Direct obligation
Rules that bind Opendome by virtue of its own activity, whoever the customer happens to be. Here it is we who answer to the authority.
Most of the rules our customers worry about bind them, not us. This page distinguishes which obligations fall directly on Opendome, which ones our role is to supply the evidence the customer needs for, and which frameworks we adopt of our own accord.
It is common to read that a platform «complies with DORA» or «complies with the ENS». Strictly speaking, those rules do not bind a technology provider except in specific cases: they bind the financial entity, the operator of essential services or the public body. What does bear on the choice of provider is whether it can supply the evidence and the clauses its customer needs in order to comply.
We prefer to make that distinction explicit. A compliance officer knows it, and an imprecise claim on this ground undermines the credibility of everything else.
Rules that bind Opendome by virtue of its own activity, whoever the customer happens to be. Here it is we who answer to the authority.
Rules that bind the customer and that reach Opendome contractually. Our role is to supply the controls, the traceability and the documentation that allow the customer to evidence its own compliance.
Standards nobody imposes on us, which we adopt as internal discipline and as a common language with whoever is assessing us.
Two frameworks apply to Opendome by virtue of its own activity.
Opendome is the controller of its own data and the processor of the data the customer holds in its dome. As processor, it processes that data solely in accordance with the customer's documented instructions and does not determine purposes.
Obligations assumed: a processing agreement under Article 28 before the first datum, the technical measures of Article 32, a record of processing activities under Article 30 kept separately by role, assistance to the customer with data subject rights and with breaches, subprocessor management with notification of changes, and return or deletion on termination.
Opendome develops AI components and infrastructure — governed retrieval, embeddings, semantic suggestions — that third parties integrate into their own systems. It does not place Annex III high-risk systems on the market.
Every AI system we develop or operate has a documented risk classification. The current features are classified as limited or minimal risk. No high-risk system goes into production without a documented classification and Security Council approval.
Where the optional inference module is contracted, Opendome acts as the deployer of self-hosted general-purpose models, with the transparency obligations of Article 50 where they apply.
These rules bind the customer organisation. Opendome does not declare that it complies with them: it declares which controls, records and contractual commitments it makes available to whoever is in fact bound.
| Framework | Who it binds | What Opendome supplies |
|---|---|---|
| DORA Regulation (EU) 2022/2554 |
Financial entities and their ICT providers designated as critical | An audit record of every access to data — which identity, which policy applied, over which datum —, contractual clauses for third-party risk management, incident notification within the deadline, and declared recovery objectives with the basis on which they are calculated. |
| NIS2 Directive (EU) 2022/2555 |
Essential and important entities according to sector and size | Documented risk and supply chain management, an incident response plan with classification by severity, and coordination on notification where the incident is notifiable by the customer. |
| ENS Esquema Nacional de Seguridad |
The Spanish public sector and its providers, contractually | Identity, encryption, traceability and per-tenant segregation controls aligned with the measures of the Esquema, and documentation for the contracting body's file. Formal adequacy is determined in each tender according to the category of the system. |
| EU AI Act Article 25(4) |
Customers that are providers or deployers of high-risk systems | A commitment, formalised by written agreement, to supply the information, capabilities and technical assistance the customer needs in order to meet its obligations under the Regulation. |
| GDPR As processor |
The customer, as controller | Assistance with the exercise of data subject rights, information for impact assessments, notification of breaches without undue delay, and evidence of the measures of Article 32. |
Exactly who controls what in each deployment model — and therefore who supplies each piece of evidence — is set out in the shared responsibility matrix. In the self-host model operated by a third party, operational responsibility is the operator's; Opendome answers for the artefact it distributes.
None of these is required of a company our size. We adopt them because they structure the internal work, and because they are the language in which a procurement committee knows how to assess.
| Framework | Scope | State |
|---|---|---|
| ISO/IEC 27001:2022 | Information security management system | Audit · November 2026 |
| SOC 2 | Security, availability and privacy criteria | Type I · autumn 2026 |
| OpenChain ISO/IEC 5230 | Open source licence compliance, SBOM and third-party notices | Programme in place |
| ISO/IEC 42001 · NIST AI RMF | Governance of AI systems | Design reference |
The management system policies are approved and in force, and compliance with them is verified in Security Council reviews. The ISO certification and the SOC 2 attestation conclude on the dates indicated; until then we do not present them as obtained. The current state of both processes is published in the trust portal.
The requirements for traceability, access minimisation and human oversight recur in almost all of these rules. They are resolved in the architecture, not in a configuration layer someone has to set up and maintain.
| Governed consumption | Every read of data passes through the semantic layer and its policy enforcement point, in fail-closed mode. There is no alternative read path towards the data engines. |
| Atomic access | Policies govern access at column and cell level. Minimisation is not a procedure: it is the behaviour of the system. |
| Traceability | Every consumption leaves a record of which identity accessed which datum and under which policy. It is the primary evidence DORA and the EU AI Act ask for. |
| Isolation | Each customer's data resides in an isolated dome, with no mixing and no cross-access between customers. |
| Human oversight | No relevant decision on security, access, data classification or a person's rights is taken fully automatically. AI assists; a person decides and is accountable. |
| Declared classification | Whether a datum is personal is declared in the connector that ingests it. The system may suggest a classification, but never determines it automatically. |
A session with your compliance team to review which obligations apply to you, what evidence you need from a technology provider, and which of that evidence we can supply today.
Request a technical meetingSix European regulations apply to an enterprise AI deployment, and most of them ask for the same things in different words. This manual reduces them to four common questions and explains what each one requires, of whom and from when. It covers the four layers of data sovereignty. A shared reference for executives, business, technology and legal teams.
Descargar el whitepaperBusiness memory already exists: it lives in the data. The only memory that should belong to the agent is procedural.
guardrails vs data security"The agent has guardrails, so the data is protected." That sentence conflates two things operating on different planes. Guardrails watch what the agent says; they don't govern what it accesses. Only structural, reproducible access control protects the data — because it isn't statistical: it's deterministic.
Enterprise AI strategyThere's no enterprise AI strategy without centralizing, relating, describing, and protecting the data. They aren't four good ideas to choose among. They're four conditions, and missing one invalidates the rest.
Ver todos los recursos