← Insights

·open source, DORA, compliance

Open by choice: why a compliance tool should be auditable

A product that asks regulated firms to trust it with their data should let them read its code. Open source is not a giveaway here. It can underpin the exit plan.


There is something odd about asking a regulated firm to trust a closed box with its most sensitive data. The firm’s whole obligation is to know where that data goes and what touches it. A product that says “trust us, the inside is fine” is asking it to take on faith the one thing it is not allowed to take on faith.

This is why compliance software is the rare category where open source works as a feature rather than a concession.

When the code is open, a buyer’s own engineers and auditors can read what the system does with the data: how it decides what is sensitive, what it sends out, what it keeps, how it logs. They do not have to believe a datasheet. They can check. For a firm that will have to defend the choice to a supervisor, “we reviewed the source” is a stronger sentence than “the vendor assured us”. Reading the code does not, by itself, prove which version and configuration is actually running.

Open code also helps answer a question DORA forces every firm to ask: what happens if the supplier disappears. A closed product that shuts down takes its internals with it. An open one can be maintained, audited, and kept running by someone else, because the firm has the code. The open licence is not an exit plan by itself, but it is a strong foundation for the documented, tested exit plan DORA requires for ICT services supporting critical or important functions.

None of this means giving the work away. The model that fits is an open, auditable core with a proprietary layer on top for the parts that are a service rather than a mechanism: the turnkey compliance automation, the support, the managed hosting. The core earns trust by being readable. The layer earns revenue by being useful. The two are not in tension; the openness is what makes the paid part credible to the kind of buyer who reads licences.

GAIA-CORE will be released under GNU AGPLv3. Its repository remains private and no release date has been announced. The first obligation is clean title, a reproducible release, external review and a support plan. Until the release, inspection and continuity are provided through controlled diligence, agreed source access and escrow.