Validation build: prices are simulated and no cover is in force. What that means

For procurement, risk and DORA review

DORA Article 30, clause by clause

A financial entity may rely on an ICT provider only under a written contract that contains the provisions Regulation (EU) 2022/2554 (DORA), Article 30, lists. Below is each of those provisions, the clause we offer for it, and what is in place today. Where something is not in place, it says so.

These are proposed terms. RiskRouter has no legal entity registered yet, so no contract can be signed today (facts for your register of information). When one can, these are the terms we will put in it, in one written document you can keep. The summaries of the Regulation are ours and the linked text is the law. This is not legal advice: your counsel should check the clauses against your own policy, and whether the function we support is critical or important is your assessment.

Article 30(2): in every contract

(a) The services, and subcontracting

Requires
A clear and complete description of the functions and services, saying whether subcontracting is permitted and on what conditions.
We offer
The service is described in the order form: the evidence log (/api/v2), the quote ledger and pricing engine (/api/v1), with the API reference as the technical description at the date of signature. Subcontracting is permitted only to the providers listed on the data protection page. We give you at least 30 days’ written notice before adding or replacing one, and you may terminate without charge if you object.
In place today
The description and the list of subprocessors are published.

(b) Where services are provided and data is kept

Requires
The regions or countries where the services are provided and data is processed and stored, and advance notice of any change.
We offer
Stored in the EU: the database is in Frankfurt, Germany. Requests are handled at the Cloudflare location nearest the caller, which may be outside the EEA, and nothing is stored there. An encrypted daily backup is kept on GitHub for 90 days, outside the EU. At least 30 days’ written notice before any of these changes.
In place today
As stated, and published on Trust.

(c) Availability, authenticity, integrity and confidentiality of data

Requires
Provisions on the availability, authenticity, integrity and confidentiality of data, including personal data.
We offer
Integrity is the product: entries are append-only in the database itself, hash-chained, under signed heads with public timestamps and a Bitcoin anchor, and you can check all of it without us. Your records never reach us: only salted fingerprints are sent. Only the SHA-256 of an API key is stored. A data processing agreement under GDPR Article 28 is attached where any personal data is processed on your behalf.
In place today
Built, tested in CI, and described in the specification and on Security.

(d) Access to your data, and its return, whatever happens to us

Requires
Access, recovery and return of your data in an easily accessible format if the provider becomes insolvent, is resolved or stops, or the contract ends.
We offer
You can export everything you recorded at any time, in an open JSON format, without a ticket or a fee, and it verifies without us. We give at least 90 days’ written notice before discontinuing the service, and the export stays available throughout that period and any transition period under (3)(f).
In place today
The export, the open format and the public verifier. What you keep

(e) Service levels

Requires
Service level descriptions, including their updates and revisions.
We offer
The service levels agreed for your contract, in the order form. Every change to the API and to the rating matrix is listed in the changelog, with at least 90 days’ written notice before we remove or change anything you rely on; live availability is on the status page.
In place today
No service level is offered during the validation build. It is agreed in writing per pilot.

(f) Help when an incident touches the service

Requires
Assistance when an ICT incident related to the service occurs, at no additional cost or at a cost fixed in advance.
We offer
Assistance at no additional cost: the facts, logs and timeline we hold about the incident, and our help in establishing what it affected.
In place today
Incident notes are kept in the repository, and the ledger’s own history is independently checkable.

(g) Cooperation with your authorities

Requires
Full cooperation with your competent and resolution authorities, and the people they appoint.
We offer
Full cooperation, without charge.
In place today
A commitment; nothing is needed to begin it.

(h) Ending the contract

Requires
Termination rights and minimum notice periods that meet your authorities’ expectations, including the grounds in Article 28(7).
We offer
You may end the contract at any time, for any reason, with no notice period and no termination fee, as well as on every ground in Article 28(7). We may end it for convenience only with at least 90 days’ written notice, and never without the transition period under (3)(f) if you ask for it.
In place today
Leaving needs nothing from us but revoking your key. The steps to leave

(i) Security awareness and resilience training

Requires
The conditions on which the provider takes part in your ICT security awareness programmes and digital operational resilience training (Article 13(6)).
We offer
We take part when you ask, at no charge.
In place today
A commitment.

Article 30(3): where the service supports a critical or important function

Whether it does is your assessment. If it does, the contract also needs the following, and the first is not something we can offer yet. Tell us before a pilot starts, so it is settled in writing rather than discovered later.

(a) Measurable service levels

Requires
Full service level descriptions with precise quantitative and qualitative performance targets, so you can monitor the service and act when a target is missed.
In place today
Not offered. During the validation build we publish no availability target and give no service credit. A contract for a critical or important function would need them agreed first.

(b) Notice of anything that affects the service

Requires
Notice periods and reporting obligations, including notice of any development that might materially affect the provider’s ability to provide the service.
We offer
Notice of any incident affecting the service without undue delay, and in any case within 24 hours of our becoming aware of it; and prompt written notice of any development that might materially affect our ability to provide it.

(c) Contingency plans and security measures

Requires
Business contingency plans that are implemented and tested, and appropriate ICT security measures, tools and policies.
In place today
A daily restore drill, run automatically, that restores the production ledger into a fresh database and checks every entry; the engine can also run in your own account. Restore drill · Running it yourself. The database plan keeps no backups of its own, no penetration test has been done, and no certification is held. Security

(d) Threat-led penetration testing

Requires
Participation and full cooperation in your threat-led penetration testing (Articles 26 and 27).
We offer
Full participation and cooperation, on terms agreed in advance so the test does not disturb other customers.

(e) Monitoring, access, inspection and audit

Requires
Unrestricted rights of access, inspection and audit for you, a third party you appoint, and your competent authority, with the right to take copies; alternative assurance levels where other customers’ rights are affected; cooperation during inspections; and details of their scope and frequency.
We offer
Those rights, on reasonable notice to us, and without notice where your competent authority requires it. Much of the evidence is already public and checkable without asking us: the log, its heads, the anchors and the software bill of materials.

(f) Exit, with a transition period

Requires
Exit strategies, including a mandatory adequate transition period during which the provider keeps providing the service, so you can move to another provider or in-house.
We offer
On any termination, including ours, the service continues at your request for a transition period of up to six months, on the same terms.
In place today
The documented exit plan. Continuity and exit plan
Facts for your register of information Discuss a pilot’s terms