Two mandates. One platform. One evidence trail.
If you're supervised under DORA and assessed under PCI DSS, you're being asked to prove the same testing twice. breachr runs one programme and hands you both evidence packs.
DORA Article-by-Article Coverage
General ICT Testing
Continuous vulnerability scanning mapped to your ICT asset register - continuous coverage vs. point-in-time sampling. Automated cadence supports the annual testing requirement.
✅ Fully coveredAdvanced Testing
LLM exploit chaining combines vulnerabilities into real attack paths. Threat intelligence from MITRE ATT&CK and FS-ISAC. Every critical and high finding is confirmed by a named security professional.
✅ Fully coveredTLPT - Significant Entities
TLPT under Article 26 requires an independent accredited testing provider and threat-intelligence-led scoping. breachr is designed to align with TIBER-EU, and we scope Article 26 engagements with you directly.
Talk to usWhere Your Data Lives
Residency is a compliance property, not a deployment preference - so we are explicit about it:
- ✅ Stored and processed in the EU - Frankfurt, eu-central-1
- ✅ We do not sell your data, and it is never used to train models for other customers
- ✅ Credentials encrypted per tenant, and deleted after the scan
- ✅ Every access recorded on an append-only audit trail
- ✅ Some AI analysis uses a model provider hosted outside the EU - minimised to what a finding needs, and never retained for training
- ✅ Data residency, audit rights and exit strategy documented in the DPA
What Your Auditor Asks - And What breachr Hands You
| The question | What you hand over |
|---|---|
| “Show me your methodology” | Signed, documented red-team methodology |
| “Prove segmentation holds” | In-CDE Req. 11.4.5/11.4.6 evidence |
| “Who found this, and how?” | Cryptographic chain of custody per finding |
| “Where does our data go?” | Stored and processed in the EU (Frankfurt, eu-central-1). Some AI analysis uses a provider outside the EU, minimised and never used to train models for other customers. |
| “Is the AI auditable?” | Model, version, confidence + SHA-256 on every finding |
Why Compliance Deadlines Matter Now
Deep-dive guides
Meet Every Regulatory Deadline
PCI DSS pen tests are annual and the date doesn't move. DORA has been in force since January 2025. Start building your compliance evidence trail today.