# ApertureRisks Paid Exposure Assessment - Pilot Readiness Pack

Version: July 19, 2026

Operator: PWLogiConGroup LLC, operator of the ApertureRisks platform

## Offer and engagement scope

The Paid Exposure Assessment is a fixed-scope, time-bound engagement for one agreed supply-chain exposure question. Base scope includes up to 100 accepted supplier and operating records and an evidence-backed assessment connecting available disruption evidence to accepted Client records.

The assessment is not an open-ended consulting engagement. Provider does not guarantee that every record, supplier, tier, signal, or dependency can be mapped. Results depend on the accepted records, available relationships, and evidence appropriate to the agreed question.

## Delivery specification

Target delivery is five U.S. business days after Provider accepts all of the following:

- the scoped question
- the approved intake path
- usable records
- the accountable Client contact

The delivery clock pauses for missing or unusable data, unresolved clarification, approval delays, security or access issues, scope changes, or material revised inputs.

An illustrative delivery sequence is:

1. Day 1: intake validation and baseline preparation.
2. Day 2: signal and dependency analysis.
3. Day 3: evidence classification, gap analysis, and Exposure Score basis.
4. Day 4: Decision Brief and Action Register preparation.
5. Day 5: review, formatting, and delivery.

Activities may overlap. This sequence is illustrative and is not a guaranteed daily schedule.

## Client responsibilities and data requirements

The Client will name an accountable owner; approve the question, scope, and intake path; confirm authority to provide the data; provide usable records; answer blocking questions; identify handling restrictions; and review delivery.

Minimum expected fields may include:

- internal supplier or vendor identifier
- supplier name
- country and available location
- relevant PO, BOM, component, product, contract, facility, lane, or commitment identifier
- available relationship fields needed for the agreed question

DUNS and UEI may be supplied as optional matching fields. They are not universal minimum requirements.

Provider will identify an approved, engagement-specific intake path before operational data is exchanged.

## Deliverables

Delivery consists of:

1. Evidence-backed Exposure Baseline across accepted records, including unresolved and unassessed items.
2. Evidence Gap Register.
3. Owner-Based Action Register.
4. Executive Decision Brief.
5. Readout or asynchronous handoff.

The assessment does not promise complete risk quantification, complete tier-N visibility, complete supplier mapping, guaranteed identification of hidden risks, or legal, regulatory, or compliance determinations. Recommendations remain subject to named Client review.

## Five pilot measures

The engagement may record these measurement categories:

1. Signal-to-assigned-action time.
2. Previously unmapped exposure identified where supported by accepted evidence.
3. Evidence gaps closed through Client, supplier, or Provider action.
4. Governed Decision Briefs reviewed by named owners.
5. Like-for-like response-time comparison where a defensible baseline exists.

No metric, reduction, improvement, or result is represented as achieved until measured, documented, and approved.

## Commercial terms

Base fixed fee: $1,500 USD one time.

Payment is due before assessment intake unless the executed order form states a different payment schedule. Taxes and additions approved in a written scope are extra.

## Security and data boundary

Sensitive files must use the approved intake path. Required data-purpose, role, retention, deletion, subprocessor, and Client-specific control terms must be separately prepared, confirmed, and executed where applicable before intake. ApertureRisks is not represented as SOC 2 certified. Recommendations require human review.

## Change control

Additional questions, increased record volume, integrations, revised data after intake, recurring monitoring, bespoke analysis, enterprise controls, or custom reporting require a written change describing scope, price, schedule, and security impact before changed work begins.

## Retention, export, deletion, and exit

The executed agreement should identify permitted data and purpose, retention period, export format, deletion deadline, confirmation method, legal retention exceptions, backup or archival limitations, and provider-retention limitations.

Upon written request and subject to the executed agreement, legal obligations, provider retention, and backup limitations, Provider will export agreed Client data and delete it from active systems within the agreed period.

No immediate or universal deletion, deletion from every backup on demand, cryptographic deletion from all systems, or guaranteed Certificate of Deletion is represented.

## Acceptance and contract priority

The Client review period, written acceptance method, and correction process must be negotiated in the executed agreement. No deemed acceptance applies through silence, operational use, or expiration of a review period unless expressly negotiated in an executed agreement.

This public pack is not an executed agreement. Any separately prepared and executed order form, services agreement, DPA, or SOW controls when it differs from this pack.
