FOR BANKS, INSURERS AND REGULATED INSTITUTIONS

The examiner does not ask whether the control exists. He asks whether it operated.

Evidence has become the deliverable. A register that has to be true about somebody else's company, an incident chronology written against a four-hour clock, a four-eyes decision that has to be reconstructable a decade later, a due-diligence assessment that has to be dated before the contract it justifies. Exedra Gate is one governed place where those records are produced by the work rather than assembled after the request.

A reviewer can confirm, with free standard tools, that the documents are unchanged and existed at the stated moment. The timestamp comes from an independent authority.

THE WORLD AS A REGULATED INSTITUTION MEETS IT

The dates are published. None of them are projections.

Digital operational resilience arrived as a regulation with a calendar, and the calendar has kept moving since. Each entry below is a fixed, published fact with its primary source attached.

Jurisdiction
United Arab Emirates

Showing rules for European Union

The argument on this page does not change with the selection. The citations do.

Every jurisdiction is shown below, grouped and labelled.

European Union

  • Operational resilience

    DORA applies. The Digital Operational Resilience Act binds financial entities across the Union, and has since 17 January 2025: banks, insurers, investment firms and their critical ICT providers, with incident reporting and resilience testing as supervised obligations.

    Regulation (EU) 2022/2554, Art. 64

    Source checked

  • Register of information

    The register of information has a fixed shape. Fifteen inter-linked templates form a relational model of every ICT contractual arrangement, reported at least yearly, and submitted as a structured report package rather than a document. Coded fields demand country, currency, legal-entity and service-type codes; free text is not accepted. The implementing regulation was published on 2 December 2024.

    Implementing Regulation (EU) 2024/2956; Art. 28(3) DORA

    Source checked

  • Register of information

    The dry run said what the difficulty is. On 17 December 2024 the European Supervisory Authorities ran the exercise with roughly one thousand financial entities. Against 116 data quality checks, 6.5% of submitted registers passed all of them, and half of the remainder failed fewer than five. The exercise was voluntary and best-effort, and the authorities described the result as in line with expectations.

    EBA; EIOPA key findings

    Source checked

  • Resilience testing

    Threat-led penetration testing became a rule, not a practice. Since 8 July 2025 identified entities test at least every three years, on live production systems, covering several or all critical or important functions, with the competent authority validating the scope.

    Delegated Regulation (EU) 2025/1190

    Source checked

  • Third-party risk

    Subcontracting has its own standard. Since 2 July 2025 what an entity must determine and assess when a provider subcontracts a service that supports a critical or important function is specified, which pushes the question one layer further down the chain.

    Delegated Regulation (EU) 2025/532

    Source checked

  • Third-party risk

    The register became an input to a decision with legal consequences. On 18 November 2025 the European Supervisory Authorities designated 19 critical ICT third-party providers for direct oversight, and the designation was fed by the aggregated register data submitted earlier that year.

    EIOPA

    Source checked

Germany

  • Operational resilience

    Germany widens the perimeter and retires the old rulebook. The Finanzmarktdigitalisierungsgesetz extends DORA to further institutions under the Kreditwesengesetz from 1 January 2027, and the supervisory IT circular it replaces is stated as fully repealed by 31 December 2026.

    BaFin

    Source checked

  • Supervisory access

    Supervision may demand information and conduct an audit expressly without special cause, and that power reaches the outsourcing companies holding material functions as well as the institution itself. It is the older standard underneath the DORA calendar, and it has not moved.

    § 44 KWG; § 25b KWG

    Source checked

  • Record retention

    Records are held for six, eight or ten years depending on their type. One statute, three retention lengths, which is the practical reason an institution cannot operate a single retention rule.

    § 257 HGB

    Source checked

  • Record integrity

    A booking may not be altered so that its original content is no longer ascertainable. Tamper-evidence stated as a statutory test: what the provision requires is that the original content remain ascertainable, not that alteration be impossible.

    § 146(4) AO

    Source checked

United Kingdom

United States

  • Books and records for advisers

    The clock runs from the last entry, not from the document. An investment adviser must keep the required books and records in an easily accessible place for not less than five years from the end of the fiscal year in which the last entry was made, the first two of those years in an appropriate office of the adviser.

    17 CFR 275.204-2(e)(1), Investment Advisers Act of 1940

    Source checked

  • Electronic records: the audit trail alternative

    The rule accepts an audit trail in place of immutability. A broker-dealer keeping records electronically may satisfy the rule either by preserving them in a non-rewriteable, non-erasable format or by maintaining a complete time-stamped audit trail of every modification and deletion, with the date and time and the identity of the person, sufficient to permit re-creation of the original record.

    17 CFR 240.17a-4(f)(2)(i)(A) and (B)

    Source checked

  • Anti-money-laundering records

    Five years, and accessible within a reasonable period. All records a financial institution is required to retain under the Bank Secrecy Act regulations must be kept for five years and stored so as to be accessible within a reasonable period of time.

    31 CFR 1010.430(d)

    Source checked

  • Anti-money-laundering records

    Where no record exists, one has to be made. Where no record of a transaction is made in the ordinary course of business, the institution must prepare one in writing, so the duty is to produce the record and not only to keep whatever happened to exist.

    31 CFR 1010.430(b)

    Source checked

  • Sanctions record duties

    Ten years, and it reaches parties that are not banks. Every person engaging in a transaction subject to the sanctions regulations must keep a full and accurate record of it, available for examination for at least ten years after the transaction, whether or not the transaction was licensed.

    31 CFR 501.601, Reporting, Procedures and Penalties Regulations

    Source checked

  • Electronic signature and admissibility

    The operative word is "solely". For a transaction in or affecting interstate or foreign commerce, a signature, contract or record may not be denied legal effect, validity or enforceability solely because it is in electronic form.

    15 U.S.C. 7001(a), Electronic Signatures in Global and National Commerce Act

    Source checked

  • Electronic records and retention

    Accuracy, accessibility and reproducibility are the three conditions. Where a law requires a record to be retained, an electronic record meets that requirement if it accurately reflects the information and remains accessible to those entitled to it, for the period the law requires, in a form capable of being accurately reproduced for later reference.

    15 U.S.C. 7001(d)(1)

    Source checked

  • Electronic records in evidence

    Self-authentication removes a witness, not an objection. A record generated by an electronic process that produces an accurate result, and data copied from an electronic device that is authenticated by a process of digital identification, are each self-authenticating on a certification by a qualified person, so no extrinsic evidence of authenticity is required to admit them.

    Federal Rules of Evidence, Rule 902(13) and Rule 902(14)

    Source checked

  • What happens to a record under investigation

    The offence reaches conduct before the subpoena arrives. Knowingly altering, destroying, concealing, falsifying or making a false entry in a record, with intent to impede or influence a federal investigation or the administration of a federal matter, carries up to twenty years, and the offence reaches conduct in contemplation of such a matter.

    18 U.S.C. 1519

    Source checked

  • Audit record retention

    The statutory duty sits on the accountant. An accountant auditing an issuer to which section 10A(a) of the Securities Exchange Act applies must keep all audit and review workpapers for five years from the end of the fiscal period in which the audit or review concluded.

    18 U.S.C. 1520(a)(1)

    Source checked

United Arab Emirates, onshore

  • AML record keeping

    The statute states the duty and defers the period. Financial institutions, designated non-financial businesses and professions and virtual asset service providers must retain all records, documents and data relating to transactions and make them immediately available to the competent authorities on request.

    Federal Decree-Law No. (10) of 2025, Article 19(1)(f)

    Source checked

  • AML record keeping

    The five years live in the Executive Regulations. Records, documents, instruments and data for domestic and international transactions and commercial dealings must be retained for not less than five years from completion of the transaction or the end of the business relationship.

    Cabinet Resolution No. (134) of 2025, Article 25(1)

    Source checked

  • AML record keeping

    The clock restarts on the most recent of several triggers. Customer due diligence records, account files, business correspondence and suspicious transaction reports run for not less than five years from the most recent of several triggers, so a later inspection, investigation or final judgment restarts the clock rather than the account closure alone.

    Cabinet Resolution No. (134) of 2025, Article 25(2)

    Source checked

  • AML record keeping

    Holding the documents is not the same as holding them usably. Retained records must be organised so that individual transactions can be reconstructed, so the duty is not merely to hold the documents but to hold them in a form that can be put back together years later.

    Cabinet Resolution No. (134) of 2025, Article 25(3)

    Source checked

  • Electronic signatures

    Equivalence attaches to the qualified tier only. Equivalence to a handwritten signature is attached to the qualified tier only: a Qualified Electronic Signature has the same legal effect as a manual signature where it meets the conditions in the Decree-Law and its Executive Regulations, and a signature below that tier does not carry that equivalence.

    Federal Decree-Law No. (46) of 2021, Article 18(3)

    Source checked

United Arab Emirates, DIFC

  • Data protection

    The duty is to comply and to be able to show it. A controller or processor must establish a programme to demonstrate compliance with the Law, and must implement appropriate technical and organisational measures to demonstrate that processing is performed in accordance with it, so the obligation is not only to comply but to be able to show it.

    Data Protection Law, DIFC Law No. 5 of 2020, Article 14(1) and 14(2)

    Source checked

  • Data protection

    The record of processing is itself a required document. A controller must maintain a written record of the processing activities under its responsibility, which may be in electronic form, covering at least the purposes, the categories of data subjects and personal data, the categories of recipients including those in Third Countries, and where possible the time limits for erasure.

    Data Protection Law, DIFC Law No. 5 of 2020, Article 15(1)

    Source checked

  • AML record keeping

    The duty catches the analysis that led to no report at all. A Relevant Person must maintain sufficient records of transactions to enable individual transactions to be reconstructed, together with the customer due diligence documents, the business correspondence relating to the customer’s account and its own internal findings and analysis on unusual or suspicious business.

    DFSA Rulebook, AML module, Rule 14.4.1(a) and (b)

    Source checked

  • AML record keeping

    Where the record sits is a decision with conditions attached. Where these records are kept outside the DIFC, the firm must take reasonable steps to ensure they are held in a manner consistent with the Rules, ensure they remain easily accessible to it, and ensure that on the DFSA’s request they are immediately available for inspection.

    DFSA Rulebook, AML module, Rule 14.4.3

    Source checked

United Arab Emirates, ADGM

  • Data protection

    The record has to exist and to be handed over on request. Each controller must maintain a record of the processing activities under its responsibility, the record must be in writing including in electronic form, and it must be made available to the Commissioner of Data Protection on request.

    Data Protection Regulations 2021, sections 28(1), 28(3) and 28(4)

    Source checked

  • Data protection

    Ongoing integrity, and a process for testing that it holds. Controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including the ability to ensure the ongoing integrity of processing systems and a process for regularly testing and evaluating whether those measures are effective.

    Data Protection Regulations 2021, sections 30(1)(b) and 30(1)(d)

    Source checked

  • AML record keeping

    The word in the rule is "immediately". A Relevant Person must maintain sufficient records of transactions to enable individual transactions to be reconstructed, and must immediately provide a copy of those records to the Regulator on request.

    ADGM Anti-Money Laundering and Sanctions Rulebook, Rules 4.5.1(b)(ii) and 4.5.2

    Source checked

  • AML record keeping

    The same conditions, from a second regulator in a second jurisdiction. Where these records are kept outside ADGM, the firm must take reasonable steps to ensure they are held consistently with the Rules, keep them easily accessible to itself, and ensure that on the Regulator’s request they are immediately available for inspection.

    ADGM Anti-Money Laundering and Sanctions Rulebook, Rule 4.5.5

    Source checked

  • Electronic records and signatures

    Electronic retention satisfies the enactment only on conditions. Where an ADGM enactment requires a record to be retained, an electronic record satisfies that requirement only if it stays accessible for subsequent reference, keeps its original format or one demonstrably replicating the original information, and retains the information identifying the record’s origin, destination, the parties who sent or received it and the date and time.

    Electronic Transactions Regulations 2021, section 4(1)

    Source checked

Singapore

  • Data protection

    This clock runs the other way: it is a duty to stop. An organisation must cease to retain documents containing personal data, or remove the means of associating that data with particular individuals, as soon as it is reasonable to assume that the collection purpose is no longer served and retention is no longer necessary for legal or business purposes.

    Personal Data Protection Act 2012, section 25

    Source checked

  • Data protection

    Modification is named alongside access. An organisation must make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal of the personal data in its possession or under its control.

    Personal Data Protection Act 2012, section 24

    Source checked

  • Data protection

    A refusal creates a preservation duty. Where an organisation refuses an individual’s request for access to their personal data, it must preserve a complete and accurate copy of that data for not less than the prescribed period.

    Personal Data Protection Act 2012, section 22A(1) and (2)

    Source checked

  • AML record keeping

    The record has to support reconstruction of the transaction. A bank must prepare, maintain and retain records of the data, documents and information the Notice requires, and must do so such that any individual transaction it undertook can be reconstructed, including the amount and type of currency involved.

    MAS Notice 626, paragraphs 12.1 and 12.2(b)

    Source checked

  • AML record keeping

    Five years is a floor an investigation displaces. A bank must retain customer due diligence information, account files, business correspondence and the results of any analysis for at least five years after the business relations end, and transaction records, including whatever is needed to explain and reconstruct the transaction, for at least five years after the transaction completes.

    MAS Notice 626, paragraphs 12.3(a) and 12.3(b)

    Source checked

  • AML record keeping

    The electronic form is open, conditional on admissibility. A bank may keep these records as originals or copies, on paper, in electronic form or on microfilm, provided they are admissible as evidence in a Singapore court of law.

    MAS Notice 626, paragraph 12.4

    Source checked

Canada

  • AML record keeping

    The duty is to be able to hand it over, on a clock. Every record required to be kept under the Regulations must be kept in such a way that it can be provided to an authorised person within 30 days after a request to examine it is made.

    Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, SOR/2002-184, section 149

    Source checked

  • AML record keeping

    One figure hides three different start dates. Records required under the Regulations must be kept for at least five years, running from account closure for account records, from the last business transaction for records proving an entity’s existence, and from the day of creation for all other records.

    Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, SOR/2002-184, section 148(1)

    Source checked

  • AML record keeping

    Electronic retention is conditional on producing paper. A record required under the Regulations may be kept in machine-readable or electronic form only if a paper copy can readily be produced from it.

    Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, SOR/2002-184, section 147

    Source checked

  • Data protection

    The modal verbs differ inside one clause. Personal information used to make a decision about an individual must be retained long enough to allow that individual access to it after the decision has been made, and information no longer required for the identified purposes should be destroyed, erased or made anonymous.

    Personal Information Protection and Electronic Documents Act, Schedule 1, clauses 4.5.2 and 4.5.3

    Source checked

  • Data protection

    The safeguards follow the information into any format. Security safeguards must protect personal information against loss or theft and against unauthorised access, disclosure, copying, use or modification, regardless of the format in which it is held.

    Personal Information Protection and Electronic Documents Act, Schedule 1, clause 4.7.1

    Source checked

  • Electronic records and signatures

    Part 2 reaches requirements under federal law. A requirement under federal law to retain a document for a specified period is satisfied by an electronic document only if it is kept for that period in the format in which it was made, sent or received, or in a format that does not change the information, if it stays readable to those entitled to it, and if the information identifying its origin, destination and the date and time it was sent or received is retained too.

    Personal Information Protection and Electronic Documents Act, section 37

    Source checked

  • Electronic records and signatures

    Three cumulative conditions, and a defined term. Where federal law requires a document in its original form, an electronic document satisfies that requirement only where the provision is listed in Schedule 2 or 3, the regulations are complied with, and the document carries a secure electronic signature added when it was first generated in its final form which can be used to verify that it has not been changed since.

    Personal Information Protection and Electronic Documents Act, section 42

    Source checked

Ledger entries are published in English only, and cite each instrument by its own official name.

One exercise, in the European Union

Shown as an example of what assembling this evidence costs, rather than as a duty on any reader. It does not change with the jurisdiction selected above, and every reader is shown it.

The 2024 dry run, as reported
of submitted registers passed every check
6.5%
data quality checks applied
116

Roughly one thousand financial entities took part. Exactly as the European Supervisory Authorities reported it, with the caveats attached: the exercise was voluntary and best-effort, and the authorities described the result as in line with expectations (EBA; EIOPA key findings).

The enforcement record behind these calendars, statute by statute and figure by figure, is kept on its own page. The risk, sourced.

WHERE IT GOES WRONG

Six situations, named precisely. Every one of them is an evidence problem.

The register that has to be true about somebody else

The templates want the provider's legal identifier, legal name, country and provider type; the contract's start and end dates, notice periods, governing law and annual cost; the service type against a fixed taxonomy with its service-level objectives; the functions supported, the assets involved and the data classification; and, where a critical or important function is in scope, the full subcontractor chain. None of that data is generated inside the institution. It is chased, by email, from every vendor, once a year, and it is graded on referential integrity rather than on effort.

The four-hour clock, and the question that follows it

An initial notification is due within four hours of classification as major, and no later than twenty-four hours from becoming aware. An intermediate report follows at the latest seventy-two hours after that, and a final report no later than one month after the intermediate one (Art. 5, Delegated Regulation (EU) 2025/301). The submission is rarely the hard part. The hard part arrives afterwards, when somebody asks when the institution knew what, who classified it, and on what basis, and the answer lives in a ticketing system whose entries can be edited.

The assessment that must be dated before the signature

A documented assessment of criticality, supervisory conditions, risk and conflicts of interest has to precede the contract it justifies (Art. 28(4) DORA). Ordering is the whole point of the obligation, and a file modification date on a shared drive is a weaker answer to it than most institutions realise, because that date describes the file's last write rather than its first.

The four eyes that have to be reconstructable

A decision was approved by two named people, against a specific document, under the policy version in force at that time. Ten years later the policy has been rewritten twice, the approval workflow has been migrated to a different platform, and both approvers have left. The decision was correct. What is missing is the ability to show it, in the shape the question is asked in.

The retention period that outlives the system of record

Six to ten years is longer than most platforms survive inside an institution. The migration is planned, competent and lossy in exactly one respect: the exported record arrives in the new system with the new system's dates on it. Nothing was falsified. The provenance simply did not travel.

The standing criticism: controls on paper

German supervisory practice returns repeatedly to purely paper-based controls without actual implementation, and the recommended answer is documented evidence that the control ran: protocols, testing, training, effectiveness measurement, issue management. That is not a documentation problem. It is a question about what the institution can attribute and date.

WHY THE CURRENT ANSWER FAILS

The governance suite says "audit trail". The examiner asks who could have changed it.

Every governance platform in this market records activity, and every one of those records is attested by the vendor that produced it and mutable by an administrator inside it. In ordinary operation that is unremarkable. In an inspection it is the difference between a record and an assertion, and it is the reason a supervisor's question so often turns into a conversation about the tool rather than about the control.

Around the suite, the evidence is scattered by construction. The register data sits in spreadsheets: a survey of roughly one hundred German financial institutions found nearly half still relying on them for DORA work (KPMG). Vendor attestations arrive as email attachments. Incident chronologies live in a ticketing system, four-eyes approvals in a workflow tool, the contracts themselves in a third repository, and the covering correspondence in mailboxes. Each system keeps its own clock and its own retention period, and the joint between them is where the proof is supposed to be.

The industry knows which of these hurts most. In a March 2025 survey of financial entities, 46% named the register of information as the single most challenging DORA requirement, and 8% considered themselves fully compliant on third-party risk (Deloitte, DORA Survey for Financial Services Entities, Wave 3, March 2025; 36 entities across 28 countries).

The joint, not the tool
The failure is not that any one system is bad. It is that the answer to a supervisory question has to be composed from five of them by hand, under a deadline, by people who were not there when the events happened. A composed answer is slower, and it invites the second question: how does anyone know this is what the file said at the time.
A CLOSED ROOM

A governed place where the record is a byproduct of the decision.

On Exedra Gate the work that generates evidence happens inside the system rather than around it. Identity, documents, contracts, signatures, approvals, deadlines and the correspondence that carries them run in one flow, and each step becomes an entry as it happens: sent, opened, read, signed and independently timestamped. Nobody writes the protocol afterwards.

Read against the six situations above: a four-eyes approval is signed by two named people against a specific document fingerprint under a stated policy version, and the entry carries all four facts rather than pointing at them. An incident chronology accumulates while the incident is running, each entry chained to the one before it, so the question of when the institution knew what has a dated answer instead of a reconstruction. A pre-contractual assessment is signed at the moment it is completed, which is what makes it demonstrably earlier than the contract. And a vendor evidence request is answered from the room rather than from a mailbox: what the vendor stated, on what date, over which signature.

Exedra Gate is itself an ICT third-party service provider when a financial entity relies on it, and it is written that way. The contractual terms that reach a provider through Art. 30 DORA, including the rights of access, inspection and audit for the institution, its appointed third party and the competent authority, land on Exedra Gate as they land on any other vendor. The vendor-side facts an institution needs for its own register are supplied by Exedra Gate about Exedra Gate, dated and under signature, rather than reconstructed from a sales email.

The signature on every entry carries a timestamp issued under RFC 3161 by an authority that is not Exedra Gate. That is the whole of the integrity claim, and it is deliberately narrow: it says the documents are unchanged and existed at the stated moment, and it says nothing about whether they satisfy a rule.

One check, reproducible years later

A document is fingerprinted, the fingerprints are chained and signed, and the record carries a timestamp from an independent authority. Years later, a different reviewer runs the same check with free standard tools and confirms the documents are unchanged and existed at that moment.

The claim is narrow and checkable: a reviewer confirms with free standard tools that the documents are unchanged and existed at that moment, because the timestamp comes from an authority that is not Exedra Gate, issued under RFC 3161. Whether a record satisfies a particular legal standard remains a question for counsel, and the chain is tamper-evident rather than tamper-proof.
What the record covers, and what it does not

Two labelled regions. Inside the record: documents and their fingerprints, identity checks, signatures and their signers, approvals with the policy version in force, accesses to the document room, dated chronologies, and the independent timestamp on every entry. Outside it, stated as excluded: supervisory returns are not calculated or submitted, the register of information's report package is not generated, transaction monitoring and sanctions decisioning are not performed, and no judgment is made about whether a record satisfies a legal standard.

The exclusions are a product decision, not a caveat. Calculation and submission belong to the reporting vendors that own them, and the fines attach to the filing. What is missing from that market is the layer underneath: a dated, attributable, independently timestamped record of what was decided, by whom, on which evidence.

The evidence pack is the flight recorder.

Nobody thinks about it while the work is going well; then something goes wrong, and it is the only thing that matters. Each engagement closes into one evidence pack: every document, identity check, signature and access, in order, each entry fingerprinted and chained to the one before it. It is handed over rather than assembled, and it reads the same whichever entity is asked.

SOVEREIGNTY

One rail across every entity, standing where the mandate says it stands.

A regulator may decide where an institution's data lives, and a group may hold a dozen entities across four jurisdictions with no single place where the record of any of it sits. On Exedra Gate every entity in stewardship runs the same process. Workspaces are held side by side and switched deliberately; nothing blends between entities. And when anyone asks, an auditor, an acquirer, a supervisor or opposing counsel, the answer has one shape: the same evidence export, from every entity, checkable on their own machine with free standard tools.

The same platform. Three boundaries.

Three deployment models, drawn side by side, each containing the identical platform rail ending in the same signed close. Managed: the platform runs inside a cloud boundary Exedra Gate operates. Private: the same platform inside the client's own cloud boundary, with the client's keys on the boundary. Sovereign: the same platform and the same keys, enclosed by a further boundary drawn around the client's jurisdiction, single-tenant inside the country the client chooses.

MANAGED

Exedra Gate's cloud

Exedra Gate runs and operates the platform. Counterparties onboard from the first day, with nothing to host.

PRIVATE

The client's cloud

Deployed into the institution's own infrastructure, under its keys and its security controls, with Exedra Gate's support behind it.

SOVEREIGN

The client's country

Single-tenant inside the chosen jurisdiction, for data-residency rules and government mandates.

A dedicated deployment is scoped, quoted and delivered as an implementation engagement rather than configured from a self-serve setting: residency in the jurisdiction the engagement specifies, deployment into the infrastructure the client provides, the client's keys and the client's security controls. Custom features are built on request for clients who need them, on the same terms.

What will not be done, in writing
No share of any raise and no success fee, ever; Exedra Gate sells software. Client and investor funds never touch Exedra Gate; money moves between the parties and their licensed institutions. Deals are not recommended to investors and not ranked; the entity publishes, the investor decides. No trading, no custody, no settlement; those are licensed activities performed by licensed venues.

These are deployment models Exedra Gate offers. No client is named, and nothing here suggests that any authority uses, approves or endorses the platform. If that ever changes, it will be because someone has said so in writing and agreed to be quoted. No certification against SOC 2 or ISO 27001 is claimed; the control set and its readiness status are stated in full on the security page.

WHAT IT LOOKS LIKE IN PRACTICE

Which parts the institution touches, and in what order.

Adoption in a regulated institution starts at the edge, where the evidence is already being demanded and nobody owns the joint. It moves inward only as far as it earns.

  • FIRST

    The vendor evidence room. Exedra Gate supplies the facts about itself that the institution's own register needs, dated and under signature, together with the contractual terms it has accepted. The first piece of evidence the platform produces is evidence about the platform.

  • THEN

    The request workspace. An audit or supervisory request list becomes a room: each item bound to the artefact that answers it, each artefact carrying its own fingerprint and date, with what is outstanding visible rather than tracked in a side spreadsheet.

  • THEN

    Decisions and approvals. Four-eyes approvals are signed inside the room against a document fingerprint and a stated policy version, on the phone where that is more practical than a desk.

  • THEN

    Chronologies. An incident, a remediation or a change accumulates entries while it is running, in the order they arrived, each chained to the last.

  • THEN

    Obligations and their proof. Each recurring duty carries its deadline and the artefact that answers it, in the calendars the institution already uses.

  • WHEN ASKED

    The export. One evidence pack per entity, in one shape, handed over rather than assembled, and checked by the reviewer on his own machine with free standard tools.

The compliance rail is live in production today. The mobile app is arriving and is named as arriving wherever it appears. What runs today, in full.

THE CLOSE

Time will show who was prepared.

The rules are published and the calendars are fixed. The questions arrive on their own schedule, usually about work done years earlier, and they are answered from records or from memory. An institution that prepares answers in days rather than weeks. Exedra Gate exists for it.

Deployment, residency and branding are scoped per engagement, not configured from a self-serve form. A short note on the mandate and what it requires is enough to begin.

Exedra Gate is a technology platform, not a broker, dealer, custodian, escrow provider, or investment adviser. It never holds, routes, or settles investor funds, does not recommend offerings to investors, and charges no success-based fees on raises. Records and timestamps attest integrity and existence as of a date, not compliance with any particular regime; that judgment remains with the institution and its counsel.

Regulatory references on this page are orientation, not legal advice: see Sources & verification.