ES Technical meeting
Menu
01 — Approach

Who each rule binds

It is common to read that a platform «complies with DORA» or «complies with the ENS». Strictly speaking, those rules do not bind a technology provider except in specific cases: they bind the financial entity, the operator of essential services or the public body. What does bear on the choice of provider is whether it can supply the evidence and the clauses its customer needs in order to comply.

We prefer to make that distinction explicit. A compliance officer knows it, and an imprecise claim on this ground undermines the credibility of everything else.

Level 1

Direct obligation

Rules that bind Opendome by virtue of its own activity, whoever the customer happens to be. Here it is we who answer to the authority.

Level 2

Customer assistance

Rules that bind the customer and that reach Opendome contractually. Our role is to supply the controls, the traceability and the documentation that allow the customer to evidence its own compliance.

Level 3

Voluntary frameworks

Standards nobody imposes on us, which we adopt as internal discipline and as a common language with whoever is assessing us.

02 — Level 1

What binds us directly

Two frameworks apply to Opendome by virtue of its own activity.

GDPR

Regulation (EU) 2016/679

Opendome is the controller of its own data and the processor of the data the customer holds in its dome. As processor, it processes that data solely in accordance with the customer's documented instructions and does not determine purposes.

Obligations assumed: a processing agreement under Article 28 before the first datum, the technical measures of Article 32, a record of processing activities under Article 30 kept separately by role, assistance to the customer with data subject rights and with breaches, subprocessor management with notification of changes, and return or deletion on termination.

EU AI Act

Regulation (EU) 2024/1689

Opendome develops AI components and infrastructure — governed retrieval, embeddings, semantic suggestions — that third parties integrate into their own systems. It does not place Annex III high-risk systems on the market.

Every AI system we develop or operate has a documented risk classification. The current features are classified as limited or minimal risk. No high-risk system goes into production without a documented classification and Security Council approval.

Where the optional inference module is contracted, Opendome acts as the deployer of self-hosted general-purpose models, with the transparency obligations of Article 50 where they apply.

03 — Level 2

What we supply so the customer can comply

These rules bind the customer organisation. Opendome does not declare that it complies with them: it declares which controls, records and contractual commitments it makes available to whoever is in fact bound.

Framework Who it binds What Opendome supplies
DORA
Regulation (EU) 2022/2554
Financial entities and their ICT providers designated as critical An audit record of every access to data — which identity, which policy applied, over which datum —, contractual clauses for third-party risk management, incident notification within the deadline, and declared recovery objectives with the basis on which they are calculated.
NIS2
Directive (EU) 2022/2555
Essential and important entities according to sector and size Documented risk and supply chain management, an incident response plan with classification by severity, and coordination on notification where the incident is notifiable by the customer.
ENS
Esquema Nacional de Seguridad
The Spanish public sector and its providers, contractually Identity, encryption, traceability and per-tenant segregation controls aligned with the measures of the Esquema, and documentation for the contracting body's file. Formal adequacy is determined in each tender according to the category of the system.
EU AI Act
Article 25(4)
Customers that are providers or deployers of high-risk systems A commitment, formalised by written agreement, to supply the information, capabilities and technical assistance the customer needs in order to meet its obligations under the Regulation.
GDPR
As processor
The customer, as controller Assistance with the exercise of data subject rights, information for impact assessments, notification of breaches without undue delay, and evidence of the measures of Article 32.

Exactly who controls what in each deployment model — and therefore who supplies each piece of evidence — is set out in the shared responsibility matrix. In the self-host model operated by a third party, operational responsibility is the operator's; Opendome answers for the artefact it distributes.

04 — Level 3

Frameworks we adopt of our own accord

None of these is required of a company our size. We adopt them because they structure the internal work, and because they are the language in which a procurement committee knows how to assess.

Framework Scope State
ISO/IEC 27001:2022 Information security management system Audit · November 2026
SOC 2 Security, availability and privacy criteria Type I · autumn 2026
OpenChain ISO/IEC 5230 Open source licence compliance, SBOM and third-party notices Programme in place
ISO/IEC 42001 · NIST AI RMF Governance of AI systems Design reference

The management system policies are approved and in force, and compliance with them is verified in Security Council reviews. The ISO certification and the SOC 2 attestation conclude on the dates indicated; until then we do not present them as obtained. The current state of both processes is published in the trust portal.

05 — Architecture

Controls that serve several frameworks at once

The requirements for traceability, access minimisation and human oversight recur in almost all of these rules. They are resolved in the architecture, not in a configuration layer someone has to set up and maintain.

Governed consumption Every read of data passes through the semantic layer and its policy enforcement point, in fail-closed mode. There is no alternative read path towards the data engines.
Atomic access Policies govern access at column and cell level. Minimisation is not a procedure: it is the behaviour of the system.
Traceability Every consumption leaves a record of which identity accessed which datum and under which policy. It is the primary evidence DORA and the EU AI Act ask for.
Isolation Each customer's data resides in an isolated dome, with no mixing and no cross-access between customers.
Human oversight No relevant decision on security, access, data classification or a person's rights is taken fully automatically. AI assists; a person decides and is accountable.
Declared classification Whether a datum is personal is declared in the connector that ingests it. The system may suggest a classification, but never determines it automatically.

Compliance review

A session with your compliance team to review which obligations apply to you, what evidence you need from a technology provider, and which of that evidence we can supply today.

Request a technical meeting