Talk to sales

DORA evidence for regulated ICT

Trace a critical service to its applications, ICT third parties and evidence.

Give CISO, risk and architecture teams one auditable dependency view for critical ICT services, while regulatory accountability remains with the organization.

APM & Risk

Archilu for DORA is the APM & Risk story for regulated European organizations. It maps ICT assets, critical services, third parties, concentration paths, controls and evidence in an EU-hosted enterprise graph; it does not provide legal compliance or file the official register for you.

From €14,900/year

What is blocking the decision

Critical services, applications and third parties are listed but not connected.

Evidence is collected for audits without a durable lineage to the affected assets.

Concentration and ownership questions require manual reconciliation across teams.

What you see on Monday

One critical service traced to supporting applications and ICT providers.

Owners, controls and evidence linked to the assets they support.

A reproducible view of concentration and dependency paths for review.

Video script ready; recording pending

One critical service, one evidence chain

Trace a service through applications and an ICT third party to the control and evidence a reviewer asks for.

Recommended pack

APM & Risk

From €14,900/year

Application portfolio, lifecycle, licences, ICT third parties, critical dependencies and DORA-oriented evidence with unlimited users and EU hosting.

Questions buyers ask

What role does Archilu play in a DORA program?
It maps ICT assets, third parties, controls and evidence. Your organization remains responsible for its regulatory framework and obligations.
Does it generate the official Register of Information?
It provides dependency and third-party context that can support the register; no certified filing or official export is claimed unless contractually validated.
Can we see concentration risk?
Yes. Where the source data exists, the graph can show providers supporting multiple critical services and the paths involved.
Which plan contains this?
DORA is a buyer story within APM & Risk, not a separate SKU.

Technical note: typed graph relationships preserve architecture lineage beneath the control and evidence view; modelling notation stays out of the CISO workflow.

See your own context in the graph

Book a DORA-focused APM & Risk demo