ServicesCase studiesAbout usLet's talk
Case study · Regtech · SaaS · Financial services

From Excel cycles to provable resilience.

DORApp is the platform we built for European financial institutions wrestling with the EU's Digital Operational Resilience Act. Continuous controls, automated regulatory reporting, an audit trail for every change — and the move from "compliant on paper" to provably resilient in practice.

DORAppby HoliSentra · a U-centrix venture
Live · EU-wide
Sector
Banking · Insurance · Regtech
Reach
27 EU countries
Active clients
30+
Pricing
from €200/user/month
Stack
SaaS · EU cloud · XBRL · LEI enrichment · MFA · ISO 27001
30+
institutions across Slovenia & Germany
€100K
first-year revenue — market validated
27
EU countries · regulator-ready filings
24h
DORA incident notification SLA met
DORAppDASHBOARDROIRISKINCIDENTSDORASSISTANTREPORTSMVM. VatovecDORA COMPLIANCE SCORE● LIVE94%AUDIT-READYRoI completeness98%Risk assessments87%REGISTER OF INFORMATIONXBRL · READYPROVIDERLEICRITICALITYSTATUSAmazon Web Services EMEA5493007V8M2T8X…CRITICALMicrosoft Azure Ireland635400AKJBGNS5…CRITICALCloudflare Inc.5493004UCASNGUK…IMPORTANTDatadog EMEA Ltd894500H7C0R7H6…IMPORTANTSendGrid (Twilio Inc.)549300LFGKAEELE…SUPPORTSHOWING 5 OF 47 ENTRIES · ENRICHED FROM LEI DB↓ EXPORT XBRLOPEN INCIDENTS2/ 47 closed YTD1 IN 24H1 IN 72HNEXT FILINGRoI Q1 · 2026in 18 days · on track✦ DORASSISTANT3 new contracts readyto import into RoIREVIEW →INCIDENT REPORTING TIMELINE · DORA SLA● ALL ON TIMEDETECTIONT+0Incident #2026-01414 Mar · 08:42 CETINITIAL NOTIFICATIONT+ 22h 14m · 1h 46m UNDER SLASubmitted to AJPESXML · auto-validatedINTERMEDIATE REPORTT+ 68h · ON TIMEStatus update filedroot cause confirmed!FINAL REPORT DUET+ 1 month · in 11 daysDRAFT · 64% completeassigned · M. Vatovec
Forbes Slovenija
— Business · 03 May 2026 —
"Finančnike zaradi novih pravil boli glava. Mariborčani v njih vidijo priložnost."
By Marko Rabuza·5 min read

New European rules on digital resilience created a major challenge for financial institutions — and a Maribor-based company saw an opportunity to develop a dedicated application for easier reporting to European institutions.

"Companies previously treated risk and compliance in annual cycles. DORA requires continuous monitoring — something companies must control every day."

The article identifies Joachim Heidebrecht, Matevž Rostaher, and Uroš Orešič as the people behind DORApp, the platform now used by more than 30 financial institutions across Slovenia and Germany.

forbes.n1info.si · DORApp · regtech
PressForbes Slovenija · 3 May 2026

"A Maribor-based company saw an opportunity where everyone else saw a regulatory headache."

"DORApp is not a tool for intrusion scanning or technical security testing — it's a GRC tool for management-level monitoring, analysis, and decision-making. The real competitor isn't another platform. It's Excel."
Read the full Forbes article

The end of checkbox compliance.

DORA created a major shift for European banks, insurers, and investment firms — they have to understand and control their digital dependencies, ICT third-party providers, risks, incidents, and evidence trails. Annual spreadsheets don't cut it any more.

The original push came from a German insurance association that recognised how difficult it would be to maintain accurate, up-to-date DORA records with Excel or generic GRC tools. We built DORApp as the answer — a cloud-based platform that moves institutions from "checkbox compliance" to "provable resilience", with traceable workflows, approvals, data quality controls, and audit-ready records.

It's modular. An institution can start with the most urgent pain point — usually the Register of Information — and expand into risk management, incident reporting, and AI-assisted contract review as they grow into the regulation. Each module works independently. Together, they create automation, consistency, and an audit trail nobody else has to maintain by hand.

One platform, six critical pillars.

DORApp covers every DORA pillar through interconnected modules. Pick what you need now, add the rest as you go.

REGISTER OF INFORMATION↓ EXPORT XBRLLEI ENRICHMENT · 47 / 47VALIDATION✓ ALL 47 PASSPROVIDERLEITIERVALIDAWS EMEA5493007V8M2T8XC2N5T7TIER 1Microsoft Azure635400AKJBGNS5WNQL34TIER 1Cloudflare Inc.5493004UCASNGUKKLW21TIER 2Datadog EMEA894500H7C0R7H6WKQU07TIER 2SendGrid (Twilio)549300LFGKAEELE6T8X4TIER 3Atlassian B.V.724500EBQEDMYNX17B58TIER 3
— Module 01

Register of Information (RoI).

Keeps your RoI always up to date, validated, and regulator-ready — eliminating spreadsheets and fragmented data, fully aligned with DORA requirements.

  • Import from Excel, CSV, XBRL, RMM or contract management systems
  • Manage all ICT third-party providers, contracts and key details
  • Auto-enrich from public sources (LEI database) to fill gaps and confirm accuracy
  • Validate against ESA rules automatically
  • Generate fully compliant reports with one click
ICT THIRD-PARTY RISKQ1 · 2026RISK HEATMAP · IMPACT × LIKELIHOODVHHMLVLVLLMHVH32712QUESTIONNAIRES SENT · Q1AWS EMEA100%Microsoft Azure100%Cloudflare Inc.72%Datadog EMEA38% · OVERDUE
— Module 02

Third-Party Risk & Questionnaire Automation.

Identify, evaluate, and track third-party risks in one place — fully aligned with DORA's risk management framework. Achieve complete automatic ICT supply chain oversight and stop validating LEI by hand.

  • Send and manage questionnaires automatically
  • Collaborate with ICT third-party providers
  • Assess third-party risks and compliance
  • Business impact analysis (BIA) for critical services
  • Assign tasks, set deadlines, monitor progress
  • Periodic review reminders built-in
INCIDENT #2026-014SEV 2 · OPENCloud provider outage — payment gatewayPROVIDER · STRIPE PAYMENTS EU · DETECTED 14·MAR · 08:42 CETDORA REPORTING TIMELINEDETECTEDT+0INITIAL · 24HFILED · T+22hINTERMEDIATE · 72HFILED · T+68h!FINAL · 1 MODUE · 11DASSIGNEEMVM. VatovecCISOROOT CAUSEDNS misrouteCONFIRMED · 72hREPORT · AUTO-GENERATEDXML · Schema validated↓ SUBMITTED TO AJPES
— Module 03

Incident Management & Reporting.

A straight path to capture, track, and report ICT-related incidents — fully aligned with DORA's strict timelines and formats.

  • Log incidents in real time, categorize and track status until resolution
  • Generate regulator-ready reports (initial notifications, follow-ups, final summaries)
  • Meet DORA timelines (24h, 72h, 1-month reporting)
  • Assign tasks and monitor accountability
RISK MANAGEMENT & GOVERNANCEPOLICIES & CONTROLSICT Security PolicyDONEBusiness Continuity PlanDRAFTIncident Response ProcedureDONEGOVERNANCE DASHBOARDAUDIT READINESS94%OPEN TASKS3 pending approval
— Module 04

Risk Management & Governance.

Create transparency across all DORA compliance activities. Document policies, assign responsibilities, and keep evidence ready for audits and supervisory reviews.

  • Document and monitor policies, processes, risks, assets, controls and projects
  • Assign responsibilities and approvals
  • Support governance bodies with dashboards
  • Keep evidence ready for audits and supervisory reviews
ICT RESILIENCE TESTINGTEST PLAN · Q1 2026Penetration Test — External perimeterCOMPLETED · 14 Mar · findings: 2 medium, 0 critical!BCP Walkthrough — Payment systemsIN PROGRESS · remediation assigned · M. VatovecTLPT — Threat-led penetration testPLANNED · Q2 2026 · DORA Art. 26OPEN FINDINGS2 mediumAUDIT EVIDENCEReady
— Module 05

ICT Resilience Testing.

Document ICT resilience testing, findings, and corrective actions — keeping complete audit-ready evidence for every test cycle.

  • Plan and record ICT tests
  • Capture findings and weaknesses
  • Assign remediation actions
  • Track closure and acceptance
  • Maintain audit-ready evidence
✦ DORASSISTANT · AI AGENTONLINEDoes our AWS contract include DORA audit rights?DORASSISTANTanalysed in 0.8sYes. Article 14.2 grants audit accesswith 30 days notice. DORA-compliant ✓AWS-EMEA-§14.2RTS 2024/41Want me to enter this contract into the RoI as a Tier-1 critical provider?Yes, add itShow me more
— Module 06

DORAssistant — AI agent.

DORAssistant is our AI agent, designed specifically around clients' needs in the field. It's like having a compliance expert by your side: instant answers, guided data entry, and automated reporting.

  • Reviews contracts for DORA compliance in seconds
  • Independently enters contracts into the RoI
  • Answers DORA questions in the context of your institution
  • Guided data entry and automated reporting

Between the institution and the regulator.

DORApp sits as the single source of truth between financial institutions and the European supervisory authorities — automating the flow of evidence, registers, and incident reports both ways.

— DORApp system architecture · regulatory data flow —
FINANCIAL INSTITUTIONSBanksDBS, KIELER RÜCK + 10InsurersMERKUR, VIGO, UELZENER + 8Investment firmsCROWDFUNDING · CASPS30+ ENTITIESSLOVENIA · GERMANY · LATVIADORAppCLOUD · EU-HOSTEDROIREGISTERRISK+ BIAINCIDENTS24/72/1MO✦ AI AGENTDORASSISTANTISO 27001 · GDPR · MFAIMMUTABLE AUDIT TRAILEU SUPERVISORY AUTHORITIESESAsEBA · EIOPA · ESMANational authoritiesAJPES · BAFIN · FMALGLEIF · LEI databasePUBLIC ENRICHMENTXBRL · XML · XLSX27 EU · ONE-CLICK FILINGCONTRACTSRISK DATAINCIDENTSXBRL FILINGSSLA REPORTSLEI ENRICHMENTData inbound · institutions feed DORAppReports outbound · regulator-ready in one clickPublic data · LEI enrichment
30+
Institutions
Slovenian banks, German insurers, Latvian investment firms — and growing.
27
EU countries
Guaranteed regulator-ready filings across the full EU footprint.
€100K
Year-1 revenue
Market validation in the conservative financial-services buyer base.
100%
SLA met
Every DORA incident report filed inside the 24h / 72h / 1-month window.

Confidence in compliance, without the complexity.

Built for compliance officers who can't afford a missed deadline — and for boards who need to see resilience, not paperwork.

— 01

Compliance, guaranteed.

With a few clicks DORApp generates regulator-ready reports in XBRL, XML, XLSX, or other mandated formats — validated against official taxonomies and guaranteed to be accepted by national and EU authorities.

— 02

Smarter data entry, auto-enriched.

An intuitive web interface with built-in validation. The platform automatically enriches records with verified data from public sources like the LEI database — minimal manual effort, maximum accuracy.

— 03

Proactive risk management.

Step-by-step risk assessments, business impact analyses, and mitigation planning — with reminders for scheduled reviews. Risks stay tracked, updated, and linked to controls.

— 04

Stress-free incident reporting.

Structured workflows for logging, classification, and escalation. Auto-generated regulator-ready incident reports tracked through to resolution — DORA's 24h, 72h, and 1-month deadlines met without overtime.

What clients actually say.

Three customers, three countries, one consistent message: the support behind the platform matters as much as the platform itself.

"
★★★★★
"We've had an absolutely fantastic experience with DORApp and the team behind it. DORApp is more than softwarethe team has proven time and again to be excellent professionals with deep knowledge of EU regulation. The support is stellar."
MV
Marko Vatovec
CISO · Deželna Banka Slovenije
🇸🇮 Slovenia
"
★★★★★
"I'm still thrilled. We were looking for a simple solution for the DORA Register of Information reporting. I doubted DORApp could be tailored so quickly to deliver such a polished result. Instead of creating a maintenance burden, DORApp is precisely what we needa streamlined reporting platform."
MS
Martin Steinbach
Head of IT · Kieler Rück
🇩🇪 Germany
"
★★★★★
"DORApp is an excellent solution for managing DORA RoI requirements — intuitive, transparent, clearly built with regulatory practitioners in mind. The fantastic support team is responsive, knowledgeable, and genuinely helpful throughout onboarding and day-to-day usage."
MS
Mihails Sutirins
CTO · Millifera Kartiera Limited
🇱🇻 Latvia

Be fully compliant, confident, transparent.

DORApp's promise to every institution: every requirement covered, every action logged, every report defendable.

— 01

Fully
compliant.

Every DORA requirement covered: Register of Information, risk management, incident reporting, outsourcing, audit trails — all in one place. EBA Guidelines on Outsourcing included.

— 02

Fully
confident.

Guaranteed compliance, validated reporting, complete oversight. DORApp gives compliance officers and boards peace of mind at every step — and a guarantee written down.

— 03

Fully
transparent.

Every action logged immutably, every risk monitored, every dashboard giving management and auditors instant visibility. Prove compliance at any moment, to any regulator.

Learn more about the product

See DORApp in action.

The full feature list, the live product tour, partner logos, the 14-day free trial, and the link to book a 45-minute demo with the team that built it — all at dorapp.eu.

dorapp.eu/dashboardDORA COMPLIANCE94%RoI completeness98%Risk assessments87%Incident SLA100%NEXT FILINGRoIQ1 · 2026DUE IN18dON TRACKDORApp by Holisentra● ALL SYSTEMS GREEN
— Let's talk —

Got a regulation that won't sit still?

A 30-minute call with our CEO or technical lead. No sales script, no obligation — just a real conversation about what you're trying to solve.

Book a call