saascode

Dorapack

A lightweight evidence-pack workspace for software vendors selling to EU-regulated buyers that inventories approved code and cloud sources, produces versioned SBOM and architecture candidates, maps evidence to buyer-requested DORA and NIS2 questions, and signs a bounded release manifest while keeping source observation, generated artifact, reviewer approval, supplier representation, buyer assessment, auditor work, authority decision, correction, and compliance outcome separate.

Genesis score6.90/10
Make Dorapack real.0/500
500 more votes and Dorapack is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The opportunity
3Cross-references
3Inbound connections
2Direct connections
The case

Software vendors face expanding procurement requests for machine-readable component inventories, architecture context, incident commitments, resilience evidence, and regulatory mappings. Dorapack assembles a source-linked bundle for a defined release and buyer request, but the supplied evidence does not establish that DORA universally mandates an SBOM from every SaaS vendor or that a secondary market statistic is legal authority. Generated diagrams and crosswalks are candidates; an incident-SLA statement requires contractual and operational authority; and a signed manifest proves bounded bundle integrity, not completeness, accuracy, audit readiness, DORA or NIS2 compliance, buyer acceptance, or supervisory approval.

Who pays — and why

A security, compliance, procurement-response, sales-engineering, or technical leader at a software vendor serving EU financial entities or other regulated buyers that repeatedly requests evidence packs.

What it unlocks
A release evidence registry linking repository and commit, build or artifact identifier, deployment environment, dependency inventory, cloud observations, architecture source, incident commitments, evidence owner, observed time, scope, freshness, and correction
A mapping workflow separating buyer question, cited legal or contractual source, applicability candidate, control objective, evidence candidate, gap, reviewer disposition, approved supplier response, recipient version, and later correction
A signed pack manifest listing included artifacts, hashes, tools and versions, source times, coverage limits, reviewer approvals, known gaps, release status, verification method, revocation, and amendment without certifying the contents
How Genesis scored it
6.90across seven criteria
tension 7temporal 8blindspot 5buyer 8leverage 6convergence 5why-not 8
8
Temporal window

The supplied market signal shows active EU procurement pressure, while exact legal requirements need current primary validation.

8
Buyer persona

Security, compliance, and procurement-response owners at vendors serving regulated buyers have a named recurring task.

5
Convergence

Three cross-references, three inbound connections, and two direct connections show a coherent evidence-pack cluster.

Why it scored well

The source identifies a regulated-buyer procurement workflow, verifies open SBOM and mapping primitives, confirms a close compliance-pack competitor, and supplies multiple connected evidence-governance ideas.

What's holding it back

No structural copying cost is proven, the closest competitor already ships signed packs, the legal mandate claim is not supported by primary authority in the input, architecture and control mappings require review, and a SOFT bundle can be copied quickly.

Signals detected4 sources crossed
SignalSource-run competitor verification

SignalSource-run technical verification

SignalSource-run package verification

SignalSource-run market research

Direction briefdorapack.md
dorapack.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.