Operating model grounded in NIST CSF 2.0 supply-chain governance, built against Anthropic's own compute counterparties from public announcements, SEC filings and reporting. No inside information. Every supplier here is named, because every one of them announced the arrangement itself.
4 of 8 suppliers are simultaneously investors. A supplier who is also on the cap table has different incentives in a dispute, a capacity squeeze, and a renegotiation. Counting them as independent counterparties overstates diversification.
Structural, not per-vendor. Each of these is invisible in a supplier-by-supplier view, which is why portfolio-level reporting is a programme capability rather than a dashboard nicety.
Two honest observations about this data. The distribution is 5 mission critical / 2 high / 1 medium — for a portfolio this small that reflects a scoring model tuned conservatively, not a claim that everything is dangerous. And where a supplier has no locatable attestation, residual equals inherent: an unevidenced supplier is unmeasured, not demonstrably weak. That inversion is deliberate and it is the number most likely to move once real diligence is possible.
Eight compute counterparties, assembled from public announcements, SEC filings and reporting — no inside information. Inherent is scored before controls; residual after publicly evidenced ones. Where a supplier has no locatable attestation, residual equals inherent, because an unevidenced supplier is unmeasured, not demonstrably safe.
| ID | Supplier | Tier | Inherent | Residual | Investor | Open | Fourth-party |
|---|---|---|---|---|---|---|---|
| ANT-SUP-001 | Amazon Web ServicesPrimary cloud provider (2023) and primary training partner (2024). Project Rainier. | Mission Critical | 92 | 57 | investor | 3 | Annapurna Labs (Trainium silicon) |
| ANT-SUP-002 | Google CloudTPU compute capacity; Vertex AI distribution. | Mission Critical | 87 | 52 | investor | 3 | Broadcom (TPU co-development) |
| ANT-SUP-003 | Microsoft AzureCompute purchase; Foundry distribution. | Mission Critical | 83 | 48 | investor | 3 | NVIDIA (GPU supply underlying Azure capacity) |
| ANT-SUP-004 | NVIDIAGPU architecture and supply. | Mission Critical | 70 | 60 | investor | 3 | TSMC (foundry — industry-wide dependency) |
| ANT-SUP-008 | TeraWulfDirect 20-year data centre lease, Justified Data campus, Hawesville, Kentucky. | Mission Critical | 68 | 68 | — | 2 | Kentucky grid interconnection (former Century Aluminum smelter load), GPU/accelerator supply chain, TSMC (foundry, via all accelerator architectures) |
| ANT-SUP-005 | BroadcomCo-development of next-generation TPUs with Google. | High | 40 | 40 | — | 1 | — |
| ANT-SUP-006 | FluidstackNeocloud data centre build-out, Texas and New York; now also owner/developer at Abernathy following the July 2026 JV buyout. | High | 38 | 38 | — | 1 | Regional power grids (ERCOT, NYISO), GPU supply chain |
| ANT-SUP-007 | SpaceXCompute capacity; exploring orbital compute. | Medium | 37 | 37 | — | 1 | NVIDIA (reported 220,000+ GPUs) |
This is the head of the portfolio, and only the head. The tail is Anthropic's published subprocessor list — 20 vendors covering cloud infrastructure, traffic routing, billing, single sign-on, user support across three jurisdictions, fraud and identity, web search and text-to-speech. It carries no assessment here, because no public assessment exists and inventing one would be the defect this instrument argues against. Reconciling the two populations is where a real engagement starts — and three vendors sit in both halves at once, carrying a multi-billion-dollar compute commitment and a data-processing relationship under different instruments.
Generated from the endpoint. This table is built by
build_register.py against techfoundations.ai/mcp/tprm, so the page and
the server cannot disagree. Until 27 July 2026 they did — the page served a different register
entirely, and every count in the packet inherited the discrepancy.
Each stage traces to a NIST CSF 2.0 subcategory, so the program is auditable against something other than my opinion.
GV.SC-06 · ID.RA-10GV.SC-04GV.SC-05GV.SC-07GV.SC-07 · GV.SC-09GV.SC-08GV.SC-10Definitions matter more than the numbers. Each of these is chosen because the obvious alternative hides something.
Aggregate coverage hides the case where the uncovered remainder is the critical tier.
Keyed on report period end plus bridge letter held — never on date received, which shows green forever.
Long cycle time is what pushes the business to route around the process entirely.
The only measure of whether findings cause anything to change.
The direct year-two indicator. Count and age, by tier.
Share of critical vendors whose carve-out subservice orgs were chased to their own report. Rarely measured; often where the exposure is.
Any scoring model encodes somebody's judgement. A different organisation has a different risk appetite, different regulators and different data classes — so the model takes practitioner input rather than hard-coding mine.
A policy, SOP, control standard or scoring model. Parsed into candidate rules, each traced back to the line of your document that produced it.
"Re-tiers 3 vendors High → Critical, opens 7 findings." Population impact shown before commit — a scoring change that lands silently is a governance failure.
Candidate rules run against a held-out set of human-tiered vendors. Precision and recall reported with the direction of the errors.
Under-tiering a critical vendor costs far more than over-tiering a trivial one. False negatives are reported separately, not averaged into an accuracy figure.
Every score carries the calibration version that produced it, so a finding from March is interpretable in July.
The model drafts risk statements and extracts CUECs. It does not make the risk acceptance decision — a named human does. That boundary is the control.