Compliance controls built into every workflow run.

Enforce policy in the process itself and let every run produce the audit-ready evidence your auditors and regulators ask for.

§ 01 · The approach

Workflow Compliance and Governance

Kora supports business-process compliance: each released workflow enforces the policies, approvals, and access rules defined for the process, people and AI agents execute inside those controls, and every run captures a hash-chained, replayable audit trail that can provide evidence for DORA, the EU AI Act, SOX, and MiFID II obligations.

  1. Hands pressing an approval stamp onto a stack of documents on a desk.
    01

    Policy as part of the process

    Approvals, segregation of duties, and access rules are defined in the workflow, so those controls are enforced at execution time instead of checked after the fact.

  2. Archival record boxes on shelves, linked together by a steel chain.
    02

    Hash-chained evidence on every run

    Each run produces a hash-chained, replayable record of who did what, which version ran, and what the outcome was: an audit pack that builds itself.

  3. A secure on-premise server room aisle between two rows of dark racks.
    03

    Deployment you control

    Run customer-controlled: on-prem, in your own cloud account, or air-gapped, so data residency and sovereignty stay in your hands.

§ 02 · Frameworks

Built for the frameworks you answer to.

The same governed run supports the regulatory frameworks you are measured against, so evidence comes from running the process instead of a separate compliance project bolted on after the fact.

DORA

Binding since Jan 2025

Financial entities must prove operational resilience for their critical processes.

With Kora
  • Critical processes run under release control with full runtime observability, so you can show a regulator how a process behaves.
  • Every run leaves a hash-chained record: proof of what happened, not a reconstruction after the fact.
  • Enterprise adds a DORA Chapter 5 addendum: audit rights, exit strategy, concentration-risk disclosure, and incident reporting.

EU AI Act

High-risk AI · from Dec 2027

High-risk AI must run under human oversight and log its operation automatically.

With Kora
  • Agents act under scoped permissions, with human approval on the decisions that carry risk.
  • Every agent action is captured in the run, so how a decision was reached is a lookup, not a reconstruction.
  • The record-keeping the Act expects for high-risk (Annex III) systems, produced automatically on every run.

SOX

Internal controls (ICFR)

Management is accountable for internal controls over financial reporting.

With Kora
  • Segregation of duties, approvals, and access rules live in the released process, enforced as it runs.
  • Change management runs through release control, so every control change ships audited.
  • Each run leaves a hash-chained record of who did what: control evidence is a lookup, not a year-end scramble.

MiFID II

Transaction reporting

Investment firms must keep complete, reconstructable records of what they report and why.

With Kora
  • Reporting runs as a governed workflow: agentic validation and enrichment propose, a person approves exceptions.
  • Every submission leaves a hash-chained record you can replay field by field.
  • The reporting trail builds itself as the chain runs, ready for the regulator.
§ 03 · Evidence

The audit trail every run leaves.

Compliance evidence is a byproduct of running the process, captured the moment it happens, not assembled from logs in the week before an audit.

  1. Captured as it runs

    Each run is observed, logged, and hash-chained into an append-only record: step timings, hashed inputs and outputs, and the human approval chain, tagged with the released version, environment, and deployment.

  2. Replayable to the same digest

    Open any run and replay it to the same cryptographic digest, then hand the record to an auditor without rebuilding history from logs. Signing and anchoring are handled by a downstream system.

  3. Two evidence layers

    A control-plane audit log of who changed what sits alongside the runtime record of what each run did, so process changes and process runs are both accounted for.

§ 04 · The payoff

Compliance without the scramble.

The same governed runs that get the work done execute compliance controls and produce evidence for your compliance program, so evidence collection and control testing stop being a separate project.

  • Evidence that builds itself

    Every run writes its hash-chained record as the work happens, so the evidence exists the moment the process finishes.

  • Controls enforced at execution time

    Approvals, segregation of duties, and access rules run inside the released process, not as after-the-fact checks.

  • An audit that is a lookup

    Open the run, replay it to the same digest, and hand the record over, with no history to reconstruct.

  • One record, many regimes

    One governed record contributes evidence relevant to DORA, the EU AI Act, SOX, and MiFID II, instead of each regime becoming its own project.

§ 06 · FAQ

Questions, answered.

What teams ask when they evaluate Kora for this problem.

DORA asks for demonstrable operational resilience. Kora gives critical processes release control, runtime observability, and hash-chained evidence on every run, so you can show regulators how a process behaves and prove what actually happened.

The EU AI Act expects high-risk AI to run under human oversight and to keep automatic logs of its operation. In Kora, AI agents act under scoped permissions, people approve the decisions that carry risk, and every agent action is captured in the run, so the record the Act expects for high-risk (Annex III) AI systems is produced automatically on every run.

A hash-chained, replayable audit trail per run: the process version that executed, every human, system, and AI action, approvals with their owners, and the final outcome.

An append-only log where each entry includes a cryptographic hash of the previous one, so records cannot be silently edited or reordered without breaking the chain. Kora writes one for every workflow run, can replay the run to the same digest to prove the record is intact, and the record is designed to feed the tamper-evident or WORM retention systems some regimes require.

Yes. Kora installs from a Docker Compose bundle and deploys customer-controlled: on-prem, in your own cloud account, or fully air-gapped. The runtime and every workflow run inside your environment.
§ 07 · Next step

Bring one control you have to evidence.

In a demo, bring a process your auditors ask about. We will run it as a governed workflow and show the hash-chained, replayable record each run leaves for the frameworks you answer to.