> ## Documentation Index
> Fetch the complete documentation index at: https://docs.molin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# DORA customer support

> Security evidence and contract support for financial-sector customers

Molin AI provides technology services to financial-sector customers.
DORA applies to the regulated customer, so each customer must assess whether Molin meets its requirements.

Visit the [Molin trust center](https://molin.ai/trust) to review our security information and request internal documents.

## Available now

* [security practices](./security-practices)
* [data processing addendum](./data-processing-addendum)
* [privacy policy](./privacy-policy)
* [subprocessor register](./subprocessors)
* [data retention policy](./data-retention-policy)
* [GDPR information](./gdpr)
* a platform data-flow overview
* security, access, encryption, monitoring, incident, recovery, AI, and vendor controls

## Internal documents

The trust center lists our current security policies individually.
Sign in with a Molin account, select the documents you need, and send an access request.
Approved documents appear in the trust center for a limited time.

Available policies include access control, information security, encryption, incident response, logging and monitoring, vendor management, backups, business continuity, and disaster recovery.
These documents are moving into Molin's internal compliance system, which will manage their versions and approvals.

## Recovery targets

Our current internal disaster recovery targets are:

* **RTO:** 4 hours
* **RPO:** 1 hour

Customer contracts can define the services and recovery commitments in scope.

## Contract support

For an in-scope service, we can cover:

* service levels, support, response, and restoration
* incident and outage notifications
* audit and regulatory cooperation
* resilience tests and remediation
* subprocessors and processing locations
* backups, continuity, RTO, and RPO
* data export, transition, retention, and deletion

## Independent assurance

| Programme        | Status                           |
| ---------------- | -------------------------------- |
| SOC 2 Type II    | Coming soon, expected in Q3 2026 |
| ISO 27001:2022   | Coming soon, expected in Q3 2026 |
| Penetration test | Coming soon, expected in Q3 2026 |

## Regulatory sources

Our approach is informed by [Regulation (EU) 2022/2554](https://eur-lex.europa.eu/eli/reg/2022/2554/oj?uri=CELEX%3A32022R2554) and its supporting regulations.

Questions? Email [compliance@molin.ai](mailto:compliance@molin.ai).
