Centrum zgodności danych
One place for the frameworks, data-handling practices, and documentation that clients and auditors most often ask us for.
What we're aligned to
GDPR
Our own processing activities, and the advisory work we do for clients, are built around GDPR principles and data subject rights.
NIS2
Incident classification, reporting timelines, and resilience requirements under the NIS2 Directive and its Lithuanian transposition.
DORA
ICT risk management and third-party oversight for financial-sector clients under the Digital Operational Resilience Act.
ISO 27001 / EU AI Act
Information security management aligned to ISO 27001, and AI system risk classification aligned to the EU AI Act and ISO 42001.
Where your data lives
Client data is hosted primarily within the EU. Where processing occurs outside the EEA — for example through CYBORA LLC in the United States — it is covered by appropriate safeguards such as Standard Contractual Clauses. Full details are available under a signed NDA or Data Processing Agreement.
What you can ask us for
Data Processing Agreement (DPA)
A standard DPA covering our processing activities on your behalf, ready to countersign.
Sub-processor list
The current list of third parties we use to deliver our platform and services.
Security questionnaire responses
Pre-filled answers to common vendor security questionnaires (SIG Lite, CAIQ, or your own format).
Need a DPA or sub-processor list?
Email us and we'll send over the current version, or set up time to walk through it.