For regulated AI · Banks & financial services

The governance your regulator is about to demand — enforced, not promised.

Under DORA, the EU AI Act, and SR 11-7, every regulated firm now has to inventory, control, and evidence the AI agents touching its operations. EcoCloud is the runtime that makes those controls architectural: every agent action is checked against a machine-readable constitution, scoped, ES256-signed, hash-chained, and reversible — before it executes.

The straight answer first

EcoCloud is not SOC 2 or ISO 27001 certified yet, and "DORA-certified" isn't a badge a vendor can hold — DORA and the AI Act place obligations on you, the financial entity/deployer. What EcoCloud gives you is the enforceable control substrate and signed audit evidence those obligations are assessed against, plus an honest account of what we don't do yet. We won't claim a badge we don't hold. See our full posture on the Trust Center →

DORA

Regulation (EU) 2022/2554 · in force Jan 2025

EcoCloud is an ICT third-party service provider. These are the DORA obligation areas where our real, deployed mechanisms do the enforcing and produce the evidence — and the parts that remain yours.

DORA obligationEcoCloud mechanism (live)What you still own
Art. 5–15ICT risk management framework — controls enforced, resilience by design enforced pre-execution
The constitution gate checks every agent action against a machine-readable policy before it runs — controls are enforced, not monitored after the fact. Ships with 8 sector constitution packs.
Your ICT risk framework, risk appetite, and governance ownership.
Art. 9Protection & prevention — least privilege, segregation of duties Authority subsetting (an agent can never exceed its delegator), four-eyes maker-checker, and signing-limit escrow route high-value or low-confidence actions to a named human. Your access policy, joiner/mover/leaver process, IAM.
Art. 17–23ICT incident management — detect, classify, log, report A SHA-256 hash-chained audit ledger with ES256-signed Merkle checkpoints gives you a tamper-evident record of every action — any silent edit breaks the chain and fails verification; the in-flight watchdog and circuit breaker catch runaway/anomalous runs mid-flight. Classification against your thresholds, then reporting to your NCA — initial notification within 4h of classifying an incident as major (≤24h from awareness), then the 72-hour and one-month reports. We supply the evidence; you file it.
Art. 24–27Resilience testing (incl. TLPT) Eval suite (agent CI/CD), dry-run preflight + scenario simulation, and a 724-assertion deterministic conformance suite give you repeatable, evidenced control testing. Your threat-led penetration test (TLPT) engagement and scope.
Art. 28–30ICT third-party risk — Register of Information, exit & portability Public subprocessor list (Cloudflare, Supabase, Anthropic, Stripe — jurisdiction + data touched), full machine-readable data export (no lock-in), and compensating transactions for clean unwind. Your Register of Information and the executed third-party contract.

EU AI Act

Regulation (EU) 2024/1689 · high-risk duties phasing in 2026–27

EcoCloud is a governance layer, not itself the high-risk AI system. Articles 9–15 are provider obligations (Art. 16); a deployer that materially customizes a high-risk system can become a provider under Art. 25 and inherit them, while deployers separately owe the narrower duties in Art. 26 (use per instructions, human oversight, input relevance, log retention). Wherever the obligation lands, these are the mechanisms that help you meet it.

AI Act obligationEcoCloud mechanism (live)What you still own
Art. 9Risk management system Constitution gate + risk-at-dispatch scoring + preflight continuously gate actions by risk band. Risk classification of your specific use case.
Art. 10Data governance & minimization A documented, narrow data boundary — the model sees only your typed text + a browser-extracted excerpt, never your other tasks/members/keys; and verifiable receipts prove compliance without exposing raw data. Governance of the data you choose to feed it.
Art. 12Record-keeping — automatic event logging over the lifecycle strongest map
The SHA-256 hash-chained, ES256-checkpointed audit trail is automatic, tamper-evident lifecycle logging — the exact capability Art. 12 requires, built as the substrate rather than bolted on.
Your retention schedule (we retain per your plan).
Art. 13Transparency & information to deployers A public AI Dispatch spec (model in use, pipeline, failure modes) and machine-readable capabilities — you always know which model acts and how. Your end-user-facing disclosures.
Art. 14Human oversight Four-eyes review, staged approvals with conditional delegation, and override-hotspot analytics — a human can always intervene, and the UI is where you go to disagree with the agent. Staffing and competence of your oversight function.
Art. 15Accuracy, robustness & cybersecurity Prompt-injection defense, deterministic kernels, watchdog/breaker, and dual-rail verification harden the agent path. Your accuracy/robustness acceptance thresholds.

Model risk (SR 11-7 / ECB)

supervisory model-risk expectations

EcoCloud is model-risk-management infrastructure — not a validated model. It supports the three things supervisors ask for:

Inventory

Which foundation model dispatches in your tenant is documented and queryable — not a black box. See the spec →

Monitoring

Every dispatch is logged with method, confidence, and outcome; the eval suite gives you ongoing performance evidence.

Control & explainability

Each action records which constitution clause was evaluated and the verdict — a signed reasoning trail, not a post-hoc guess. Lineage →

What we don't do yet

so nothing surprises you in the security questionnaire

A CISO deserves the gaps up front. These are real, and most are on the roadmap — but today, the honest answer is no:

SOC 2 Type II / ISO 27001Not yet certified. The controls above are exactly what those audits assess; certification is our roadmap and your attestation — we won't pretend otherwise.roadmap
Region-pinned / in-jurisdiction tenantsRuns on Cloudflare's global edge + Supabase (region per project). Hard EU-only / in-country data residency is not yet offered.roadmap
VPC / air-gapped self-hosted runtimeNo self-hosted deployment today — it's SaaS. A customer-VPC runtime with the same governance guarantees is a roadmap item, not available now.roadmap
Customer-managed / HSM-backed keys (EKM)Today: BYOK for your model API key, encrypted at rest (AES-256-GCM). Full customer-managed KMS/HSM key custody is not yet available.partial
Continuous-control-monitoring push feedThe signed audit trail is queryable and exportable today; a real-time push into your GRC/SIEM (Splunk/Sentinel/ServiceNow) is roadmap.roadmap
Cyber-insurance certificate / TLPT resultsNo published pen-test or TLPT summary yet, and we won't cite one we don't have.not yet

Bring your security questionnaire.

We'll walk your TPRM and model-risk teams through the architecture, the audit chain, and this exact map — line by line, honestly.

Start free Read the Trust Center