Offer · Govern Early access

Compliance is demonstrated, not declared.
Evidence your runtime signs, in the GRC you already own.

Regulatory Evidence Desk produces evidence for DORA, NIS2 and the EU AI Act while the work happens, signed by the runtime that enforced the controls. It assembles an auditor-ready pack per regulation and per entity, and exports the same evidence into the GRC and security tools you already run. We are the evidence source, not another GRC.

A spreadsheet of answers is not evidence

Most compliance evidence is written after the fact, by people describing what the controls should have done. An auditor then checks the description. The desk works from the other end: the record of what each control actually did, produced and signed at the moment it happened.

Mapped article by article

Each governance control is tied to the article it serves in DORA, NIS2 or the EU AI Act, and the article and its objective are quoted in every pack, never paraphrased.

A result an auditor can re-check

A control counts as holding only when its automated check passed inside the period. Everything else is listed as a gap, with the reason: failed, stale, never checked, or switched off.

Signed by the runtime

Every pack and export is signed with the platform key and verifiable against a published key set, so anyone can prove it was not edited between our runtime and your auditor.

Per regulation and per entity

One pack per regulation for each entity in scope — the group, or an entity with its own governance configuration — every period.

Into the tools you own

OSCAL assessment results for your GRC tool, OCSF events for your SIEM. No second register to keep, no new console for your auditors.

Gaps stated, not hidden

Every pack says which sources could not be read and which obligations it does not cover. A gap stated is worth more than a pack that looks complete.

Five agents, none of which signs

Each agent has one job and holds only the tools that job needs. None of them can sign, release, send or file anything.

Evidence Lead

Keeps the scope, reviews every pack before it reaches your compliance owner, and brings every decision to a person with its evidence.

Control Mapper

Ties each regulation's control objectives to your own control library, and proposes where each piece of evidence belongs.

Evidence Collector

Watches that evidence keeps being produced, and flags stale checks, unreadable sources and systems it cannot see.

Pack Assembler

Builds the signed pack per regulation and entity, prepares the attestations a person must sign, and drafts filing material on request.

Evidence Exporter

Produces the signed OSCAL and OCSF exports, checks them, and hands them to the owners of your GRC and SIEM.

What they never do

  • Sign an attestation
  • Release a pack to an auditor, at entry
  • Send evidence anywhere
  • File with a regulator or supervisor
  • Write a regulatory rule from memory

How the desk earns its autonomy

Autonomous

Reading evidence, and producing signed packs and exports. Read-only, and every export is recorded in the audit log.

Proposes first

Mapping evidence to your controls. The mapper proposes; a person applies. It maps on its own only after a long run of proposals accepted without correction, and loses that on the first reversal.

Human at entry

Releasing a pack to an auditor and importing an export. Recurring packs to a named auditor can be released without a per-pack decision once quarters go by without a correction.

Always human

Signing an attestation, and submitting anything to a regulator or supervisor. The desk prepares the material; your people decide and file.

Nothing is autonomous by default, and every step up is recorded with the evidence behind it.

What we say, and what we do not

Covered

DORA, NIS2, EU AI Act

The regulations for which the platform carries a governance pack, with each control mapped to its article.

Maps to

Evidence, not a verdict

The evidence maps to the regulation and supports an assessment. Your auditor concludes; we never call you compliant or certified.

Measured

What the desk reports

Controls with evidence in the period, packs released on schedule, exports confirmed imported.

Your compliance team runs it, where your data is

Regulatory Evidence Desk is operated by your own compliance and risk team — as a service, or installed in your data centre or sovereign cloud from a signed release, with the evidence kept in your region. It is priced per regulation and entity in scope, with a component per audit pack delivered.

Join the early access →

See every offer · Compliance evidence · Continuous assurance · Audit cockpit