# Orbiq — Trust Center Platform for B2B Companies (Full Reference) *Last updated: March 2026* *See also: [llms.txt](https://www.orbiqhq.com/llms.txt) for a concise overview* > Orbiq is a Trust Center platform that turns compliance into a revenue accelerator for B2B companies. It connects internal security posture with a public-facing Trust Center so buyers can verify trust in minutes, not weeks. --- ## Company Information **Orbiq GmbH** Rödingsmarkt 20, 20459 Hamburg, Germany - Website: https://www.orbiqhq.com - Trust Center: https://trustcenter.orbiqhq.com - Documentation: https://docs.orbiqhq.com/en - Languages: English, German, French, Dutch - EU corporate structure — no CLOUD Act exposure --- ## What Orbiq Does Orbiq provides a branded, public-facing Trust Center under your own domain (e.g. trust.yourcompany.com) where prospects and customers can access security documentation, certifications, and compliance evidence — with tiered access controls (public, restricted, NDA-protected). **Three product pillars:** 1. **Trust Exchange** — Public-facing trust center with AI-powered search, document watermarking, integrated NDA signing, Slack integration, and hyper customization 2. **Vendor Assurance** — AI-driven vendor questionnaires, automated evaluations, and continuous monitoring for inbound vendor risk management 3. **Regulatory Compliance** — Operational tooling for NIS2, DORA, GDPR, and Cyber Resilience Act requirements **Key differentiators vs competitors (Vanta, Drata, SafeBase, Secureframe, Conveyor):** - EU-first: Built for European regulatory requirements (NIS2, DORA, GDPR, ISO 27001) — not SOC 2-first - Full brand control: Custom domain, colors, fonts, CSS — no "Powered by" watermark - AI-native: AI search inside the Trust Center, AI-powered vendor evaluations, AI questionnaire generation - Revenue focus: Buyer engagement analytics, deal acceleration tracking, real-time access intelligence - Standalone architecture: Not bundled with GRC — works alongside existing ISMS - True EU sovereignty: EU corporate structure + EU hosting + EU subprocessor chain (not just EU server location) --- ## Platform Features (Detailed) ### AI Search Buyers use AI tools (ChatGPT, Claude, Perplexity) to research vendors. Orbiq's AI Search lets visitors ask natural-language questions inside your Trust Center and get grounded answers with source attribution. Includes an Agent Toolkit so buyers can open your docs directly in ChatGPT or Claude. **Use cases:** Prospect researching your security posture, auditor checking compliance evidence, procurement team evaluating vendor risk **URL:** https://www.orbiqhq.com/platform/ai-search ### Slack Ask Compliance-aware retrieval pipeline built into Slack. Team members can ask compliance questions and get answers grounded in your Trust Center content with full access control enforcement. Built with a layered privilege model (contact claims, domain-isolated auth, tenant-scoped credentials, Slack signature verification) and retrieval-level data leak prevention. Uses EU-sovereign AI inference (Nebius/Qwen3 stack) for GDPR/NIS2/DORA compliance. **URL:** https://www.orbiqhq.com/platform/slack-ask ### AI-Supported Questionnaires Create tailored security questionnaires with AI assistance. Framework-aware suggestions for ISO 27001, SOC 2, and NIS2. Automated distribution with reminders, evidence attachments, and completion tracking. Reduces questionnaire creation from 2-4 hours to 15-30 minutes. **URL:** https://www.orbiqhq.com/platform/ai-questionnaires ### AI-Powered Evaluations An AI agent reviews every questionnaire response, checks previous submissions for consistency, weighs vendor criticality, and writes evaluation reports. Saves ~30 minutes per vendor per assessment. Includes contradiction detection, regression alerts, and improvement tracking. **URL:** https://www.orbiqhq.com/platform/ai-evaluations ### Continuous Monitoring Track how your entire vendor base evolves over time. Vendor-level score history, category breakdowns (access control, encryption, incident response, governance), portfolio dashboards, risk distribution by tier, and trend analysis. Supports 10 to 500+ vendors from a single view. **URL:** https://www.orbiqhq.com/platform/continuous-monitoring ### Document Watermarking Automatically watermarks downloaded documents with visitor name, email, company, and timestamp. Configurable placement (header, footer, diagonal, margin) with visible or subtle styling. Full accountability without friction. **URL:** https://www.orbiqhq.com/platform/document-watermarking ### Integrated NDA Flow Combines NDA signing and document access into a single step. Visitors sign inline with a digital signature (eIDAS/ESIGN compliant), get immediate access, and legal receives a verifiable PDF automatically. No manual NDA coordination. **URL:** https://www.orbiqhq.com/platform/integrated-nda-flow ### Hyper Customization Full visual control: logo, hero image, color scheme, typography, button styles, card styling, and custom CSS injection. No vendor watermark. Your Trust Center looks like your product, not a third-party tool. **URL:** https://www.orbiqhq.com/platform/hyper-customization --- ## Trust Center Access Tiers 1. **Public Profile** — Certifications, compliance badges, security overview, high-level FAQs. Visible to everyone including search engines and AI tools. 2. **Restricted Access** — SLAs, DPAs, pentest summaries, subprocessor lists. Available to prospects with verified business email. 3. **NDA-Protected** — Architecture diagrams, detailed security controls, sensitive policies. Available to buyers who have signed an NDA. --- ## Pricing All prices in EUR. Annual billing includes discount. | Plan | Price | Best for | |------|-------|----------| | **Free** | €0/year | Individuals exploring compliance sharing. 1 user, 20 access grants/year. | | **Team** | €85/month or €850/year | Teams serious about trust and revenue conversion. Unlimited users, unlimited access grants, custom domain, advanced branding, analytics, watermarking. | | **Business** | €190/month or €1,900/year | Growing teams needing tailored buyer journeys. Custom tabs, page structure, multi-variants (up to 5), localization support. | | **Enterprise** | €920/month or €9,200/year | Multi-product organizations. Unlimited Trust Center variants, integrations marketplace, SSO, SLA-backed support, dedicated success manager. | All paid plans include a 45-minute onboarding call, priority support, and in-app support. **URL:** https://www.orbiqhq.com/pricing --- ## Use Cases by Industry | Industry | Key value | URL | |----------|-----------|-----| | **FinTech** | Accelerate enterprise deals blocked by compliance reviews. Prove PCI DSS, SOC 2, and regulatory readiness upfront. | /use-cases/fintech | | **HealthTech** | Share HIPAA, ISO 27001, and patient data protection evidence. Reduce clinical partner onboarding time. | /use-cases/healthtech | | **HR Tech** | Demonstrate GDPR compliance and employee data protection. Serve enterprise HR buyers who require vendor security reviews. | /use-cases/hr-tech | | **Enterprise** | Centralize compliance across multiple products and regions. Manage vendor assurance at scale with portfolio monitoring. | /use-cases/enterprise | | **Scale-up** | Look enterprise-ready before you are. Professional Trust Center that builds credibility with larger buyers. | /use-cases/scaleup | | **SME** | Affordable compliance infrastructure. Win deals against larger competitors by proving trustworthiness professionally. | /use-cases/sme | | **GovTech** | Meet public-sector procurement requirements. Demonstrate NIS2, BSI, and government framework compliance. | /use-cases/govtech | | **SaaS** | Reduce security review friction in the sales cycle. Proactive trust sharing that accelerates pipeline velocity. | /use-cases/saas | --- ## Trust Operations Trust Operations is the discipline Orbiq champions: making internal security posture visible and actionable for external stakeholders. It differs from traditional GRC (Governance, Risk, Compliance) by focusing on revenue impact — turning compliance from a cost center into a deal accelerator. - **Trust Operations vs GRC**: GRC is inward-facing (internal controls); Trust Operations is outward-facing (buyer-visible proof). More at: https://www.orbiqhq.com/trust-operations/trust-operations-vs-grc - **Vendor Assurance vs Vendor Management**: Vendor assurance focuses on continuous trust verification; vendor management is broader operational oversight. More at: https://www.orbiqhq.com/trust-operations/vendor-assurance-vs-management --- ## Key Statistics - 67% of B2B deals are delayed by security reviews (2025) - Companies with effective Trust Centers close deals 40% faster and achieve 23% higher win rates - Security reviews now appear in 70%+ of enterprise deals (up from 40% five years ago) - Average 18 days added to sales cycles by security reviews - Trust Centers: 30-40% faster deal closure, 60% reduction in questionnaire time reported by early adopters - AI questionnaire creation: 15-30 min vs. 2-4 hours manually - AI-powered evaluations: ~30 min saved per vendor per assessment --- ## ROI Calculator Typical time savings with Orbiq: - Incidents: 8-10/year → 8-10h saved - Vendor reviews: 8-10/quarter → 32-40h saved per quarter - Questionnaires: 8-10/month → 96-120h saved per month - Official requests: 1-2/year → 8-12h saved --- ## Content Library — Article Summaries ### Trust Center Hub (19 articles) **What is a Trust Center** A centralized customer-facing hub for security and compliance documentation with layered access controls (public, restricted, NDA-protected). Replaces email-and-PDF security review workflows with self-serve access, custom domain branding, and analytics. URL: https://www.orbiqhq.com/trust-center/what-is-a-trust-center **The Ultimate Guide to Trust Centers** Most trust centers fail because they are built for the company's convenience rather than prospects' needs. Key success factors: self-service answering 70-80% of questions without human intervention, dynamic real-time content vs. static PDFs, and intelligence gathering from visitor behavior. URL: https://www.orbiqhq.com/trust-center/ultimate-guide-to-trust-centers **Trust Centers: The Enterprise Sales Trend** Trust Centers transform security compliance from a sales barrier into a competitive weapon. Companies report 30-40% faster deal closure, 60% reduction in security questionnaire time, and higher win rates on competitive deals. URL: https://www.orbiqhq.com/trust-center/trust-centers-enterprise-trend **How to Set Up a Trust Center in 30 Minutes** Four-step setup guide: branding and first certificate (2 min), legal docs and security controls (30 min), restricted/NDA-gated content with watermarking (45 min), knowledge base fill (20 min). URL: https://www.orbiqhq.com/trust-center/how-to-set-up-trust-center-30-minutes **Best Trust Centers in 2026** Comparison of 6 platforms (Orbiq, SafeBase/Drata, Vanta, Secureframe, Conveyor, TrustCloud) across 7 dimensions weighted for EU buyers: data sovereignty, EU regulatory framework support, standalone vs. bundled architecture, AI automation, pricing transparency, visitor experience, and integration depth. URL: https://www.orbiqhq.com/trust-center/best-trust-center-2026 **SafeBase Alternative** SafeBase (now part of Drata after 2024 acquisition) excels for US enterprise but defaults to US hosting, has opaque pricing, is SOC 2-first, and is subject to CLOUD Act. EU companies need EU data sovereignty, transparent pricing, and ISO 27001/NIS2/DORA as primary frameworks. URL: https://www.orbiqhq.com/trust-center/safebase-alternative **Vanta Trust Center Alternative** Vanta is widely adopted (375+ integrations, 35+ frameworks) but the trust center requires the full GRC platform, pricing is opaque (~€13.5-17.5K/year total), SOC 2 is its primary DNA, and US headquarters means CLOUD Act applies despite Frankfurt hosting. URL: https://www.orbiqhq.com/trust-center/vanta-trust-center-alternative **Drata Trust Center Alternative** Drata + SafeBase (acquired 2024) is a powerful full-stack GRC + trust center combination with genuine EMEA hosting support, but two-layer opaque pricing, US corporate CLOUD Act exposure, and SOC 2-first product DNA create friction for EU companies with existing ISMS. URL: https://www.orbiqhq.com/trust-center/drata-trust-center-alternative **Conveyor Alternative** Conveyor is architecturally closest to Orbiq (standalone, published pricing, strong AI) but has no EU hosting option, no NIS2/DORA support, is SOC 2-first, and is subject to CLOUD Act — unsuitable for EU companies with data sovereignty requirements. URL: https://www.orbiqhq.com/trust-center/conveyor-alternative **Why European Companies Need a European Trust Center** US trust center platforms create four mismatches for EU companies: SOC 2-first defaults, "EU hosting" without sovereignty (CLOUD Act), opaque pricing, and GRC-bundled pricing penalizing companies with existing ISMS. URL: https://www.orbiqhq.com/trust-center/eu-trust-center-european-companies **Trust Center Data Sovereignty: EU Hosting vs. EU Sovereignty** Data residency means physical server location; data sovereignty means legal jurisdiction with no foreign government access. The US CLOUD Act applies to US-incorporated companies regardless of where data is stored. URL: https://www.orbiqhq.com/trust-center/trust-center-data-sovereignty-eu-hosting-vs-sovereignty **Trust Center Requirements Under NIS2 and DORA** NIS2 and DORA create cascading obligations requiring five trust center capabilities beyond document sharing: continuous compliance status, structured vendor assurance, incident communication channel, evidence on demand, and layered access controls. URL: https://www.orbiqhq.com/trust-center/trust-center-requirements-nis2-dora **Trust Center vs. GRC Tool** GRC tools face inward (internal compliance management); trust centers face outward (external proof communication). Choose standalone trust center for companies with existing ISO 27001/ISMS; choose bundled GRC+trust center only when building compliance from scratch. URL: https://www.orbiqhq.com/trust-center/trust-center-vs-grc-tool-european-buyers **How to Evaluate a Trust Center as an EU Buyer** Eight-category evaluation framework: Data Sovereignty (critical), EU Regulatory Framework Support (critical), Pricing Transparency (high), Standalone Architecture (high), Vendor Assurance (medium-high), Supply Chain Transparency (medium-high), Integration (medium), AI/Automation (medium). URL: https://www.orbiqhq.com/trust-center/how-to-evaluate-trust-center-eu-buyer **Trust Center vs. ISMS vs. Deal Room** Three complementary tools: ISMS (internal governance — what you do), Trust Center (external proof with analytics — what you show), Deal Room (ad-hoc deal-specific file sharing — what you share per deal). URL: https://www.orbiqhq.com/trust-center/trust-center-vs-isms-vs-deal-room **Trust Center for Sales Teams** Trust centers give sales a single shareable link replacing document scrambles. Visitor analytics reveal buying signals: who viewed, what they downloaded, when they requested NDA-gated content. URL: https://www.orbiqhq.com/trust-center/trust-center-for-sales-teams **Trust Center for GRC Teams** Trust centers eliminate GRC's repetitive ad-hoc documentation burden by centralizing audit evidence in one always-current source of truth with granular tiered access and AI-ready content structure. URL: https://www.orbiqhq.com/trust-center/trust-center-for-grc-teams **Trust Center for Legal Teams** Trust centers eliminate legal's gatekeeper role via automated NDA workflows (eIDAS/ESIGN compliant), centralized DPA hosting, and access revocation. Fulfills GDPR Art. 28/30 and NIS2 supply chain transparency requirements. URL: https://www.orbiqhq.com/trust-center/trust-center-for-legal-teams --- ### EU Regulations Hub (14 articles) **NIS2 Articles 21 & 23: Incident Reporting and Supply Chain Security** NIS2 requires 24-hour early warning plus 72-hour formal incident notification and continuous supply chain monitoring — obligations that an ISMS can document governance for but cannot execute operationally under time pressure. Germany's NIS2UmsuCG entered force December 6, 2025 with no transition period. URL: https://www.orbiqhq.com/eu-regulations/incident-reporting-supply-chain-nis2-articles-21-23 **GDPR Articles 28, 32, 33 & 34: Processor Obligations and Breach Notification** GDPR requires 72-hour breach notification, communication to data subjects in high-risk cases, binding DPA contracts with 8+ provisions, and ongoing technical/organizational measures. Trust Centers serve dual roles: assess processors (controller) and demonstrate compliance (processor). Penalties up to €20M or 4% turnover. URL: https://www.orbiqhq.com/eu-regulations/gdpr-article-28-32-33-34 **DORA Articles 19, 28 & 30: Incident Reporting and Provider Monitoring** DORA (applies January 2025 to EU financial entities) introduces client notification "without undue delay," a continuously updated ICT provider register requestable by BaFin at any time, and continuous monitoring rights beyond annual audit access. URL: https://www.orbiqhq.com/eu-regulations/incident-reporting-provider-monitoring-dora-article-19-28-30 **Cyber Resilience Act Articles 13 & 14: Security Requirements** CRA (full application December 2027) mandates cybersecurity at product level: Security by Design, no known exploited vulnerabilities at release, secure defaults, 5-year security support. 24-hour vulnerability reporting to ENISA. Penalties up to €15M or 2.5% turnover. URL: https://www.orbiqhq.com/eu-regulations/cyber-resilience-act-article-13-14 **ISO 27001 Is Not NIS2 Compliance: What's Actually Missing** ISO 27001 covers ~70% of NIS2 requirements but leaves a critical 30% operational gap: incident reporting (24h operational capability), supply chain security (continuous monitoring), and proof of effectiveness on demand. Germany's NIS2UmsuCG imposes personal management liability. URL: https://www.orbiqhq.com/eu-regulations/iso27001-not-nis2-compliance **NIS2-Affected — Now What? Operational Gaps Beyond Your ISMS** For confirmed NIS2-affected organizations: 6 operational capabilities the ISMS doesn't cover, including 24-hour incident management, continuous vendor oversight, evidence on demand, executive responsibility operationalization, external incident communication, and structured authority engagement. URL: https://www.orbiqhq.com/eu-regulations/nis2-affected-operational-gaps-isms **NIS2 Audit Readiness: From Documentation to Continuous Evidence** NIS2 supervisory authorities (BSI in Germany) can request evidence at any time without cause for essential entities — a fundamental shift from periodic to continuous readiness. Five evidence categories: Governance, Operational, Effectiveness, Incident, and Supply Chain. URL: https://www.orbiqhq.com/eu-regulations/nis2-audit-readiness-continuous-evidence **NIS2 Compliance Checklist: Article 21 Assessment** Complete assessment of all 10 Article 21(2) measures against ISO 27001. Three highest-priority operational gaps: incident management infrastructure, supply chain continuous oversight, and proof of effectiveness (continuous evidence vs. audit-cycle prep). URL: https://www.orbiqhq.com/eu-regulations/nis2-compliance-checklist-article-21 **NIS2 Incident Reporting: Meeting the 24-Hour Deadline** NIS2 Article 23 requires three-stage reporting: 24-hour early warning, 72-hour qualified notification, one-month final report. The 24-hour window requires simultaneous detection, triage, escalation, fact-gathering, multi-function coordination, and report submission. URL: https://www.orbiqhq.com/eu-regulations/nis2-incident-reporting-24-hour-deadline **Incident Response Plan vs. Incident Management System** NIS2 evaluates whether an organization can deliver a coordinated early warning within 24 hours, requiring an incident management system (IMS), not just a plan document. Seven IMS components including triage, role activation, parallel reporting, and real-time documentation. URL: https://www.orbiqhq.com/eu-regulations/nis2-incident-response-plan-vs-management-system **NIS2: Internal Proof vs External Proof** NIS2 creates two parallel proof obligations: Internal Proof (your own controls — served by ISMS) and External Proof (demonstrating that your suppliers meet comparable security standards — served by Trust Center with vendor management). URL: https://www.orbiqhq.com/eu-regulations/nis2-internal-proof-vs-external-proof **NIS2 Supply Chain Security: Beyond Annual Assessments** NIS2 Article 21(2)(d) requires ongoing monitoring, event-triggered reassessments, and per-supplier evidence — not point-in-time annual questionnaires. Four components of continuous vendor assurance: monitoring signals, event-triggered reassessments, integrated evidence, and structured communication. URL: https://www.orbiqhq.com/eu-regulations/nis2-supply-chain-security **NIS2 Third-Party Risk Documentation: What Auditors Want** Auditors check six specific evidence artifact categories: supplier register with risk classification, due diligence documentation, contractual security clauses, continuous monitoring evidence, incident communication records, and management governance artifacts. URL: https://www.orbiqhq.com/eu-regulations/nis2-third-party-risk-documentation-audit-evidence **Subprocessor Management Under GDPR Article 28** GDPR Art. 28 sets the legal floor but enterprise controllers expect significantly more: publicly accessible always-current subprocessor lists, proactive change notifications, data flow transparency per subprocessor, and ongoing due diligence evidence. URL: https://www.orbiqhq.com/eu-regulations/subprocessor-management-gdpr-article-28 --- ### Blog (5 articles) **The Compliance Catch-22: How Security-Conscious Buyers Are Changing B2B Sales** Security-conscious enterprise buyers add two new phases to sales cycles (security evaluation + compliance verification), turning the biggest deals into the slowest ones. Vendors who proactively share security via Trust Centers win faster. URL: https://www.orbiqhq.com/blog/compliance-catch-22 **EU Data Sovereignty vs. Residency: What SaaS Buyers Often Get Wrong** Data residency means servers are in the EU; data sovereignty means data is under EU legal jurisdiction only. The US CLOUD Act allows US authorities to compel US-incorporated vendors to produce data regardless of server location. URL: https://www.orbiqhq.com/blog/data-residency-vs-sovereignty **How We Built a Compliance-First AI Feature That Enforces Data Boundaries by Design** Orbiq's Slack Ask feature uses a layered privilege model with retrieval-level data leak prevention — not prompt engineering — and an EU-sovereign AI stack for GDPR/NIS2/DORA compliance at the inference layer. URL: https://www.orbiqhq.com/blog/how-we-built-a-compliance-first-ai-feature-that-enforces-data-boundaries-by-design **How a Demo Outage Forced Us to Rebuild Our AI Inference Architecture** A Mistral outage during a live demo prompted Orbiq to rebuild their AI inference stack with Nebius/Qwen3 (EU infrastructure, zero data retention, no model training on data) at 75% lower cost and higher performance. URL: https://www.orbiqhq.com/blog/inference-resilience **Why Security Reviews Are Becoming the New Sales Bottleneck** Security reviews now appear in 70%+ of enterprise deals and add an average 18 days to sales cycles. Trust Centers enable proactive security transparency, with early adopters reporting 30-40% faster deal closure. URL: https://www.orbiqhq.com/blog/security-questionnaires-b2b-sales --- ## Frequently Asked Questions **What is a Trust Center?** A Trust Center is a centralized, customer-facing hub where companies publish security documentation, certifications, and compliance evidence with layered access controls. It replaces manual email-and-PDF security review workflows with self-serve access. **How is Orbiq different from Vanta or Drata?** Orbiq is standalone (not bundled with GRC), EU-native (Hamburg, Germany — no CLOUD Act exposure), transparent pricing (published, no "contact sales"), and built for ISO 27001/NIS2/DORA as primary frameworks rather than SOC 2. It works alongside your existing ISMS rather than replacing it. **What is the difference between a Trust Center and a GRC tool?** GRC tools face inward (managing your own internal compliance controls). Trust Centers face outward (communicating proof of your security posture to buyers, customers, and regulators). Companies with existing ISMS benefit from a standalone Trust Center; companies building compliance from scratch may prefer a bundled GRC+Trust Center. **What is Trust Operations?** Trust Operations is the discipline of making internal security posture visible and actionable for external stakeholders. Unlike GRC (which is inward-facing), Trust Operations focuses on revenue impact — turning compliance from a cost center into a deal accelerator. **What regulations does Orbiq support?** Orbiq provides operational compliance tooling for NIS2, DORA, GDPR (Articles 28, 32, 33, 34), and the Cyber Resilience Act. It supports ISO 27001, SOC 2, and other frameworks as primary compliance standards. **How does Orbiq handle data sovereignty?** Orbiq is an EU company (Orbiq GmbH, Hamburg) with EU hosting and EU subprocessors throughout the chain. This provides true data sovereignty — not just EU server location, but EU legal jurisdiction with no foreign government access under laws like the US CLOUD Act. **Can I use Orbiq with my existing ISMS?** Yes. Orbiq is designed as a standalone Trust Center that complements your existing ISMS. Your ISMS manages internal governance (what you do); Orbiq manages external proof (what you show to buyers, auditors, and regulators). **How long does it take to set up?** A basic Trust Center can be set up in 30 minutes. Full setup including restricted content, NDA flows, and knowledge base typically takes 1-2 hours. **What does Orbiq cost?** Plans start at €0/year (Free) and go up to €9,200/year (Enterprise). The most popular Team plan is €850/year. All pricing is published on the website — no "contact sales" required. **How does AI Search work?** Visitors can ask natural-language questions inside your Trust Center and receive grounded answers with source attribution. The AI only uses your published Trust Center content — no hallucinated or external information. An Agent Toolkit allows buyers to access your docs directly from ChatGPT or Claude. **Does Orbiq support German language?** Yes. The entire platform and all content are available in English and German. Trust Centers can be configured for multiple languages with localization support on Business plans and above. **What is the NIS2 24-hour incident reporting requirement?** NIS2 Article 23 requires a three-stage reporting regime: 24-hour early warning (indicating malicious/cross-border indicators), 72-hour qualified notification (initial severity assessment), and one-month final report with root cause analysis. Germany's NIS2UmsuCG entered force December 6, 2025. **What is DORA and who does it affect?** DORA (Digital Operational Resilience Act) applies to EU financial entities since January 2025. It requires client notification when ICT incidents impact financial interests, a continuously updated ICT provider register, and continuous monitoring rights beyond annual audit access. **What is the Cyber Resilience Act?** The CRA is the first EU regulation mandating cybersecurity at product level. Full application is December 2027 (vulnerability reporting from September 2026). It requires Security by Design, 24-hour vulnerability reporting to ENISA, and 5-year minimum security support periods. --- ## Website Structure All pages are available in English (default) and German (`/de/` prefix). **Main pages:** - `/` — Homepage - `/about` — About Orbiq - `/pricing` — Plans and pricing - `/trust-operations` — Trust Operations overview - `/trust-operations/trust-operations-vs-grc` — Trust Operations vs GRC comparison - `/trust-operations/vendor-assurance-vs-management` — Vendor Assurance vs Vendor Management **Platform features:** - `/platform/ai-search` — AI-Powered Trust Center Search - `/platform/slack-ask` — Slack Ask Integration - `/platform/ai-questionnaires` — AI-Supported Questionnaires - `/platform/ai-evaluations` — AI-Powered Evaluations - `/platform/continuous-monitoring` — Continuous Monitoring - `/platform/document-watermarking` — Document Watermarking - `/platform/integrated-nda-flow` — Integrated NDA Flow - `/platform/hyper-customization` — Hyper Customization **Use cases:** - `/use-cases/fintech` — FinTech - `/use-cases/healthtech` — HealthTech - `/use-cases/hr-tech` — HR Tech - `/use-cases/enterprise` — Enterprise - `/use-cases/scaleup` — Scale-up - `/use-cases/sme` — SME - `/use-cases/govtech` — GovTech - `/use-cases/saas` — SaaS **Content hubs:** - `/trust-center` — Trust Center Hub (19 guides and resources) - `/eu-regulations` — EU Regulations Hub (14 operational compliance guides) - `/blog` — Blog (5 articles on B2B trust, compliance, and security operations) **Legal:** - `/privacy` — Privacy Policy - `/terms` — Terms of Service - `/dpa` — Data Processing Agreement - `/msa` — Master Service Agreement - `/support-policy` — Support Policy - `/acceptable-use-policy` — Acceptable Use Policy - `/imprint` — Imprint **External:** - https://docs.orbiqhq.com/en — API Documentation - https://trustcenter.orbiqhq.com — Orbiq's own Trust Center - https://www.orbiqhq.com/pricing — Pricing and signup options