DORA Compliance Statement

(Cloud Services Provider)

Overview

As part of our commitment to maintaining the highest standards of digital operational resilience, Inflectra affirms that our cloud services are in compliance with the Digital Operational Resilience Act (DORA), as enacted by the European Union. DORA aims to strengthen the operational resilience of critical infrastructure within the financial sector, ensuring that entities are prepared to prevent, respond to, and recover from ICT-related incidents.

Key Areas of Compliance

ICT Risk Management
Inflectra has established a comprehensive ICT risk management framework that aligns with DORA requirements. This framework includes the identification, assessment, monitoring, and mitigation of risks related to information and communications technology (ICT) systems that may impact service continuity.

Incident Reporting
We maintain protocols for the timely detection, reporting, and management of ICT-related incidents. In line with DORA's provisions, we ensure that significant incidents are reported to competent authorities within the required timeframes, providing full transparency and details of the incidents, including potential impacts on our customers.

Third-Party Oversight
As a cloud service provider, we recognize the importance of third-party risk management. Our due diligence processes ensure that all subcontractors and third-party vendors who provide critical services meet DORA's regulatory requirements. We continually assess third-party contracts and ensure that they are in line with the legislation’s standards for resilience.

Operational Resilience and Recovery
Our cloud infrastructure is designed to provide continuous service availability. We have implemented robust business continuity and disaster recovery plans, ensuring that our services remain operational during and after an incident. These plans are regularly tested and updated in compliance with DORA's operational resilience standards.

Data Protection and Security
We adhere to stringent security protocols to protect the integrity, availability, and confidentiality of our clients' data. This includes data encryption, access control, and the adoption of industry-standard security practices in alignment with DORA’s provisions on data protection and digital operational resilience.

Governance and Compliance Monitoring
Inflectra has a dedicated compliance team that ensures continuous monitoring of all DORA-related requirements. Our governance framework is designed to provide accountability and oversight of ICT resilience measures, and we work closely with regulatory bodies to ensure ongoing compliance.

Commitment to Continued Compliance

We are committed to ensuring that our cloud services remain fully compliant with DORA and to adapting our operational practices in response to any updates or changes to the regulation. Our teams continuously monitor and improve our digital resilience measures, and we are prepared to collaborate with regulators and stakeholders to further strengthen the resilience of our services.

If you have any questions or require further details about our compliance with the Digital Operational Resilience Act, please contact us using the online form.