DORA register of information
If you are a financial entity under DORA, you maintain a register of information about every ICT third-party provider you use. The templates come from Commission Implementing Regulation (EU) 2024/2956, as corrected on 19 September 2025. Some of the fields can only be answered by us.
They are below. We publish them rather than waiting to be asked, because you should be able to assess us before a call rather than after one.
The obligations here fall on you. DORA names ICT third-party service providers in its scope, but a provider that has not been designated critical has no direct supervisory duty under it; what reaches us reaches us through the contract. We are not designated and could not meet the criteria at our size, so nothing here is us claiming a status we do not have.
How much of this you actually need
Most of the register is scoped to ICT services that support a critical or important function. If the function you would run on us is not one, you need B_05.01 and a small part of B_02.02, and you can skip the subcontracting chain and the assessment fields entirely.
If it is one, stop here and read where we are the wrong supplier before you fill anything in. Article 30(3) applies to you then, and it asks for things we do not offer.
We publish all of it anyway, because a supplier assessment is not the same document as a register, and the answers are the same either way. Each section below says when it is required.
B_05.01 ICT third-party service providers
Required for every provider, whatever the function.
| Field | Value |
|---|---|
| Legal name (0050) | Hackerman AB |
| Identification code (0010) | SEBOLREG.5590791918, our EUID. Article 3(5) accepts an LEI or an EUID, and Annex I limits the EUID option to legal persons established in the Union, which we are. We hold no LEI; if your tooling requires one, tell us and we will obtain it |
| Type of code (0020) | EUID |
| Additional identification code (0030, 0040) | 5590791918, our Swedish organisation number, type of code CRN. Swedish convention writes it 559079-1918; the register and the EUID both carry it without the hyphen |
| Type of person (0070) | Legal person |
| Country of headquarters (0080) | SE. Registered office in Gothenburg |
| Total annual expense (0100) | Your spend with us, which only you can compute. Our invoices carry the figures |
| Ultimate parent undertaking (0110, 0120) | None. Hackerman AB is not owned by another company |
You can confirm that without asking us, though BRIS has no shareable link to a single record. On the Commission's business registers portal, tick Sweden, put 5590791918 in the registration number field, accept the terms, and the record that comes back carries the same EUID.
If you report a subcontracting chain, each of our sub-processors below needs its own B_05.01 row as well.
B_02.02 Contractual arrangements, specific information
The first two rows apply to every arrangement. The rest are required only where the ICT service supports a critical or important function.
| Field | Value |
|---|---|
| Type of ICT services (0060) | S19, cloud services: SaaS. Annex III has no code for hosted CI. S02 covers ICT development, meaning analysis, design, testing and development work done for you, which is not what our runners do, so we would not report it |
| Start and end date (0070, 0080) | On your invoice and in your billing page |
| Notice period, you to us (0100) | 0 calendar days. You may cancel at any time (Terms 10.6) |
| Notice period, us to you (0110) | 90 calendar days, except for your breach or non-payment (Terms 10.6) |
| Governing law (0120) | SE. Courts of Gothenburg (Terms 15) |
| Country of provision (0130) | FR. The field asks where the service is provided from, which is Paris. Our contracting entity is Swedish, which is B_05.01.0080 above, not this field |
| Storage of data (0140) | Yes |
| Country of data at rest (0150) | FR primary, DE backups |
| Country of data processing (0160) | FR |
| Sensitiveness of data stored (0170) | Your assessment, not ours. The field takes Low, Medium or High, and the most sensitive applies. We hold your source code, which most financial entities classify High |
B_05.02 ICT service supply chains
Required only for ICT services supporting a critical or important function. If that is not your case, none of this section goes in your register.
Where it does apply, we are rank 1 as your direct provider and our sub-processors are rank 2. The ESAs declined to cap the chain at a fixed rank and applied a materiality filter instead: within a critical or important function, report the subcontractors whose disruption would impair the security or continuity of the service, whatever their rank.
By that test, two of our four sub-processors are material and two are not. The template itself carries only the reference number, service type, identification codes and rank; the function and country columns below are ours, added because you need them for B_06.01 and B_05.01 and would otherwise have to ask.
| Rank | Entity | Function | Country | Material to continuity |
|---|---|---|---|---|
| 1 | Hackerman AB | Managed Git and CI | SE | - |
| 2 | Scaleway | Compute, object storage, managed PostgreSQL, container registry, transactional email | FR | Yes |
| 2 | Hetzner | Backup storage | DE | Yes |
| 2 | Mollie | Payment processing | NL | No. A payments outage stops billing, not the service |
| 2 | Crisp | In-app support chat | FR | No. Not in the data path for repositories or CI |
Every sub-processor is EU-incorporated. The current list, with any changes, is at codebahn.net/docs/subprocessors. We give 30 days' notice before adding or replacing one, with a right to object.
Each of them also needs its own B_05.01 row, so here are the identifiers rather than four lookups. Two of the four have no LEI, which is worth knowing before you go looking for one.
| Entity | Identification code | Type | Registered seat |
|---|---|---|---|
| Scaleway SAS | 433 115 904 | CRN (SIREN) | Paris, FR |
| Hetzner Online GmbH | 391200XMWUW8G8MXV439 | LEI | Gunzenhausen, DE |
| Mollie B.V. | 98450064AC9753611E09 | LEI | Amsterdam, NL |
| Crisp IM SAS | 833 085 806 | CRN (SIREN) | Nantes, FR |
Retrieved 14 September 2026 from the GLEIF register and the French national register. Verify against GLEIF before you submit, because these values are ours to report and theirs to change. Three specifics that will save you time:
- Scaleway and Crisp hold no LEI. That is a fact about them, not a gap in this page. Use the SIREN with a type of CRN, which the corrigendum of 19 September 2025 made an explicit option in B_05.01.0020.
- Do not use Iliad's LEI for Scaleway. Iliad is the parent and has one; Scaleway is a separate legal entity and a register naming Iliad would be wrong.
- Mollie has several records. The operating payment institution is Mollie B.V., KvK 30204462, above. Mollie Holding B.V. is a different entity and its LEI has lapsed. Mollie's own LEI renews on 29 October 2026, so re-check it after that date.
Hetzner's registered seat is Gunzenhausen. Falkenstein, where your backups sit, is a data centre site rather than the company's seat, so the two fields take different values.
B_07.01 Assessment of the ICT services
Required only for ICT services supporting a critical or important function. These are your judgements, not ours. What follows is the evidence you need to make them, and our own view where we have one.
| Field | Our input |
|---|---|
| Substitutability (0050) | We would answer easily substitutable. We run Forgejo, an open-source forge with commercial hosts and a self-hosting path. Your repositories are standard Git and clone to anywhere |
| Reason, if not easily substitutable (0060) | Not applicable on our answer, and the field is only mandatory if you select not substitutable or highly complex |
| Date of last audit (0070) | None. We have never been audited by a third party, and we hold no ISO 27001 or SOC 2. See our security page |
| Existence of an exit plan (0080) | Yes, and it is published at codebahn.net/leaving rather than described. It states what does not transfer as well as what does |
| Possibility of reintegration (0090) | The field takes Easy, Difficult or Highly complex. For repositories and history it is Easy. For issues, pull requests and permissions it is Difficult, because they restore one repository at a time and teams are recreated by hand. If you must enter one value for the service, enter Difficult |
| Impact of discontinuation (0100) | Your judgement. Ours: you would lose the hosted service, not your code. A clone taken at any moment is complete |
| Alternative providers identified (0110) | Your judgement, from Yes, No, or assessment not performed. STACKIT Git, run by the Schwarz Group in Germany, is a commercial Forgejo host inside the EU. There are further Gitea and Forgejo hosts in Europe outside the EU, and self-hosting Forgejo is documented upstream |
Article 30 contractual provisions
Article 30(2) lists nine provisions every ICT contract must contain, whatever the function. That is worth saying twice, because it is the part a non-critical customer still has to satisfy after the register is done.
All nine are in our standard paper. Six sit in the Terms and the Security and Exit Addendum already: the service description and whether subcontracting is permitted, the locations of processing and data with notice of changes to them, provisions on availability, authenticity, integrity and confidentiality, data access and return on discontinuation, incident assistance, and termination rights with notice periods.
The other three are the ones ordinary SaaS terms leave out, so we wrote them into section 17 of the Terms rather than making you ask: the service level description and how we revise it (sections 7.1 and 7.3, with 7.2 saying outright that it carries no financial remedies), cooperation with your competent and resolution authorities (17.2), and taking part in your awareness and resilience training (17.3, one session a year, remote).
If your legal team wants a clause mapped to its Article 30 reference, ask. That is inside the questionnaire allowance on Assurance.
How fast we tell you
Your initial notification of a major incident is due within four hours of your classifying it as major, and in any event within 24 hours of your becoming aware of it, whichever falls first. The intermediate report follows 72 hours after that notification, and the final one a month after the intermediate. Article 5 of Delegated Regulation (EU) 2025/301.
Our commitment is 48 hours from our becoming aware, both for a personal data breach and for any incident affecting the confidentiality, integrity or availability of your data (DPA 8.1, addendum 5.1 and 5.2).
Those two numbers do not collide, and it is worth being exact about why. Both of your clocks start from your own awareness or your own classification, so nothing we do spends them. What our 48 hours decides is when your clock starts, in the case where we are how you find out.
Three consequences follow, and you should weigh them rather than take our word for it.
- Once you classify, you have four hours, not 24. Our notice can arrive with a short fuse on it.
- If you learn of an incident before we reach you, your 24 hours runs from that moment and you may be reporting with nothing from us. Article 5(3) then requires you to tell your authority inside the limit anyway and explain why the report is thin.
- For a critical or important function, Article 30(3)(b) makes our reporting obligation part of what your contract has to specify. So whether 48 hours is adequate is a question your supervisor can put to you, not just a number we chose.
If your own deadline needs something shorter, tell us what it is and we will work to it (addendum 5.4). We would rather agree a number we can hold than publish one we cannot.
Where we are the wrong supplier
If the function you would run on us is a critical or important function, Article 30(3) applies and requires more than we can honestly provide. It obliges us to grant unrestricted rights of access, inspection and audit to you, to your appointee, and to your regulator, and under point (d) to participate and fully cooperate in your threat-led penetration testing.
We are one person. We offer the reports and evidence we hold, and we do not offer on-site audit rights or TLPT participation. That is a real gap, not a negotiating position, and it does not close by talking to us about it.
There is one exception, and it is narrower than it first looks. If your entity is a microenterprise within Article 3(60), the last subparagraph of Article 30(3) lets the two of us agree that your rights of access, inspection and audit pass to an independent third party. We would appoint that third party, not you, and the agreement only stands if you can ask them for information and assurance about our performance at any time. We have not appointed one. If that route would unblock you, ask and we will price it. Your competent authority's access is untouched either way, and so is the Lead Overseer's.
So: if this is a critical or important function, we are probably not your supplier, and it is better that you learn that on this page than in month three of a procurement.
If you are not running a critical or important function under DORA, the same question (what happens if we are not here) still deserves an answer. See Continuity.
If it is not, two separate things are true. Your register needs the first two sections above and nothing more. Your contract still needs all nine Article 30(2) provisions, because those bind every arrangement whatever the function, and they are already in our standard Terms. So there is nothing to negotiate and nothing to request.
Anything missing, email hello@codebahn.net.