Guide · ComplianceNIS2 · DORA

NIS2-ready automation,
from day one.

Compliance retrofitted is compliance resented. In BitSwan, the controls NIS2 and DORA audits ask about are properties of the runtime itself — every app and automation inherits them the second it's deployed. In the Czech market, the new cybersecurity act has made this a boardroom topic; here is how the platform answers it.

What auditors ask

Four questions. Four built-in answers.

"Who can access this?"

Access control per user and per automation — who builds, who runs, who sees. The runtime enforces it; the answer is a screen, not a policy PDF.

"Show me the logs."

Every action recorded, automatically. When the auditor asks, the answer is already written.

"Where does the data live?"

Your servers, private cloud, or public cloud — your choice, including where the AI model runs. Residency is a deployment setting, not a negotiation.

"Can you trace an incident?"

Versioned, reversible deployments plus complete logs: what changed, when, by whom, and one press back to the last good state.

These controls live in the Bailey — the governed runtime every BitSwan automation runs in. They also close the biggest audit gap most companies don't know they have: Shadow AI →

Honest scope

What this page is, and isn't.

This page describes platform controls, not legal advice — your specific obligations depend on how your company is classified. What we'll do at the demo: go through your compliance checklist line by line against the running platform, so your answer to the auditor is a demonstration, not a promise.

Bring us a process.
We'll show you how it builds.

30 minutes. Real automations in real operation — no slides, no obligations.

The manual way isn't getting cheaper.