Digital Operational Resilience Act
EU · RegulationRegister of Information, incident timelines, TLPT.
Compliance, made provable
One graph for every framework you answer to. Every score is a pure function your auditor can reproduce, line by line — EU-native, self-hostable, with national supervisory layers built in.
No account required for the gap report
What compliance officers ask for on day one
The platform
Select a capability. Watch what changes.
Not lists. A directed graph where every obligation knows its systems, its evidence and its blast radius.
1 graph · every dependency
The difference
The same inputs always produce the same posture. No model guesses between you and your auditor.
The library
Versioned, machine-readable requirement trees — not paraphrased prompts.
Digital Operational Resilience Act
EU · RegulationRegister of Information, incident timelines, TLPT.
Markets in Crypto-Assets
EU · RegulationCASP authorisation, whitepapers, prudential safeguards.
Network & Information Security 2
EU · DirectiveRisk management, reporting, supply-chain security.
General Data Protection Regulation
EU · RegulationLawful basis, DPIAs, breach notification.
Information Security Management
ISO · StandardAnnex A controls, Statement of Applicability.
Service Organization Control 2
AICPA · AttestationTrust services criteria, evidence over a period.
KMAG · BAIT
Germany · NationalCrypto-custody and IT-supervision specifics.
Austrian Financial Market Authority
Austria · NationalNational CASP supervision layer.
Autorité des marchés financiers
France · NationalFrench market-authority requirements.
Trust
Vellorum gives you a compliance posture. It also gives you every input, formula, and audit event that produced it — so you never have to ask your system to trust itself.
Same inputs, same output, always. The scoring engine is a pure function — injectable date, no global state, unit-tested at every boundary. Hover any number to see its derivation.
The AI assistant answers strictly from your workspace data. Every sentence carries an inline citation. No retrieval = no answer. Offline fallback produces the same structure without an API key.
Every mutation — status change, evidence upload, member action — writes an audit event. Your auditor reads the same history you do. Nothing is editable after the fact.
EU CASPs and banks cannot load compliance data into US-SaaS. Vellorum runs entirely on your infrastructure via docker-compose. No phone-home. Ed25519-signed offline license.
Our public demo stores the email you enter so we can follow up, plus your IP address solely to prevent abuse. Both are deleted automatically after 90 days, and all data stays within the EU.
Every number is a pure function of data + date. Hover any metric to see the exact formula. No model between you and your auditor.
EU CASPs cannot load compliance data into US-SaaS. Run Vellorum on-premise on docker-compose. Zero external dependencies required.
Public, no-login. Select your entity type, member state, services. Receive a regulator-style PDF with per-article gap citations.
Company
Not a quarterly panic. Vellorum exists to make regulatory posture something you can read off your infrastructure — at any moment, with proof.
Vellorum is built in Europe, for the European regulatory reality, by people who believe auditability is an engineering discipline.
MiCA fully applicable to crypto-asset service providers
DORA in force for the financial sector
Active supervision — regulators are requesting evidence now.
Tell us where compliance hurts. We respond within one business day. (CET)