← Trust center

Compliance

Demanding texts. A platform that helps you document.

Compliance belongs to your organization. graal helps you trace and document what the texts require: who accessed what, where workloads run, how to switch providers.

The texts

What they require, and how graal helps

Five European and French texts, their status at the date shown, and what the platform brings to your files.

NIS2

Directive (EU) 2022/2555

Not yet transposed into French law as of 28/09/2026: it will apply once the law, decrees and orders are published.

What the text requires

Cybersecurity risk management, supply chain security, incident notification.

How graal helps

A platform installed on your premises, an audit trail of human and agent actions, signed images and a software bill of materials (SBOM) with every release.

DORA

Regulation (EU) 2022/2554

Applies to the financial sector since 17/01/2025.

What the text requires

ICT third-party risk management, register of information (Article 28), minimum contractual clauses (Article 30), exit strategy.

How graal helps

A platform operated by you or by the hosting provider of your choice, and an exit strategy backed by exported code and open formats.

Data Act

Regulation (EU) 2023/2854

Applies since 12/09/2025; cloud switching charges are prohibited from 12/01/2027.

What the text requires

Easier switching between data processing providers, without exit fees.

How graal helps

Exportable code, Iceberg tables and Parquet files on your storage, documented APIs: your data and workloads stay portable.

AI Act

Regulation (EU) 2024/1689

In force since 2024, it applies in stages, depending on the category of AI system.

What the text requires

Technical documentation, traceability and logging of AI systems, in particular high-risk ones.

How graal helps

Tracked experiments, parameters and metrics, a versioned model registry, logs of calls to language models.

SREN law

Article 31 and Decree No. 2026-272

Decree of 14/04/2026, in force since 17/04/2026.

What the text requires

French State administrations and operators entrust their particularly sensitive data to a compliant provider, attested by SecNumCloud qualification or an equivalent European certification.

How graal helps

A platform deployable with a SecNumCloud-qualified hosting provider, on its Kubernetes offer.

Evidence

What you can produce

Items drawn from the platform, ready for your registers and audit files.

  • The trail of human and agent actions, per project
  • The list of permissions and their holders, at a given date
  • Where each workload runs
  • The provenance and versions of each model
  • Code and data exported in open formats
  • The log of calls to language models

Document your data platform

A specialist shows you the logs, registers and exports that matter for your files.