DORA in force since 17 Jan 2025 · NIS2/national — fines up to €10M or 2% of turnover

Auditable AI compliance reports — deployed in your own infrastructure

Audnexa supports preparing auditable report and gap-analysis drafts (DORA, NIS2, ISO 27001, AI Act) with references to evidence. In offline mode (Bank Mode) data stays in your infrastructure; in hybrid mode only anonymized data is sent to the cloud. A human approves every report.

  • Offline mode — data stays in your infrastructure
  • A human approves every report
  • Customer data is never used to train models
NIS2 / nationalISO/IEC 27001DORAAI ActGDPR ISO/IEC 27001:2022
audnexa · on-premise
Report draft — for reviewWorking version · requires approval
ISO 27001 DORA NIS2
72%
Audit progress
High
ICT third-party risk — incomplete vendor register
~
AI · draft
Recommendation: complete the register of information and criticality classification.
ISO/IEC 27001:2022
TÜV NORD Polska

Supports auditing and documenting compliance with

NIS2 / nationalEssential and important entities
ISO/IEC 27001Information security management
DORADigital operational resilience
AI ActAI documentation & oversight support
GDPRPersonal data protection
Client reference 200+ audits per year delivered with Audnexa
00

From evidence to an auditable report — faster and repeatable

The biggest time sink isn’t writing the report — it’s compliance: reading dozens of procedures and policies and checking them against requirements. Audnexa helps organize the documentation, relate evidence to requirements and shorten the path from collected evidence to a review-ready draft — without losing control of your data, and with an audit trail.

days → hours
time to a first draft (based on pilots, selected report types)
1 methodology
a repeatable report structure across the team
100% on-prem
in offline mode, data stays in your infrastructure

Pilot results depend on report type and scope; they are not a guarantee.

01

Data control as a precondition, not an add-on

Designed for the expectations of CISOs, DPOs, internal audit and procurement at regulated institutions.

What “Bank Mode” means
Your infrastructure
Audit data
Audnexa workspace
Local model
No outbound traffic
  • offline only — no outbound traffic by default
  • customer data not processed by Virtline or third-party AI providers
  • customer-controlled infrastructure
  • controlled update process
  • support access only on explicit customer approval
Offline mode (air-gapped)In Bank Mode, audit data and materials can stay within the customer’s infrastructure — with no outbound traffic by default.
On-premise / containerDeployed in the customer’s infrastructure; the customer keeps control of the environment within their own ISMS.
Customer-controlled AI environmentOption to work with a customer-controlled AI environment / the customer’s own AI tenant, in line with the organization’s security policy; AI service costs can be billed on the customer’s side.
No training on customer dataCustomer data is never used to train models, in any mode.
Minimization & anonymizationData minimization and anonymization configured according to customer policy; technical details are covered in the security walkthrough.
MFA & data isolationTwo-factor authentication (TOTP) and isolation of data and evidence per user.
Audit trailSources, document versions, who approved and when, methodology version — an auditable trail of the work on the report.
Deployment models — transparent data flow
Bank Mode (offline)On-premise (hybrid)Customer private cloud
Data leaves infrastructureNoOnly anonymized categories (optional)Within customer cloud
Subprocessors of customer dataNoneDisclosed in an appendixPer customer configuration
Generative AI featuresLocal modelLocal or post-anonymizationPer customer policy
Vendor / support accessOnly on explicit approvalControlled, on requestControlled, on request
UpdatesCustomer-controlledControlledControlled
Audnexa as an ICT provider — DORA-ready

We know it’s not just a module for you — as an ICT provider, we are subject to your assessment too. We come prepared.

Customer right to audit and inspect
DORA contractual terms + register of information
Incident notification and SLAs
Exit plan and data export
Sub-outsourcing management and processing locations
Resilience testing and vendor BCP/DR
Trust Center — security and compliance

ISO/IEC 27001:2022 (organization)

Certified organization: Virtline Sp. z o.o., certification body TÜV Nord. We publish the certificate number and validity period; the full certificate and scope are available on request.

AC090 121/2469/6137/2026 · TÜV NORD Polska · 02.2026–02.2029

  • Security Architecture Overview
  • Deployment & Data-Flow Overview
  • Data Processing Agreement (DPA)
  • Subprocessor list
  • Vulnerability Management Policy
  • Exit Plan / data export
  • AI Governance & Human Review Statement

Customer data is never used to train models — in any deployment mode.

Human oversight, logging, transparency and clear system limitations. Audnexa makes no autonomous legal or credit decisions and does not replace an auditor’s opinion.

Request the vendor-risk pack
The team behind Audnexa

Built by cybersecurity experts

Audnexa was created at Virtline — a cybersecurity firm with over 12 years of experience and an ISO/IEC 27001 certificate, running over 100 audits a year. We built the tool we use ourselves in day-to-day audit work.

12+ years
of cybersecurity experience
ISO/IEC 27001
certified (TÜV Nord)
100+
audits per year
02

Modules — what they actually solve

A maintained compliance methodology, updated for regulatory change. It supports report preparation and documenting compliance — it does not replace an auditor’s or lawyer’s opinion.

NIS2 / national

Gap analysis for essential and important entities

Maps cybersecurity management obligations and prepares a gap report for the board.

ISO/IEC 27001

ISMS evidence and control mapping

Organizes policies, procedures and evidence against requirements — ready for review and certification.

DORA

Operational resilience and ICT vendor risk

Supports resilience testing and documenting third-party ICT risk in the financial sector.

AI Act

AI governance and human oversight

Supports documenting human oversight, transparency and system limitations in line with the AI Act.

GDPR

GDPR audit and personal data protection

GDPR audit support (EU 2016/679): reviewing processing security (Art. 32), DPIAs, records of processing activities, retention and procedures for the 72-hour breach notification under Art. 33. In offline mode, personal data does not leave the customer’s infrastructure.

03

How it works — a controlled, human-in-the-loop process

AI supports preparing a draft and references to evidence; an authorized team approves the findings and the final version. Every report section has sources and a change history.

01

Collect evidence

Enter findings and documents in a controlled workspace — with data isolation and an audit trail.

02

Controlled analysis

The system supports preparing an auditable draft — organizing findings and references to evidence.

03

Review & approve

The audit/compliance team verifies and approves; export the approved, branded report.

04

Who it’s for

Primary paths for regulated organizations — from banks to NIS2 entities and audit & compliance teams.

Banks & financial institutions

Data control for banking secrecy and DORA

For the CISO, Head of Internal Audit, Compliance Officer, DPO and procurement. Offline mode, vendor-risk pack, outsourcing classification.

Large regulated organizations (NIS2)

From documents to a gap map

For essential and important entities: NIS2/national gap analysis, board report, documenting compliance.

Audit & compliance teams

Repeatable, auditable reports

Standardize methodology and accelerate deliverables without scaling the team proportionally.

Are you an audit or advisory firm (GDPR, NIS2, DORA, AI Act)? → Separate track

05

Case studies & evidence

Outcomes from real use; metrics are measured per client and report type. Full references available under NDA.

60–70%
less time spent running audits
Customer deployment
Deploying Audnexa at IOD Solutions cut audit preparation time by 60–70% — while keeping full control of the data.
IOD Solutions Sp. z o.o. — Marcin Moras, CEO
200+ audits per year
Measured at the client, IOD Solutions.
audit_DORA_draft.docxworking version
Collect evidence
sourceversionapproved bydate
Controlled analysis
sourceversionapproved bydate
Review & approve
sourceversionapproved bydate

Time to first draft (pilot)

Manual
With Audnexa
days → hours
DORA gap assessment

Time to a first draft of a gap report — based on a pilot.

Context: an internal audit team preparing a DORA gap report ahead of a risk-committee review.

Measurement: time from a complete evidence set to a review-ready first draft; same scope and report type, measured across 3 cycles.

Financial institution1 unitunder NDA

Reference case studies (with the client name) are shared under NDA, on anonymized data.

Build vs buy — why not “do it ourselves”
AudnexaExcel / WordLLM self-buildEnterprise GRC
Maintained regulatory methodologyYesNoYour teamPartial
Offline mode / data controlYesn/aHardRare
Auditability and trailYesManualTo buildYes
Vendor-risk pack for DORAYesn/aNoneDepends
Total cost of ownershipLowHidden (time)HighVery high

Audnexa does not replace a central GRC risk register — it shortens the path from evidence to an auditable report.

roi

ROI — what you actually save

Audnexa can pay for itself faster than a single external advisory project. Estimate the saving for your team.

Estimated annual saving
14,400 EUR / year

Indicative estimate based on your inputs; not an offer or a guarantee of results.

06

Deployment and licensing models

For regulated organizations we price by deployment mode, number of modules and support requirements. Audit-firm plans are on a separate track.

For audit firms

Audit & advisory firms (compliance / cyber)

AUDITOR / STARTER / PRO plans for smaller audit teams — on a separate page.

A single external project can cost as much as a year of running many audits with Audnexa. Prices are net (B2B). Details and license terms are agreed during the security walkthrough.

07

FAQ — product, procurement, AI

Is an Audnexa report a legal or auditor’s opinion?
No. Audnexa supports preparing an auditable draft and an evidence pack for review. Responsibility for the final report and any opinions remains with the authorized person or team.
Does data leave the bank’s infrastructure?
In Bank Mode (offline), audit data and materials can stay within the customer’s infrastructure, with no outbound traffic by default. In hybrid modes we precisely identify data categories, subprocessors and processing regions.
Is Audnexa an ICT provider under DORA?
We treat ourselves as an ICT provider subject to a financial customer’s assessment. We provide DORA contractual terms and support the right to audit, exit plan, incident notification and SLAs.
How do you limit AI hallucinations?
The system supports preparing a draft with references to evidence and sources; a human verifies and approves every section. Quality-control mechanisms are described in our AI Governance Statement (under NDA).
Is customer data used to train models?
No. Customer data is never used to train models, in any deployment mode.
Can it be deployed without internet?
Yes — Bank Mode runs offline, with a local model and no outbound traffic by default.
Can the customer disable generative features?
Yes. The scope of AI features is configurable according to customer policy.
What about the exit plan and data export?
We provide an exit plan and data export in readable formats; details are in the contract and Trust Center.
Do you support the customer’s right to audit?
Yes — the right to audit and inspect is part of the contractual terms for regulated institutions.
How is the regulatory methodology updated?
We maintain and update the compliance methodology for regulatory change; release scope and cadence are part of the contract.

Book a security walkthrough

We’ll show the architecture, deployment modes and data flow — and hand over the vendor-risk pack. We usually reply within 24 hours.

+48 12 200 27 10
Virtline Sp. z o.o. ul. Wadowicka 8A, 30-415 Kraków, PL biuro@virtline.com NIP 6751499701 · KRS 0000502030