CodebahnCodebahn

DORA register of information

Last updated: 21 September 2026

If you are a financial entity under DORA, you maintain a register of information about every ICT third-party provider you use. The templates come from Commission Implementing Regulation (EU) 2024/2956, as corrected on 19 September 2025. Some of the fields can only be answered by us.

They are below. We publish them rather than waiting to be asked, because you should be able to assess us before a call rather than after one.

The obligations here fall on you. DORA names ICT third-party service providers in its scope, but a provider that has not been designated critical has no direct supervisory duty under it; what reaches us reaches us through the contract. We are not designated and could not meet the criteria at our size, so nothing here is us claiming a status we do not have.

How much of this you actually need

Most of the register is scoped to ICT services that support a critical or important function. If the function you would run on us is not one, you need B_05.01 and a small part of B_02.02, and you can skip the subcontracting chain and the assessment fields entirely.

If it is one, stop here and read where we are the wrong supplier before you fill anything in. Article 30(3) applies to you then, and it asks for things we do not offer.

We publish all of it anyway, because a supplier assessment is not the same document as a register, and the answers are the same either way. Each section below says when it is required.

B_05.01 ICT third-party service providers

Required for every provider, whatever the function.

FieldValue
Legal name (0050)Hackerman AB
Identification code (0010)SEBOLREG.5590791918, our EUID. Article 3(5) accepts an LEI or an EUID, and Annex I limits the EUID option to legal persons established in the Union, which we are. We hold no LEI; if your tooling requires one, tell us and we will obtain it
Type of code (0020)EUID
Additional identification code (0030, 0040)5590791918, our Swedish organisation number, type of code CRN. Swedish convention writes it 559079-1918; the register and the EUID both carry it without the hyphen
Type of person (0070)Legal person
Country of headquarters (0080)SE. Registered office in Gothenburg
Total annual expense (0100)Your spend with us, which only you can compute. Our invoices carry the figures
Ultimate parent undertaking (0110, 0120)None. Hackerman AB is not owned by another company

You can confirm that without asking us, though BRIS has no shareable link to a single record. On the Commission's business registers portal, tick Sweden, put 5590791918 in the registration number field, accept the terms, and the record that comes back carries the same EUID.

If you report a subcontracting chain, each of our sub-processors below needs its own B_05.01 row as well.

B_02.02 Contractual arrangements, specific information

The first two rows apply to every arrangement. The rest are required only where the ICT service supports a critical or important function.

FieldValue
Type of ICT services (0060)S19, cloud services: SaaS. Annex III has no code for hosted CI. S02 covers ICT development, meaning analysis, design, testing and development work done for you, which is not what our runners do, so we would not report it
Start and end date (0070, 0080)On your invoice and in your billing page
Notice period, you to us (0100)0 calendar days. You may cancel at any time (Terms 10.6)
Notice period, us to you (0110)90 calendar days, except for your breach or non-payment (Terms 10.6)
Governing law (0120)SE. Courts of Gothenburg (Terms 15)
Country of provision (0130)FR. The field asks where the service is provided from, which is Paris. Our contracting entity is Swedish, which is B_05.01.0080 above, not this field
Storage of data (0140)Yes
Country of data at rest (0150)FR primary, DE backups
Country of data processing (0160)FR
Sensitiveness of data stored (0170)Your assessment, not ours. The field takes Low, Medium or High, and the most sensitive applies. We hold your source code, which most financial entities classify High

B_05.02 ICT service supply chains

Required only for ICT services supporting a critical or important function. If that is not your case, none of this section goes in your register.

Where it does apply, we are rank 1 as your direct provider and our sub-processors are rank 2. The ESAs declined to cap the chain at a fixed rank and applied a materiality filter instead: within a critical or important function, report the subcontractors whose disruption would impair the security or continuity of the service, whatever their rank.

By that test, two of our four sub-processors are material and two are not. The template itself carries only the reference number, service type, identification codes and rank; the function and country columns below are ours, added because you need them for B_06.01 and B_05.01 and would otherwise have to ask.

RankEntityFunctionCountryMaterial to continuity
1Hackerman ABManaged Git and CISE-
2ScalewayCompute, object storage, managed PostgreSQL, container registry, transactional emailFRYes
2HetznerBackup storageDEYes
2MolliePayment processingNLNo. A payments outage stops billing, not the service
2CrispIn-app support chatFRNo. Not in the data path for repositories or CI

Every sub-processor is EU-incorporated. The current list, with any changes, is at codebahn.net/docs/subprocessors. We give 30 days' notice before adding or replacing one, with a right to object.

Each of them also needs its own B_05.01 row, so here are the identifiers rather than four lookups. Two of the four have no LEI, which is worth knowing before you go looking for one.

EntityIdentification codeTypeRegistered seat
Scaleway SAS433 115 904CRN (SIREN)Paris, FR
Hetzner Online GmbH391200XMWUW8G8MXV439LEIGunzenhausen, DE
Mollie B.V.98450064AC9753611E09LEIAmsterdam, NL
Crisp IM SAS833 085 806CRN (SIREN)Nantes, FR

Retrieved 14 September 2026 from the GLEIF register and the French national register. Verify against GLEIF before you submit, because these values are ours to report and theirs to change. Three specifics that will save you time:

Hetzner's registered seat is Gunzenhausen. Falkenstein, where your backups sit, is a data centre site rather than the company's seat, so the two fields take different values.

B_07.01 Assessment of the ICT services

Required only for ICT services supporting a critical or important function. These are your judgements, not ours. What follows is the evidence you need to make them, and our own view where we have one.

FieldOur input
Substitutability (0050)We would answer easily substitutable. We run Forgejo, an open-source forge with commercial hosts and a self-hosting path. Your repositories are standard Git and clone to anywhere
Reason, if not easily substitutable (0060)Not applicable on our answer, and the field is only mandatory if you select not substitutable or highly complex
Date of last audit (0070)None. We have never been audited by a third party, and we hold no ISO 27001 or SOC 2. See our security page
Existence of an exit plan (0080)Yes, and it is published at codebahn.net/leaving rather than described. It states what does not transfer as well as what does
Possibility of reintegration (0090)The field takes Easy, Difficult or Highly complex. For repositories and history it is Easy. For issues, pull requests and permissions it is Difficult, because they restore one repository at a time and teams are recreated by hand. If you must enter one value for the service, enter Difficult
Impact of discontinuation (0100)Your judgement. Ours: you would lose the hosted service, not your code. A clone taken at any moment is complete
Alternative providers identified (0110)Your judgement, from Yes, No, or assessment not performed. STACKIT Git, run by the Schwarz Group in Germany, is a commercial Forgejo host inside the EU. There are further Gitea and Forgejo hosts in Europe outside the EU, and self-hosting Forgejo is documented upstream

Article 30 contractual provisions

Article 30(2) lists nine provisions every ICT contract must contain, whatever the function. That is worth saying twice, because it is the part a non-critical customer still has to satisfy after the register is done.

All nine are in our standard paper. Six sit in the Terms and the Security and Exit Addendum already: the service description and whether subcontracting is permitted, the locations of processing and data with notice of changes to them, provisions on availability, authenticity, integrity and confidentiality, data access and return on discontinuation, incident assistance, and termination rights with notice periods.

The other three are the ones ordinary SaaS terms leave out, so we wrote them into section 17 of the Terms rather than making you ask: the service level description and how we revise it (sections 7.1 and 7.3, with 7.2 saying outright that it carries no financial remedies), cooperation with your competent and resolution authorities (17.2), and taking part in your awareness and resilience training (17.3, one session a year, remote).

If your legal team wants a clause mapped to its Article 30 reference, ask. That is inside the questionnaire allowance on Assurance.

How fast we tell you

Your initial notification of a major incident is due within four hours of your classifying it as major, and in any event within 24 hours of your becoming aware of it, whichever falls first. The intermediate report follows 72 hours after that notification, and the final one a month after the intermediate. Article 5 of Delegated Regulation (EU) 2025/301.

Our commitment is 48 hours from our becoming aware, both for a personal data breach and for any incident affecting the confidentiality, integrity or availability of your data (DPA 8.1, addendum 5.1 and 5.2).

Those two numbers do not collide, and it is worth being exact about why. Both of your clocks start from your own awareness or your own classification, so nothing we do spends them. What our 48 hours decides is when your clock starts, in the case where we are how you find out.

Three consequences follow, and you should weigh them rather than take our word for it.

If your own deadline needs something shorter, tell us what it is and we will work to it (addendum 5.4). We would rather agree a number we can hold than publish one we cannot.

Where we are the wrong supplier

If the function you would run on us is a critical or important function, Article 30(3) applies and requires more than we can honestly provide. It obliges us to grant unrestricted rights of access, inspection and audit to you, to your appointee, and to your regulator, and under point (d) to participate and fully cooperate in your threat-led penetration testing.

We are one person. We offer the reports and evidence we hold, and we do not offer on-site audit rights or TLPT participation. That is a real gap, not a negotiating position, and it does not close by talking to us about it.

There is one exception, and it is narrower than it first looks. If your entity is a microenterprise within Article 3(60), the last subparagraph of Article 30(3) lets the two of us agree that your rights of access, inspection and audit pass to an independent third party. We would appoint that third party, not you, and the agreement only stands if you can ask them for information and assurance about our performance at any time. We have not appointed one. If that route would unblock you, ask and we will price it. Your competent authority's access is untouched either way, and so is the Lead Overseer's.

So: if this is a critical or important function, we are probably not your supplier, and it is better that you learn that on this page than in month three of a procurement.

If you are not running a critical or important function under DORA, the same question (what happens if we are not here) still deserves an answer. See Continuity.

If it is not, two separate things are true. Your register needs the first two sections above and nothing more. Your contract still needs all nine Article 30(2) provisions, because those bind every arrangement whatever the function, and they are already in our standard Terms. So there is nothing to negotiate and nothing to request.

Anything missing, email hello@codebahn.net.