Deterministic Consent Gate: analytics remain disabled until explicit opt-in. No third-party trackers are loaded.

Specifikacia kontroly

Replay-safe request handling

Sovereign Integration API

Replay-safe request handling defines an enforceable control requirement inside Sovereign Integration API, with measurable checkpoints and operational constraints.

nDSGDORA

Ucel

Enforce policy and runtime constraints tied to Sovereign Integration API so drift and non-compliant operations are blocked early.

Kontext rozsahu

Contract-first integration facade with idempotent transaction behavior.

Vstupy

- Policy requirements and risk appetite definition

- System boundaries and affected components

- Exception handling workflow and escalation owner

Vystupy

- Control implementation with enforceable policy condition

- Monitoring signal and alerting threshold

- Exception register entry with expiry and audit trace

Akceptacne kriterie

- Control blocks or flags non-compliant state changes

- Evidence is exportable for internal or external audit

- Exception path is time-bounded and explicitly approved

Poznamky ku compliance dokazom

- [nDSG] Control objective and test outcome recorded for assurance

- [DORA] Control objective and test outcome recorded for assurance

Schema specifikacie

Rola vlastnika

Security and Platform Governance Owner

Schvalovaci sign-off

Governance lead plus founder-level exception approval for bypasses

Politika verzovania

Policy revision tags linked to deployment release ID

Rytmus revizie

Bi-weekly control health review and quarterly deep audit

Retencia dokazov

Control test evidence retained for at least 18 months

Povinne sekcie

- Control objective and policy statement

- Trigger conditions and enforcement mechanism

- Monitoring signals and alert thresholds

- Exception process with expiry policy

- Control test method and result capture format