CleanDesk builds and validates your compliance register across DORA, MiCA, AML and KYC, FCA operational resilience, and the EU Cyber Resilience Act, catching every checkable gap before you submit. Built for smaller financial firms and crypto CASPs.
Every mandatory gate, EU and UK, validated against the rules actually published. Open a regime to watch CleanDesk resolve a real flagged finding.
Every ICT third-party arrangement mapped to the official Register of Information tables. LEI checksums (ISO-7064), broken references, and Article 28(8) exit & 30(3)(e) audit clauses checked automatically.
Open this module →Trading and order data screened for the market-abuse patterns MiCA Article 92 makes you responsible for catching, wash trading and spoofing included, with UK MAR surveillance run alongside it.
Open this module →Every client screened against sanctions and PEP lists, with due-diligence depth tracked per entity so a gap in enhanced due diligence is a flagged finding, not a silent miss.
Open this module →Important business services mapped to impact tolerances and tested against SYSC 15A, so a resilience gap shows up before your regulator finds it.
Open this module →Every product with digital elements classified against the Cyber Resilience Act's scope rules, so you know exactly which obligations apply before CE marking, not after.
Open this module →22,000+ EU financial firms must file a Register of Information by 31 Mar every year. In the 2024 ESA dry run, 93.5% of registers submitted failed at least one of the 116 required checks.
Not a compliance department of twenty. A single ops lead, a fractional MLRO, a two-person compliance function at a growing CASP, the person who currently keeps this in a spreadsheet and dreads every deadline.
Everything you need to produce, validate and maintain your compliance register, across every regime you're in scope for.
Every provider identifier mathematically verified in your browser against ISO-7064. One bad digit is an instant automated flag.
Every link between the ESA tables reconciled, so no field points at a record that doesn't exist.
Exit strategies (Art 28(8)) and audit rights (Art 30(3)(e)) checked on every critical or important function.
From vendor export to a validated register. Minutes, not days.
Any vendor export works. CleanDesk maps it to the official ESA register templates, and you see your first validated register in minutes.
CleanDesk assembles the Register of Information and runs the automated checks defined in the ESA reporting standards, including LEI checksums, broken references, and missing exit and audit clauses on critical providers.
Fix what's flagged, export the validated register, and keep it current as suppliers and rules change, ready for every deadline.
You're trusting us with sensitive supplier data. Here is exactly how we treat it.
The validator runs entirely in your browser. Your register isn't "protected on our servers". It never reaches them. The strongest data security is data we never hold.
Served over modern TLS on Cloudflare's global edge network with always on DDoS protection, the same infrastructure that shields a large share of the web.
Signing in stores only your account (email and plan), never your register, tape or KYC data. That stays in your own browser; we couldn't misuse it if we wanted to, because we never see it.
Open DevTools → Network, run a check, and watch: zero requests leave your machine. Hardened security headers and a published security.txt disclosure policy. Don't trust claims. Inspect them.
Founding design partners run CleanDesk at no cost through their first filing, with founder pricing locked in after. No card, no lock-in. Your register exports any time.
Everything a lean compliance team needs to go from a vendor spreadsheet to a validated register in an afternoon, not a fortnight.
For firms where the register is genuinely complex, with multiple entities, deep supplier chains, and the next obligations already looming.
For groups, multi-jurisdiction filings, and the consultancies who run registers for many clients at once.
Paid pilots are fixed fee and scoped on a call, always a fraction of a consultant engagement.
Under DORA Article 28, every in scope financial firm must maintain, and file annually to its national regulator, a structured register of every ICT third party arrangement, including criticality, subcontractors and exit strategies. CleanDesk builds and validates it for you.
Yes. Your register never leaves your browser. It's processed locally on your device, so there's no server side copy of your supplier data to breach. Only your account record (email and plan) is stored. It's EU hosted, encrypted, and never sold. You can export or delete it at any time.
For a regulatory filing, "plausible" isn't good enough. You need something provably correct. CleanDesk doesn't ask an AI to guess. It runs the exact deterministic checks defined in the ESA standards, so it's right by construction where a chatbot hallucinates. You get a defensible, audit ready register, and your confidential supplier data never goes into a public AI model.
General GRC platforms treat DORA as one of dozens of frameworks via control mappings. They don't actually build or validate the Register of Information. CleanDesk is purpose-built for it, runs the published ESA validation rules, and is priced for smaller firms.
Especially. CASPs have been in DORA scope since January 2025, and MiCA's transitional authorisation window has now closed in every EU/EEA state. CleanDesk is built with crypto-specific suppliers and obligations in mind.
No. CleanDesk is software that helps you produce and validate your register accurately. It does not constitute legal advice; your firm remains responsible for its regulatory obligations.
Tell us a little about your firm, and we'll show you the gaps an NCA would actually flag in your own register.
We reply to every design partner request within one business day.
No card, no lock in. Founding design partners run CleanDesk free through their first filing.
Book a 20-minute demo, or send your vendor list and we'll show you the gaps an NCA would flag.
Book a demo →