DORA, MiCA & AML (EU) · FCA & Cyber Resilience (UK)

File every regime with confidence, not in a spreadsheet.

CleanDesk builds and validates your compliance register across DORA, MiCA, AML and KYC, FCA operational resilience, and the EU Cyber Resilience Act, catching every checkable gap before you submit. Built for smaller financial firms and crypto CASPs.

Your register data never leaves your browser. The validator runs entirely on your machine.
This is the real product, not a screenshot
DORA & MiCA, EU·FCA SYSC 15A, UK·MiCA Art. 92 + UK MAR surveillance·Processed locally, never uploaded
Product

Five regimes, one click each

Every mandatory gate, EU and UK, validated against the rules actually published. Open a regime to watch CleanDesk resolve a real flagged finding.

Every ICT third-party arrangement mapped to the official Register of Information tables. LEI checksums (ISO-7064), broken references, and Article 28(8) exit & 30(3)(e) audit clauses checked automatically.

Open this module →

Trading and order data screened for the market-abuse patterns MiCA Article 92 makes you responsible for catching, wash trading and spoofing included, with UK MAR surveillance run alongside it.

Open this module →

Every client screened against sanctions and PEP lists, with due-diligence depth tracked per entity so a gap in enhanced due diligence is a flagged finding, not a silent miss.

Open this module →

Important business services mapped to impact tolerances and tested against SYSC 15A, so a resilience gap shows up before your regulator finds it.

Open this module →

Every product with digital elements classified against the Cyber Resilience Act's scope rules, so you know exactly which obligations apply before CE marking, not after.

Open this module →

22,000+ EU financial firms must file a Register of Information by 31 Mar every year. In the 2024 ESA dry run, 93.5% of registers submitted failed at least one of the 116 required checks.

Who it's for

Built for the person who actually owns the register

Not a compliance department of twenty. A single ops lead, a fractional MLRO, a two-person compliance function at a growing CASP, the person who currently keeps this in a spreadsheet and dreads every deadline.

Capabilities

Built for the register, not as a checkbox

Everything you need to produce, validate and maintain your compliance register, across every regime you're in scope for.

LEI checksum validation

Every provider identifier mathematically verified in your browser against ISO-7064. One bad digit is an instant automated flag.

Template cross-references

Every link between the ESA tables reconciled, so no field points at a record that doesn't exist.

Critical-provider clauses

Exit strategies (Art 28(8)) and audit rights (Art 30(3)(e)) checked on every critical or important function.

How it works

Three steps to a clean filing

From vendor export to a validated register. Minutes, not days.

1

Drop in your supplier spreadsheet

Any vendor export works. CleanDesk maps it to the official ESA register templates, and you see your first validated register in minutes.

2

We build & validate

CleanDesk assembles the Register of Information and runs the automated checks defined in the ESA reporting standards, including LEI checksums, broken references, and missing exit and audit clauses on critical providers.

3

File with confidence

Fix what's flagged, export the validated register, and keep it current as suppliers and rules change, ready for every deadline.

Security & trust

Your compliance data, handled properly

You're trusting us with sensitive supplier data. Here is exactly how we treat it.

Zero-upload architecture

The validator runs entirely in your browser. Your register isn't "protected on our servers". It never reaches them. The strongest data security is data we never hold.

Encrypted & edge-protected

Served over modern TLS on Cloudflare's global edge network with always on DDoS protection, the same infrastructure that shields a large share of the web.

No trackers. Your register data never leaves your browser.

Signing in stores only your account (email and plan), never your register, tape or KYC data. That stays in your own browser; we couldn't misuse it if we wanted to, because we never see it.

Verify us in 60 seconds

Open DevTools → Network, run a check, and watch: zero requests leave your machine. Hardened security headers and a published security.txt disclosure policy. Don't trust claims. Inspect them.

Now onboarding founding design partners.Use CleanDesk on your real register, shape the roadmap, and keep founder pricing through your first filing. Request a spot →
Plans

Pick the shape that fits.

Founding design partners run CleanDesk at no cost through their first filing, with founder pricing locked in after. No card, no lock-in. Your register exports any time.

Starter

For a single entity

Everything a lean compliance team needs to go from a vendor spreadsheet to a validated register in an afternoon, not a fortnight.

  • ✓ Full register builder, for any vendor export, mapped to the official ESA templates automatically
  • ✓ Validation to the published ESA rules: ISO-7064 LEI checksums, broken references, missing exit & audit clauses
  • ✓ Filing-draft export + a board-ready PDF where every finding cites its DORA article or ESA rule
  • ✓ A living register. Re-run the moment a supplier changes, and get reminded before every deadline
  • ✓ Browser-first privacy: your data never leaves your machine
  • ✓ Direct support from the founder
Claim a design-partner spot

Enterprise

For groups & platforms

For groups, multi-jurisdiction filings, and the consultancies who run registers for many clients at once.

  • ✓ Groups & multi-jurisdiction filings
  • ✓ Audit support · SSO (on the roadmap)
  • ✓ Custom integrations with your vendor & procurement systems
  • ✓ Dedicated onboarding and a named line to the founder
  • ✓ Partner options for consultancies · white-label (on the roadmap)
Talk to us

Paid pilots are fixed fee and scoped on a call, always a fraction of a consultant engagement.

FAQ

Questions, answered

Under DORA Article 28, every in scope financial firm must maintain, and file annually to its national regulator, a structured register of every ICT third party arrangement, including criticality, subcontractors and exit strategies. CleanDesk builds and validates it for you.

Yes. Your register never leaves your browser. It's processed locally on your device, so there's no server side copy of your supplier data to breach. Only your account record (email and plan) is stored. It's EU hosted, encrypted, and never sold. You can export or delete it at any time.

For a regulatory filing, "plausible" isn't good enough. You need something provably correct. CleanDesk doesn't ask an AI to guess. It runs the exact deterministic checks defined in the ESA standards, so it's right by construction where a chatbot hallucinates. You get a defensible, audit ready register, and your confidential supplier data never goes into a public AI model.

General GRC platforms treat DORA as one of dozens of frameworks via control mappings. They don't actually build or validate the Register of Information. CleanDesk is purpose-built for it, runs the published ESA validation rules, and is priced for smaller firms.

Especially. CASPs have been in DORA scope since January 2025, and MiCA's transitional authorisation window has now closed in every EU/EEA state. CleanDesk is built with crypto-specific suppliers and obligations in mind.

No. CleanDesk is software that helps you produce and validate your register accurately. It does not constitute legal advice; your firm remains responsible for its regulatory obligations.

Get in touch

Book a 20-minute demo

Tell us a little about your firm, and we'll show you the gaps an NCA would actually flag in your own register.

Thanks, that's in

We reply to every design partner request within one business day.

No card, no lock in. Founding design partners run CleanDesk free through their first filing.

See your register validated.

Book a 20-minute demo, or send your vendor list and we'll show you the gaps an NCA would flag.

Book a demo →
CleanDesk Assistant
Answers from our compliance FAQ, live now
Scripted from CleanDesk's own product & regulatory FAQ, not a general chatbot — English only for now.
93.5%of registers failed at least one of 116 required checks in the ESAs' 2024 DORA dry run. Yours might too.Source: ESAs, Dec 2024 →
Before you look around

Want us to check your own register instead?

20 minutes on a call, and we'll show you exactly what an NCA would flag in your real supplier list, not a demo one.

No card, no lock-in. Founding design partners run free through their first filing.