Under DORA, the EU AI Act, and SR 11-7, every regulated firm now has to inventory, control, and evidence the AI agents touching its operations. EcoCloud is the runtime that makes those controls architectural: every agent action is checked against a machine-readable constitution, scoped, ES256-signed, hash-chained, and reversible — before it executes.
EcoCloud is not SOC 2 or ISO 27001 certified yet, and "DORA-certified" isn't a badge a vendor can hold — DORA and the AI Act place obligations on you, the financial entity/deployer. What EcoCloud gives you is the enforceable control substrate and signed audit evidence those obligations are assessed against, plus an honest account of what we don't do yet. We won't claim a badge we don't hold. See our full posture on the Trust Center →
EcoCloud is an ICT third-party service provider. These are the DORA obligation areas where our real, deployed mechanisms do the enforcing and produce the evidence — and the parts that remain yours.
| DORA obligation | EcoCloud mechanism (live) | What you still own |
|---|---|---|
| Art. 5–15ICT risk management framework — controls enforced, resilience by design | enforced pre-execution The constitution gate checks every agent action against a machine-readable policy before it runs — controls are enforced, not monitored after the fact. Ships with 8 sector constitution packs. |
Your ICT risk framework, risk appetite, and governance ownership. |
| Art. 9Protection & prevention — least privilege, segregation of duties | Authority subsetting (an agent can never exceed its delegator), four-eyes maker-checker, and signing-limit escrow route high-value or low-confidence actions to a named human. | Your access policy, joiner/mover/leaver process, IAM. |
| Art. 17–23ICT incident management — detect, classify, log, report | A SHA-256 hash-chained audit ledger with ES256-signed Merkle checkpoints gives you a tamper-evident record of every action — any silent edit breaks the chain and fails verification; the in-flight watchdog and circuit breaker catch runaway/anomalous runs mid-flight. | Classification against your thresholds, then reporting to your NCA — initial notification within 4h of classifying an incident as major (≤24h from awareness), then the 72-hour and one-month reports. We supply the evidence; you file it. |
| Art. 24–27Resilience testing (incl. TLPT) | Eval suite (agent CI/CD), dry-run preflight + scenario simulation, and a 724-assertion deterministic conformance suite give you repeatable, evidenced control testing. | Your threat-led penetration test (TLPT) engagement and scope. |
| Art. 28–30ICT third-party risk — Register of Information, exit & portability | Public subprocessor list (Cloudflare, Supabase, Anthropic, Stripe — jurisdiction + data touched), full machine-readable data export (no lock-in), and compensating transactions for clean unwind. | Your Register of Information and the executed third-party contract. |
EcoCloud is a governance layer, not itself the high-risk AI system. Articles 9–15 are provider obligations (Art. 16); a deployer that materially customizes a high-risk system can become a provider under Art. 25 and inherit them, while deployers separately owe the narrower duties in Art. 26 (use per instructions, human oversight, input relevance, log retention). Wherever the obligation lands, these are the mechanisms that help you meet it.
| AI Act obligation | EcoCloud mechanism (live) | What you still own |
|---|---|---|
| Art. 9Risk management system | Constitution gate + risk-at-dispatch scoring + preflight continuously gate actions by risk band. | Risk classification of your specific use case. |
| Art. 10Data governance & minimization | A documented, narrow data boundary — the model sees only your typed text + a browser-extracted excerpt, never your other tasks/members/keys; and verifiable receipts prove compliance without exposing raw data. | Governance of the data you choose to feed it. |
| Art. 12Record-keeping — automatic event logging over the lifecycle | strongest map The SHA-256 hash-chained, ES256-checkpointed audit trail is automatic, tamper-evident lifecycle logging — the exact capability Art. 12 requires, built as the substrate rather than bolted on. |
Your retention schedule (we retain per your plan). |
| Art. 13Transparency & information to deployers | A public AI Dispatch spec (model in use, pipeline, failure modes) and machine-readable capabilities — you always know which model acts and how. | Your end-user-facing disclosures. |
| Art. 14Human oversight | Four-eyes review, staged approvals with conditional delegation, and override-hotspot analytics — a human can always intervene, and the UI is where you go to disagree with the agent. | Staffing and competence of your oversight function. |
| Art. 15Accuracy, robustness & cybersecurity | Prompt-injection defense, deterministic kernels, watchdog/breaker, and dual-rail verification harden the agent path. | Your accuracy/robustness acceptance thresholds. |
EcoCloud is model-risk-management infrastructure — not a validated model. It supports the three things supervisors ask for:
Which foundation model dispatches in your tenant is documented and queryable — not a black box. See the spec →
Every dispatch is logged with method, confidence, and outcome; the eval suite gives you ongoing performance evidence.
Each action records which constitution clause was evaluated and the verdict — a signed reasoning trail, not a post-hoc guess. Lineage →
A CISO deserves the gaps up front. These are real, and most are on the roadmap — but today, the honest answer is no:
We'll walk your TPRM and model-risk teams through the architecture, the audit chain, and this exact map — line by line, honestly.
Start free Read the Trust Center