File transfer that supports your DORA obligations

An ICT provider that holds nothing readable

DORA made ICT third-party risk a supervised matter for financial entities: every provider goes in a register, every contract needs specific provisions, and you have to be able to show you could leave. GCN.ONE encrypts documents in the browser before upload, so the provider you are registering holds ciphertext it cannot read - and files you could still open if we disappeared tomorrow.

Send a file now See pricing
What DORA is, in brief

DORA - the Digital Operational Resilience Act - is an EU regulation that has applied directly across the Union since 17 January 2025. Because it is a regulation rather than a directive, it applies as written, with no national transposition in between.

It brings ICT risk for the financial sector under one framework - banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, fund managers and more - and reaches through them to the ICT providers they depend on.

Who it covers
Around twenty categories of financial entity, from credit institutions and insurers to payment institutions, investment firms and crypto-asset service providers - plus, indirectly, every ICT third-party provider serving them, and directly those designated as critical.
ICT risk management
Chapter II asks for an internal framework: identification of assets and dependencies, protection and prevention including encryption, detection, response and recovery, backups, and learning from incidents. The management body owns it.
Incident reporting
Major ICT-related incidents are classified against common criteria and reported to your competent authority on an initial, intermediate and final schedule - which means you need to reconstruct what happened, and when, with some precision.
Third-party risk and the register
Chapter V: keep a register of information on all contractual arrangements for ICT services, put the Article 30 provisions in the contracts, assess concentration risk, and hold documented exit strategies so that leaving a provider is genuinely possible.
How GCN.ONE helps

If you use GCN.ONE, it goes into your register of information as an ICT service provider. The design goal is to make that a short, unexciting entry. Here is what you would be writing down.

Ciphertext is all we hold
Documents, filenames and messages are encrypted in the browser before upload, and the keys never reach us. For your ICT risk assessment, the confidentiality question about this provider has a structural answer rather than a contractual one.
Evidence for incident timelines
Every link open and download start is recorded with a timestamp, and any delivered file can be issued a cryptographically signed delivery certificate that anyone can verify without an account - useful when a reporting deadline requires you to show exactly what went where, and when.
Register-ready documentation
A signable data processing agreement, a public sub-processor list, and technical documentation of the encryption model, so the fields in your register of information can be filled from published material rather than from a questionnaire round.
An exit that needs nothing from us
Files are downloaded and decrypted with keys you hold, in the browser or through our SDK. There is no proprietary container and nothing on our side is needed to read them, so an exit - planned or not - does not put your data out of reach.
Retention that enforces itself
Transfers expire on download or on a date you set, and the encrypted data is permanently deleted afterwards. Defined retention and deletion are easier to evidence when they are the default behaviour rather than a policy someone has to remember to follow.
A tamper-evident record behind it
Delivery events go into an append-only, hash-chained audit log that is rolled up and publicly anchored, so the record behind a certificate cannot be quietly rewritten after the fact - by us or by anyone else.

See how this looks for banks and financial institutions

Two things your review will ask about

We are a third-country provider. The company behind GCN.ONE is registered in the United Kingdom; the systems that hold your data run in the European Union, so processing stays under EU data-protection law. Your register of information and your concentration-risk assessment should reflect both facts, and we would rather you read them here than discover them later.

Article 30 provisions are a conversation, not a download. Our standard terms cover data processing, sub-processors, retention and deletion, and support response times, and availability is governed by those terms rather than by a separate uptime guarantee. If your procurement needs contractual service levels, specific Article 30 clauses or an agreed exit plan in writing, ask us before you buy - that is a normal request and we will answer it plainly.

Talk to us about contractual terms

Make one register entry a short one
Send an encrypted file now, or see what it costs at scale.