Dorashelf
A two-sided DORA evidence exchange where technology vendors publish scoped claims and artifacts, regulated buyers assess coverage and generate review questions under their own risk policy.
Financial-sector buyers repeatedly request third-party ICT evidence, while vendors answer similar questionnaires with different terms and freshness. Dorashelf standardizes a submission and maps evidence candidates to a versioned DORA rule source, but a vendor claim is not verified fact, schema validation is not substantive control testing, evidence coverage is not compliance and a single health score would hide buyer-specific materiality. The safer product produces an evidence profile, gaps, provenance and RFP questions for buyer review, with vendor correction and appeal. The supplied scan supports a neutral exchange gap across cyber ratings, self-serve compliance and DORA point tools, but the buyer quartet is incomplete and the enforcement timing lacks primary text in the input.
ICT risk, procurement, compliance or resilience teams at regulated EU financial entities, plus software vendors answering their evidence requests; role, budget and current alternative remain incomplete.
The source records two cross-references and two inbound connections before the grounded score.
The supplied secondary sources describe active DORA enforcement, subject to current primary-authority confirmation.
Financial ICT-risk and vendor teams are implied, while role, size, budget and current alternative are not fully specified.
The source supplies active DORA demand, multiple graph links, one verified interface and a confirmed gap between vendor-self-service, cyber ratings and a neutral evidence exchange.
The buyer quartet is incomplete, primary regulatory authority is absent from the input, neutrality and validation require governance, one exchange can concentrate sensitive evidence and no structural incumbent cost is evidenced.
Discussion
No comments yet — be the first to weigh in.
