily impact
      Ludo.ai
        RTO 24 to 72 hours
        RPO 24 hours
        Game design AI
        Multiple alternatives
        Low impact
      Suno
        RTO 24 to 72 hours
        RPO 24 hours
        Content generation
        Easy replacement
        Minimal impact
      ElevenLabs
        RTO 24 to 72 hours
        RPO 24 hours
        Audio production
        Multiple alternatives
        Minimal impact
Loading

🔒 Security & Compliance

mindmap
  root((🔒 Security Posture))
    Enterprise Grade
      AWS
        ISO 27001 27017 27018
        SOC 1 2 3
        PCI DSS Level 1
        HIPAA HITECH
        FedRAMP High
        GDPR CCPA
        Multi region DR
        99.99 pct SLA
      GitHub
        SOC 2 Type II
        ISO 27001
        SLSA Level 3
        2FA SSO SAML
        IP allowlisting
        Audit logging
        Secret scanning
        SAST DAST tools
    Financial Compliance
      SEB Banking
        PSD2 compliant
        Swedish FSA
        SWIFT network
        AML KYC verified
        FATCA reporting
        Strong Customer Auth
      Stripe
        PCI DSS Level 1
        SOC 2 Type II
        3D Secure 2.0
        SCA ready
        Token vault
        Fraud detection
    Regulatory Compliance
      Bokio Accounting
        Swedish GAAP
        K2 K3 regelverket
        Skatteverket integration
        GDPR compliant
        Data residency Sweden
        Audit trail complete
    Security Tooling
      SonarSource
        SOC 2 Type II
        GDPR compliant
        SAST DAST tools
        Code quality gates
        Security hotspots
      FOSSA
        SOC 2 Type II
        GDPR compliant
        License compliance
        Vulnerability scanning
        Supply chain analysis
      StepSecurity
        GitHub native security
        SLSA compliance
        Workflow hardening
        Supply chain protection
        Open source transparency
    Insurance and Risk Transfer
      Trygg Hansa
        ISO 27001 aligned
        Swedish FSA regulated
        Cyber liability coverage
        Key person insurance
        Business interruption
    Basic Security
      Suno and ElevenLabs
        Terms of service
        IP protection
        Commercial license
        API security
      OpenAI
        SOC 2 Type II
        Data policies
        API security
        Rate limiting
      Ludo.ai
        Terms of service
        SaaS security
        API security
        Limited compliance
      Google Identity
        ISO 27001 SOC 2
        OAuth2 OIDC
        Strong authentication
        Data protection
Loading

📊 Porter's Five Forces Analysis

mindmap
  root((📊 Market Forces))
    🔴 Extreme Supplier Power
      AWS
        Market dominance 33 pct
        Massive infrastructure
        High switching costs
        Technical lock in
        Proprietary services
        Network effects
      GitHub
        90 pct market share
        Microsoft backing
        Developer ecosystem
        Integration depth
        Community network
    🟠 High Supplier Power
      SEB Banking
        Swedish oligopoly
        Regulatory barriers
        Relationship banking
        Limited alternatives
        High switching friction
      Stripe
        Market leadership
        Developer friendly
        Global coverage
        Feature richness
        API excellence
      Google Identity
        Market dominance
        SSO integration
        Free tier strategy
        Data network effects
    🟡 Moderate Power Balance
      Bokio Accounting
        Competitive market
        Multiple alternatives
        Standard features
        Price competition
        Easy data export
      OpenAI
        First mover advantage
        But growing competition
        API standardization
        Price pressure
      Trygg Hansa
        Limited Swedish insurers
        Regulatory requirements
        Risk assessment
        Claims history
    🟢 Buyer Advantage
      SonarSource
        Free for OSS projects
        Competitive market
        Open source alternatives
        Multiple providers
        Easy switching
      FOSSA
        Free for OSS projects
        Growing competition
        Standard APIs
        Alternative tools
        Low lock in
      StepSecurity
        Free for OSS projects
        Emerging market
        GitHub native
        Easy replacement
        No lock in
      Suno Music
        Commoditized service
        Many competitors
        Low switching costs
        Standard outputs
        Monthly contracts
      ElevenLabs Voice
        Growing competition
        Improving alternatives
        API compatibility
        Price wars starting
        Feature parity
      Social Media Platforms
        Multiple free options
        Easy multi platform
        No lock in
        Content portability
      Analytics Tools
        Free alternatives
        Data exportability
        Standard metrics
        Multiple providers
Loading


📈 Risk & Dependency Matrix

mindmap
  root((⚠️ Risk Assessment))
    🔴 Critical Risks
      AWS Outage
        Full service stop
        Data unavailable
        Recovery Multi region
      GitHub Breach
        Code exposure
        CICD failure
        Recovery Local backup
    🟠 High Risks
      Bokio Failure
        Tax non compliance
        Financial penalties
        Recovery Manual backup
      SEB Issues
        Payment delays
        Cash flow impact
        Recovery Alt account
    🟡 Medium Risks
      Cost Overrun
        AWS usage spike
        GitHub seats
        Mitigation Alerts
      Security Tool Outage
        SonarSource down
        FOSSA unavailable
        StepSecurity issues
        Recovery Alternative tools
    🟢 Low Risks
      Suno and ElevenLabs
        Content delays
        Quality issues
        Recovery Alternatives
Loading


📋 Supplier Contract & Commercial Details

Supplier Contract Type Term Annual Value Payment Terms Renewal Date Account Manager
AWS Pay-as-you-go Ongoing ~$600 Monthly invoice N/A AWS Support
GitHub Enterprise Cloud 12 months ~$1,500 Annual prepaid 2026-07-01 GitHub Sales Team
SEB Corporate Banking Ongoing ~$180 fees Monthly Annual review Business Support
Bokio Business Plan 12 months ~$660 Annual 2026-01-01 Customer Success
Google Free Tier Ongoing Free N/A N/A Self-service
Suno Pro Subscription Monthly $300 Monthly card Monthly auto-renew Self-service
ElevenLabs Creator Plan Monthly $300 Monthly card Monthly auto-renew Self-service
Ludo.ai SaaS Subscription Monthly ~$360 Monthly card Monthly auto-renew Self-service
Trygg Hansa Insurance Policy Annual ~$420 Annual premium 2026-12-31 Insurance Agent
OpenAI API Usage Based Pay-as-you-go Planned Monthly usage N/A Self-service
Stripe Platform Agreement Ongoing 2.9% + €0.25/txn Per transaction N/A Partner Team
SonarSource Open Source Plan Ongoing Free N/A N/A Community Support
FOSSA Open Source Plan Ongoing Free N/A N/A Community Support
StepSecurity Open Source Plan Ongoing Free N/A N/A Community Support

📈 Supplier Relationship Matrix

graph LR
    subgraph Strategic["🎯 Strategic Partners"]
        AWS[AWS<br/>Deep Integration]
        GitHub[GitHub<br/>Core Platform]
    end
    
    subgraph Operational["⚙️ Operational Suppliers"]
        SEB[SEB<br/>Banking]
        OpenAI[OpenAI<br/>AI Services]
        Stripe[Stripe<br/>Payments]
    end
    
    subgraph Security["🔒 Security Tools"]
        SonarSource[SonarSource<br/>Code Quality]
        FOSSA[FOSSA<br/>License Compliance]
        StepSecurity[StepSecurity<br/>Workflow Security]
    end
    
    subgraph Tactical["📦 Tactical Vendors"]
        Suno[Suno<br/>Content]
        ElevenLabs[ElevenLabs<br/>Audio]
        Bokio[Bokio<br/>Accounting]
        Ludo.ai[Ludo.ai<br/>Game Design]
    end
    
    subgraph Support["🛡️ Supporting Services"]
        Google[Google<br/>Identity]
        TryggHansa[Trygg Hansa<br/>Insurance]
    end
    
    Strategic -->|Quarterly Reviews| Executive[Executive Sponsor]
    Operational -->|Monthly Reviews| Management[Management Team]
    Security -->|Continuous Monitoring| DevSecOps[DevSecOps Team]
    Tactical -->|As Needed| Operational_Team[Operational Team]
    Support -->|Annual Reviews| Executive
    
    style AWS fill:#FF9800,stroke:#F57C00,stroke-width:2px,color:#ffffff
    style GitHub fill:#455A64,stroke:#455A64,stroke-width:2px,color:#ffffff
    style OpenAI fill:#7B1FA2,stroke:#4A148C,stroke-width:2px,color:#ffffff
    style SonarSource fill:#D32F2F,stroke:#B71C1C,stroke-width:2px,color:#ffffff
    style FOSSA fill:#7B1FA2,stroke:#4A148C,stroke-width:2px,color:#ffffff
    style StepSecurity fill:#4CAF50,stroke:#2E7D32,stroke-width:2px,color:#ffffff
Loading

🔍 Supplier Alternative Analysis

Primary Supplier Alternative Options Switching Cost Switching Time Feasibility
AWS • Google Cloud
• Azure
• Digital Ocean
Very High ($50k+) 3-6 months Low - Major refactoring
GitHub • GitLab
• Bitbucket
• Azure DevOps
High ($20k+) 1-2 months Medium - CI/CD migration
OpenAI • Anthropic Claude
• Google Gemini
• Open source (Llama)
Low ($2k) 1 week High - API compatible
SEB • Swedbank
• Handelsbanken
• Nordea
Medium ($5k) 1 month Medium - Swedish market
Suno • Mubert
• AIVA
• Soundraw
Low ($500) 1 day High - Simple switch
ElevenLabs • Play.ht
• Murf AI
• Resemble AI
Low ($500) 1 day High - Simple switch
Stripe • Klarna Checkout
• PayPal
• Adyen
Medium ($10k) 2-4 weeks Medium - Integration work
Bokio • Fortnox
• Visma
• Björn Lundén
Low ($1k) 1 week High - Data export
SonarSource • CodeClimate
• Veracode
• Checkmarx
None ($0) Instant High - Multiple options
FOSSA • WhiteSource
• Snyk
• Black Duck
None ($0) Instant High - Standard APIs
StepSecurity • Socket Security
• Dependabot
• GitHub Advanced Security
None ($0) Instant High - GitHub native
Ludo.ai • Machinations
• GameMaker AI
• Unity AI tools
Low ($500) 1 day High - Simple switch
Google • Auth0
• Okta
• Azure AD
Medium ($5k) 2 weeks Medium - Identity migration
Trygg Hansa • Länsförsäkringar
• IF Skadeförsäkring
• Folksam
Low (€1k) 2 weeks High - Policy transfer

🔐 Supplier Data Handling Matrix

Supplier Data Types Location Retention Deletion Audit Rights
AWS All company data EU (Ireland/Frankfurt) Per service config On termination Yes - Annual
GitHub Source code, secrets US/EU Indefinite 90 days after deletion Yes - SOC2
OpenAI Prompts, outputs US 30 days On request Limited
SEB Financial records Sweden 7 years Per law Yes - FSA
Suno Generated music US Account lifetime On deletion No
ElevenLabs Voice samples US/EU Account lifetime On deletion No
Stripe Payment data EU 7 years Per PCI Yes - PCI DSS
Bokio Accounting data Sweden 7 years Per law Yes
SonarSource Code analysis data EU/US Project lifetime On deletion Limited
FOSSA License scan data US Project lifetime On deletion Limited
StepSecurity Workflow metadata US 90 days On request Limited
Ludo.ai Game design data, sprites US Account lifetime On deletion No
Google Identity tokens, SSO data US/EU Account lifetime On deletion Yes - SOC2
Trygg Hansa Policy data, claims Sweden 10 years Per law Yes - FSA

📄 Supplier Documentation Links

Supplier Documentation Status Page API Docs Support Portal
AWS docs.aws.amazon.com status.aws.amazon.com API Reference Console
GitHub docs.github.com githubstatus.com API v4 Support
OpenAI platform.openai.com/docs status.openai.com API Reference Help
SEB seb.se/foretag N/A Open Banking Business Support
Stripe stripe.com/docs status.stripe.com API Docs Support
SonarSource docs.sonarcloud.io status.sonarcloud.io Web API Community
FOSSA docs.fossa.com status.fossa.com API Docs Support
StepSecurity docs.stepsecurity.io status.stepsecurity.io API Reference Support

📈 Porter's Five Forces Analysis Summary

🏪 Supplier Power Assessment

Supplier Power Level Risk Mitigation Strategy Hack23-Specific Actions
AWS High Multi-cloud strategy consideration, regular contract negotiations, maintain exit plan Leverage AWS credits for startups, implement CloudFormation IaC for portability
GitHub Moderate Maintain local backups, consider GitLab as secondary option Utilize GitHub Enterprise features, maintain self-hosted runners
Suno Reduced Multiple alternative AI music platforms available Create proprietary music library as backup, explore Mubert/AIVA alternatives
ElevenLabs Reduced Multiple alternative voice synthesis providers available Build sound effect library, consider PlayHT/Resemble AI as alternatives
SEB High Limited banking alternatives in Swedish market, maintain good relationship Explore Swedbank/Handelsbanken for backup accounts
Bokio Moderate Alternative accounting solutions available (Fortnox, Visma) Maintain export capabilities, document accounting processes
Stripe High Limited payment processor alternatives with same features, plan for redundancy Consider Klarna Checkout for Swedish market, PayPal as backup
SonarSource Very Low Free for open source, multiple alternatives available Leverage free tier for public repos, maintain alternative scanning tools
FOSSA Very Low Free for open source, competitive market with alternatives Use free tier for public repos, consider WhiteSource/Snyk as alternatives
StepSecurity Very Low Free for open source, emerging market with growing alternatives Leverage free security hardening, monitor for alternative solutions

🚪 Entry Barriers Impact

Critical suppliers (AWS, SEB, Stripe) have very high entry barriers, providing stability but also creating dependency risks. Lower barrier suppliers (Suno, ElevenLabs, security tools) offer more flexibility for switching.

🔄 Substitute Threat Analysis

Service Category Substitute Risk Mitigation Hack23 Strategy
Cloud Infrastructure Low Few viable alternatives to AWS at scale Maintain infrastructure as code for potential migration
Version Control Moderate GitLab, Bitbucket available as alternatives Regular repository backups, maintain platform-agnostic CI/CD
Music Generation High Many AI music platforms emerging Diversify audio content sources, build proprietary library
Voice Synthesis High Rapidly evolving market with new entrants Create voice presets library, maintain multiple provider accounts
Banking Low Limited options in Swedish market Maintain strong relationship with SEB
Accounting Moderate Several established competitors Ensure data portability, maintain accounting documentation
Payment Processing Low Few processors with Stripe's global reach Plan for multi-provider payment strategy
Code Quality High Multiple SAST/DAST tools available Leverage free OSS tools, maintain multiple scanning approaches
License Compliance High Growing market with multiple providers Use multiple scanning tools, maintain internal license database
Workflow Security High Emerging market with rapid innovation Monitor security tool landscape, adopt best practices

💰 Business Impact Analysis

Critical Suppliers (RTO < 1 hour)

  • AWS: Complete service outage affecting Black Trigram game servers and Citizen Intelligence Agency
  • Stripe (planned): Payment processing halt, direct revenue impact

High Priority Suppliers (RTO 1-4 hours)

  • GitHub: Development and deployment delays, affecting all projects
  • SEB: Financial transaction delays, payroll impact

Medium Priority Suppliers (RTO 4-24 hours)

  • Bokio (planned): Accounting process delays, compliance reporting delays
  • SonarSource: Code quality analysis delays, potential security vulnerabilities undetected
  • FOSSA: License compliance delays, legal risk exposure
  • StepSecurity: CI/CD security gaps, supply chain vulnerability exposure

Low Priority Suppliers (RTO > 24 hours)

  • Suno: Marketing content delays, game soundtrack updates
  • ElevenLabs: Content production delays, voice asset generation

🚨 Incident Response Contacts

Supplier Support Level Contact Response Time Escalation
AWS Enterprise AWS Support Portal 15 minutes Critical
GitHub Enterprise GitHub Support 1 hour High
SEB Business Dedicated Account Manager 4 hours High
Stripe Standard Support Portal 24 hours Medium
Bokio Standard Support Email 24 hours Medium
SonarSource Community Community Forum 48 hours Low
FOSSA Community Support Email 48 hours Low
StepSecurity Community GitHub Issues 48 hours Low
Suno Basic Support Email 48 hours Low
ElevenLabs Basic Support Email 48 hours Low

📚 Related Documents

🎯 Strategic & Governance

🔐 Security Policies & Controls

⚙️ Operational Integration


📋 Document Control:
✅ Approved by: James Pether Sörling, CEO
📤 Distribution: CEO, Insurance Company, Legal Counsel
🏷️ Classification: Confidential - Internal Use Only
📅 Effective Date: 2026-01-25
⏰ Next Review: 2026-04-25
🎯 Framework Compliance: ISO 27001 NIST CSF 2.0 CIS Controls