DORA

Regulation (EU) 2022/2554 (DORA) applies to financial entities and to the ICT third-party service providers those entities depend on. If your firm falls within DORA scope and you use Ithura as an ICT service, this guide covers the third-party-risk answers your risk register will need.

Where Ithura fits in DORA's terminology

  • ICT service (Art. 3(21)). Ithura is a work-management ICT service.
  • ICT third-party service provider (Art. 3(19)). Anorph is your ICT third-party service provider when you use the managed Ithura Cloud. On a self-hosted install you are your own ICT service provider; Ithura is the software supplier.
  • Critical or important function (Art. 3(22)). Whether the workspace supports a CIF is your assessment. The typical Ithura workspace supports the CIF of change management, incident post-mortem, or roadmap governance, not the CIF itself.

Register of information (Art. 28(3))

Fields typically requested for the DORA Register of Information for Ithura Cloud:

FieldValue
Provider nameAnorph B.V.
Provider LEIOn request
Country of registrationNetherlands
Service typeSoftware as a service (managed work-management platform)
Service descriptionMulti-workspace project, task, sprint, wiki, and audio/video huddle platform
Data locationEuropean Union (Netherlands)
Sub-contractors usedStripe (Ireland), Google Ireland (SMTP relay). Documented in the GDPR sub-processor list
Data types processedBusiness documents, project metadata, user identity for authentication, audit metadata
Encryption in transitTLS 1.2+
Encryption at restFull-disk encryption on all volumes; secrets AES-256-GCM at column level
AuthenticationPassword + TOTP 2FA, or SAML 2.0 SSO, or Google/GitHub OAuth
SubstitutabilityHigh. See "Exit and substitutability" below
Contract termMonth-to-month or annual

For self-hosted, the register entry names your infrastructure provider (the cloud or the on-prem team) as the ICT third-party. Ithura is a software supplier only.

Contractual arrangements (Art. 30)

The DPA template covers Article 28 of GDPR; for DORA Article 30, the following clauses are supported by Ithura's architecture and can be committed to in a service agreement:

  • Full description of the service and locations where data is processed. See data residency.
  • Assistance in incident response including timely notification and cooperation with the competent authority.
  • Right of the financial entity to access, inspect, and audit the service provider. For self-hosted this is a non-event (you already have full access). For Ithura Cloud, a right-of-audit clause is available in the enterprise contract.
  • Cooperation with competent authorities. Ithura commits to providing requested documentation to the financial entity for onward supply to a competent authority within a reasonable timeframe.
  • Termination rights and assistance during exit to another provider or bring-in-house. See "Exit and substitutability" below.
  • Service levels for availability, response, and recovery. Ithura Cloud publishes these in the master service agreement; self-hosted service levels are your responsibility (you operate it).

Incident reporting (Art. 17-19)

  • Notification of major ICT-related incidents. Anorph commits to notifying affected controllers of a major ICT incident affecting Ithura Cloud without undue delay and in any event within the tightest applicable window (currently 24 hours for initial notification, four hours in cases involving fraud or personal-data breaches with an additional 72-hour follow-up per Article 33 GDPR).
  • Classification cooperation. On request, Anorph will provide the technical detail needed for the financial entity to classify the incident under DORA's severity criteria.
  • Post-incident review artefacts. Anorph will provide root-cause analysis and remediation plan on request after resolution.

For self-hosted, incident classification and reporting are entirely on you. Ithura provides the audit log and metrics endpoint as your primary data sources.

Digital operational resilience testing (Art. 24-26)

  • Threat-led penetration testing (TLPT). Financial entities in scope for TLPT may test Ithura Cloud with prior coordination. Contact for scope-of-testing and RoE is defined in the master agreement.
  • On self-hosted installs, the entire deployment is yours; test freely.
  • Vulnerability disclosure. Report privately to security@ithura.com. We accept independent penetration-test findings from any customer.

Exit and substitutability (Art. 28(8), Art. 30(3))

DORA specifically requires that reliance on ICT services be substitutable without disproportionate impact. Ithura's architecture is designed with this in mind.

  • Data extractability. Every entity (issues, projects, sprints, wiki, boards, comments, activity, audit log) is reachable via the JSON API with an admin token. The Workspace File export (planned) produces a portable SQLite bundle that a competing tool or a bespoke script can consume.
  • Open protocols. Every backing service (Postgres, S3-compatible storage, Redis-protocol cache) is open and multi-vendor. There is no bespoke storage format that another vendor would have to reverse engineer.
  • Portable deployment. The reference deployment is Docker Compose or a Kubernetes Helm chart, both of which run on any DORA-eligible cloud or on-prem infrastructure without modification.
  • Exit assistance. On termination of an Ithura Cloud contract, Anorph provides a full export of the workspace on request and retains data for a further 90 days to support the migration. For self-hosted, exit means turning the software off; the data was already on your infrastructure.

Concentration risk

  • Single-provider concentration. Ithura Cloud sits on Anorph infrastructure. If your risk register requires the ICT service to sit on a different provider, self-hosting on your chosen provider is the answer. The software is identical.
  • Multi-region. Not part of the packaged Ithura Cloud offering today. If you require active-active across regions, self-host with a Postgres-replication topology of your choice.

Register-of-information change log

Any change to the sub-processor list, data-location, or encryption posture is announced with 30 days' notice to Ithura Cloud customers by email and via an entry in data residency.