CleanDesk builds your register and validates it against the published DORA/ESA rules — catching every gap before you submit. Built for smaller financial firms and crypto CASPs.
If your register is clean, you’ll know in 30 seconds. If it isn’t — better you find out than your regulator.
DORA and MiCA for the EU; FCA operational resilience and UK MAR for the UK; plus AML and CRA. One vendor, one login, priced for smaller firms.
Several regulators file weeks before the headline date. Find yours — each links to a full filing guide.
The FCA’s operational-resilience rules are already in force. If you can’t show you stay within your impact tolerances, you’re not early — you’re late. And the FCA can call in your self-assessment at any time.
| Obligation | Framework | Status |
|---|---|---|
| Operational resilience | FCA SYSC 15A · PS21/3 | In force — since 31 Mar 2025 |
| Market-abuse surveillance | UK MAR · Art 16 STORs | In force now |
| Cryptoasset regime | FSMA · FCA authorisation | Phasing in — get ahead of it |
A quick explainer of the problem, and how we solve it.
From vendor export to a submission-ready register — minutes, not days.
Any vendor export works. CleanDesk maps it to the official ESA register templates — and you see your first validated register in minutes.
CleanDesk assembles the Register of Information and runs the automated checks defined in the ESA reporting standards — LEI checksums, broken references, missing exit and audit clauses on critical providers.
Fix what's flagged, export the submission-ready register, and keep it current as suppliers and rules change — ready every March.
Everything you need to produce, validate and maintain your DORA Register of Information.
Maps your suppliers, contracts, functions and subcontractors to the ESA templates automatically.
LEI (ISO 17442) checksums, cross-table referential integrity, and criticality-control checks — the gaps NCAs flag.
Kept current as your suppliers and the ESA templates change, with reminders before the 31 March deadline.
Produce the submission-ready register and a clear gap report for your board and your regulator.
Tracks material subcontractors and concentration so critical-provider chains are complete and defensible.
Templates and the 4-hour / 24-hour clock for the major-incident reports DORA requires.
A regulatory filing has to be correct, not convincing. Here's exactly why CleanDesk's validation holds up where an AI's "best guess" doesn't.
Every check is arithmetic or a published rule — never an AI's opinion. A LEI is valid or invalid by its ISO-7064 checksum; there's no "probably." Where a chatbot hallucinates, CleanDesk is correct by construction.
Every finding cites the exact DORA article and ESA template field behind it — so your register is defensible to your board, your auditor and your NCA. No black box, no "trust me."
The checks implement the ESA Implementing Technical Standards for the Register of Information — the same documented rules in the public rulebook, not our interpretation of them.
Don't take our word for it — run your own register in the browser and check every flag against the regulation. The tool is auditable precisely because the rules are public and the checks are explicit.
CleanDesk applies the published validation rules and shows you the gaps — you review and file. It doesn't promise a regulator will accept your register; it makes sure everything that's checkable is correct, and shows its working.
You're trusting us with sensitive supplier data. Here is exactly how we treat it.
The validator runs entirely in your browser. Your register isn’t “protected on our servers” — it never reaches them. The strongest data security is data we never hold.
Served over modern TLS on Cloudflare’s global edge network with always-on DDoS protection — the same infrastructure that shields a large share of the web.
Signing in stores only your account (email + plan) — never your register, tape or KYC data. That stays in your own browser; we couldn’t misuse it if we wanted to, because we never see it.
Open DevTools → Network, run a check, and watch: zero requests leave your machine. Hardened security headers (CSP, frame-deny, nosniff) and a published security.txt disclosure policy. Don’t trust claims — inspect them.
Tools like Vendorica are full vendor-risk platforms you onboard into and maintain. CleanDesk is the opposite bet — a fast, private way to fix and file the one document you actually owe, meeting you in your spreadsheet instead of asking you to migrate into another system.
| CleanDesk | Vendorica | |
|---|---|---|
| Your data | Stays in your browser — never uploaded | Stored in their cloud (EU data centres, encrypted) |
| To try it | Drop your real file — it never leaves your browser, no vendor limit | Free tier: sign up, 1 user, up to 10 vendors |
| The core job | Fix & validate your existing register → submission-ready, every change logged | Maintain vendors in-platform, with 6-factor risk scoring |
| Regulator depth | Per-NCA deadline + XBRL-CSV format, GLEIF-checked LEIs | DORA Register of Information generation |
| Incident reporting | On the roadmap | Live — auto-submits to your NCA |
| Best for | A lean team filing this register fast and privately | A team wanting an ongoing vendor-risk platform |
| Price | Free checker · founder pricing on pilots | €0 (10 vendors) · €299/mo (50) · Enterprise |
Honest take: Vendorica is the bigger platform — more to adopt, maintain and pay for. But your NCA isn't asking for a platform; it's asking for one correct Register of Information by the deadline. That's the job CleanDesk does best — fixed, validated and submission-ready, privately in your browser, with no vendor cap. Start with the filing you actually owe. Log in →
Founding design partners run CleanDesk free through their first filing, with founder pricing locked in after — no card, no lock-in, your register exports any time.
Everything a lean compliance team needs to go from a vendor spreadsheet to a submission-ready register — in an afternoon, not a fortnight.
For firms where the register is genuinely complex — multiple entities, deep supplier chains, and the next obligations already looming.
For groups, multi-jurisdiction filings, and the consultancies who run registers for many clients at once.
Paid pilots are fixed-fee and scoped on a call — always a fraction of a consultant engagement.
Under DORA Article 28, every in-scope financial firm must maintain — and file annually to its national regulator — a structured register of every ICT third-party arrangement, including criticality, subcontractors and exit strategies. CleanDesk builds and validates it for you.
Yes. Data is EU-hosted, encrypted in transit and at rest, and never sold. Our browser-based validator processes your data locally — it never leaves your device. You can export and delete your data at any time.
For a regulatory filing, "plausible" isn't good enough — you need provably correct. CleanDesk doesn't ask an AI to guess; it runs the exact deterministic checks defined in the ESA standards (LEI ISO-7064 checksums, the official ESA template, cross-table references), so it's right by construction where a chatbot hallucinates. You get a defensible, audit-ready register you can stand behind with your NCA — not an answer with no accountability — and your confidential supplier data never goes into a public AI model.
General GRC platforms treat DORA as one of dozens of frameworks via control mappings — they don't actually build or validate the Register of Information. CleanDesk is purpose-built for it, runs the published ESA validation rules, and is priced for smaller firms.
Especially. CASPs have been in DORA scope since January 2025 and face the 1 July 2026 MiCA authorisation deadline. CleanDesk is built with crypto-specific suppliers and obligations in mind.
No. CleanDesk is software that helps you produce and validate your register accurately. It does not constitute legal advice; your firm remains responsible for its regulatory obligations.
Book a 20-minute demo, or send your vendor list and we'll show you the gaps an NCA would flag.