Every vendor review of a small supplier comes down to the same two questions: can we trust the knowledge, and what happens if they disappear? This page answers both — by design, not by promise — and tells you honestly where the certificates stand.
The knowledge base covers 58 jurisdictions in 325 grey-zone cells — each researched against primary sources (statute, case law, administrative guidance, in the local language where required), then attacked by an independent reviewer whose only job was to break it. Zero hallucinated legal references across the base.
Every cell carries a content hash; reviewed status is bound to the exact version reviewed. If a cell changes, it automatically falls back to unreviewed until re-review — and client positions that relied on it are flagged. Trust is re-earned on every change, not granted once.
Independent local tax counsel review is part of the licence: for every jurisdiction your group brings into scope, local counsel is engaged to sign off that jurisdiction’s grey-zone material and validate new incoming guidance — recurring review, not a one-off stamp. And the calculation engine itself is verified against OECD’s published worked examples.
The sensitive core — your chosen positions, your risk profile — is never stored with the supplier at all. It lives in a local project file on your machine, version-anchored against the knowledge base. The intra-group flows layer works the same way: amounts live in your browser and your own file — only country pair and transaction type ever reach the server. There is no hostage scenario, because nothing is held.
Code and knowledge-base escrow arrangements are offered as part of the licence agreement, alongside documented handover material. The continuity question is answered in the contract you sign — where it belongs — not in a marketing claim.
Small supplier, one responsible person — we don’t pretend otherwise. What a serious buyer needs is a credible plan: escrow, documentation, your data in your hands, and a filing cycle that completes even in a worst case. That plan is on the table in every procurement conversation.
The vendor pack is the documentation set a vendor review actually asks for, shared under NDA: the ISMS documentation (policy, risk register, statement of applicability, incident and continuity planning), the escrow terms, the DORA Article 30 clause set, and the sub-processor list. Request it here — it goes out personally, like everything else.
A documented ISMS aligned to ISO/IEC 27001:2022 exists and is maintained: information security policy, risk register, statement of applicability, supplier register, incident and continuity planning. It distinguishes honestly between controls that are implemented and demonstrable today, and governance still being built out. The full documentation is available for your security review under NDA.
Two facts make the evaluation easier than most. First: the demo runs entirely on public data — annual reports already published, fiscal years already filed — so the inherent risk of a trial is low, and no certification gate applies to it. Second: the architecture itself minimises what there is to secure — the most sensitive data class, your positions, never reaches the supplier at all.
For financial-sector buyers: there is no such thing as a supplier-side “DORA certificate” — DORA regulates you, and flows down contractually. The licence is written to carry the Article 30 clauses your compliance team will ask for: audit rights, sub-processor disclosure, incident cooperation, exit and transition planning.
Document data is processed for the calculation. Your chosen positions — the sensitive part — are never stored with the supplier: they live in your local project file. The demo form itself collects only name, work email, company and role.
Less than you’d guess: at runtime, AI only reads documents — extraction on Google’s Gemini via Vertex AI in an EU region, cross-examined by two non-AI readings and approved by a human. The input is annual reports: figures already published or filed with authorities. The legal content is pre-reviewed, versioned material, the calculation is deterministic code — and group-specific hosting requirements are agreed per licence. The full AI ledger →
Yes — the ISMS documentation is shared under NDA, and a full security review is expected and welcomed before any production engagement with non-public data.
The ISMS is built against ISO/IEC 27001:2022 and the controls can be demonstrated today; formal certification is a planned step, not a current claim. We will never imply a certificate we don’t hold.
Licensed annually per group — a base fee plus a per-jurisdiction rate, so the price scales with your actual footprint. A single-jurisdiction group starts at €47,500 a year; a typical fourteen-jurisdiction group lands around €150,000. Every licence includes independent local counsel review of each jurisdiction’s knowledge base, contractual update SLAs, source and knowledge-base escrow, and unlimited users. Founding member terms are available for the first groups. Or compute your exact number yourself →