Skip to main content
STATUS: PRE-CONSTRUCTION · SITE A UNDER EXCLUSIVITYNODE: VASILIKOS-01 — 34.7246°N, 33.2247°ECAMPUS: RISC-V PHASE 1 · MULTI-SILICON EVAL · PLANNEDPOWER: 42MW ON-SITE GENERATION · DESIGN TARGETSTATUS: PRE-CONSTRUCTION · SITE A UNDER EXCLUSIVITYNODE: VASILIKOS-01 — 34.7246°N, 33.2247°ECAMPUS: RISC-V PHASE 1 · MULTI-SILICON EVAL · PLANNEDPOWER: 42MW ON-SITE GENERATION · DESIGN TARGET
AGICY.AI
StackTechnology OverviewRISC-V sovereign stackComputeBare-metal EU compute
FacilitiesData CentersWorldwide map & trackerVasilikos Campus42MW sovereign campus briefingSustainability100% renewable mission
HardwareHardware FleetVendor hub · phased COD roadmapTenstorrent GalaxyPhase 1 Blackhole fleet (pre-COD)AESOLAR AlpineEnergy stack · hail-class PV + BESSAMD HeliosPhase 2 open rack-scale (eval · pre-COD)CerebrasPhase 2 · wafer-scale eval (pre-COD)
Submit your Hardware for reviewPropose accelerators for the Vasilikos fleet
AIAI Web SearchNew!Sovereign AI search · AGICY & the webAI My MapsNew!Smart Maps · voice routing · agentsAgents Trading CryptoBeta · New!Live paper-trading arena · BTC · ETH · SUIAI Video SearchNew!Find AI videos · avatars · films · adsAdvertiseSearch ad program · how it works · board ranks
GatewayCopperwayEU-sovereign OpenAI-compatible gatewayTry PlaygroundNewLive Copperway demo · PII vaultSovereign Exchange5-year cross-org sovereign plan
ProductsReserve CapacityPre-construction LOI tiersMarketplaceCompute marketplaceGPUs Rent LiveLiveEU partner GPU now · until CODCompute VouchersSovereign compute creditsModel LeaderboardFrontier model rankingsPricingSubscription tiers
WorkloadsComputeBare-metal EU inference & trainingCopperway GatewayOpenAI-compatible EU APIVasilikos Campus42MW sovereign campus briefing
Trust & complianceTrust CenterSecurity portal · docs · statusEU AI ActRegulatory mapping & controlsAI Readiness AuditPublic-data readiness hub
PricingTiers
Capital & EducationInvestInstitutional data room & deal flowAcademyAI training programs
Individuals & Family OfficesLiving in EUNewClass B capital allocation · no visa framingInternationalNewPlan B · equity alternative to property
IntelligenceResearchPublications & portals
CompanyAboutBrand · HoldCo targetMissionCharter & sovereigntyTrust CenterSecurity portal · docs · status
Schedule Briefing
Sign In
DORA ICT Resilience
DORA (EU) 2022/2554 REGULATORY COMPLIANCE

DORA ICT Resilience

AGICY is designing a Digital Operational Resilience Act (DORA) readiness backbone for European FinTechs, banks, and algorithmic trading firms operating AI models — pre-construction design status, not a held certification.

Last UpdatedJanuary 10, 2026
Document Version1.1.5
ClassificationCONFIDENTIAL / PUBLIC

1. Financial Sector Resilience

As AI becomes deeply integrated into algorithmic trading, risk modeling, and fraud detection, financial institutions face strict regulations under the Digital Operational Resilience Act (DORA). Hyperscaler outages are no longer acceptable risks. AGICY is engineered for extreme availability as a design target.

DORA (Regulation (EU) 2022/2554) entered into application on 17 January 2025. It applies to virtually all regulated financial entities and their critical ICT third-party service providers. When operational, AGICY intends to support financial institutions as an ICT third-party service provider within that framework.

2. Redundant Energy & Network Topology

Located at the Vasilikos Energy Center (pre-construction), AGICY is designing a proprietary micro-grid with direct access to Cyprus's primary energy infrastructure. The design target is a 99.999% uptime SLA, intended to support DORA's ICT third-party risk management expectations.

2.1 Redundancy Architecture

  • Power: Dual gas turbine feeds + solar array + diesel backup (N+2 redundancy). No single point of failure in power delivery.
  • Cooling: Ambient air cooling with redundant fan arrays. No water dependency means no drought-related downtime risk.
  • Network: Dual submarine cable feeds (TEFKROS, ARSINOE) with automatic failover. Latency to Frankfurt: <18ms.
  • Compute: Tenstorrent Galaxy fleet with hot-spare allocation planned at campus-class MW scale (pre-construction; unit counts at procurement lock).
Threat-Led Penetration Testing (TLPT)

"AGICY plans Threat-Led Penetration Testing with qualified red-team providers under frameworks such as TIBER-EU. Summarized attestations are intended for financial-sector clients to append to their DORA compliance reports — this is a roadmap commitment, not a present-tense ECB-certified programme."

3. ICT Risk Management Framework (Article 6)

AGICY's planned ICT risk management framework includes:

  • Comprehensive identification of all ICT-supported business functions, roles, and assets.
  • Continuous monitoring and control of ICT systems security and functioning.
  • Mechanisms for the prompt detection of anomalous activities.
  • Dedicated and comprehensive business continuity policy.
  • Learning and evolving mechanisms — incorporating lessons from incidents and TLPT exercises.
  • Communication plans for responsible disclosure and crisis coordination.

4. ICT-Related Incident Reporting (Article 19)

AGICY intends to support financial-sector clients with automated incident classification and reporting infrastructure:

  • Initial notification: Within 4 hours of classifying a major ICT-related incident.
  • Intermediate report: Within 72 hours, with updates on impact assessment and recovery progress.
  • Final report: Within 1 month, including root cause analysis and remediation measures.

A planned Security Operations Centre is designed to generate DORA-formatted incident reports so financial clients can forward them to their national competent authority.

5. Digital Operational Resilience Testing (Article 26)

AGICY plans the following testing programme:

  • Quarterly: Vulnerability assessments and network security scans.
  • Semi-annually: Open-source code reviews and software composition analysis.
  • Annually: Full penetration testing by independent third-party providers.
  • Every 3 years: Threat-led penetration testing (TLPT) in accordance with TIBER-EU framework.

6. Third-Party Risk Management (Article 28)

As a planned critical ICT third-party service provider, AGICY intends to provide financial clients with:

  • Full contractual provisions as specified in Article 30 — including SLAs, data localisation guarantees, audit rights, and exit strategies.
  • Planned SOC 2 Type II attestation reports covering Trust Service Criteria — a roadmap target, not currently held.
  • Right to audit — AGICY plans to grant financial clients and their regulators the right to conduct on-site inspections with 30 days' notice.
  • Exit strategy — documented transition plan ensuring orderly migration of workloads within 90 days, with no data lock-in.
Oversight Framework Readiness

"Should AGICY be designated as a critical ICT third-party service provider under DORA Article 31, we are prepared to cooperate fully with the Lead Overseer (EBA, ESMA, or EIOPA) including providing information, submitting to inspections, and implementing recommendations."

7. Information Sharing (Article 45)

AGICY plans voluntary cyber threat intelligence sharing arrangements with financial sector ISACs (Information Sharing and Analysis Centres) across the EU, providing anonymised threat data from the planned Security Operations Centre to strengthen the collective resilience of the European financial ecosystem.

Download Official Policy Document

PDF Format · SHA-256 Verified · 1.4 MB

Secure Your Compliance

Pre-book Sovereign Compute compliant with all EU regulations.

Calculate SRA Allocation

§ FIN — Close of Document

Ready to build on sovereign infrastructure?

Schedule a confidential briefing with our team. NDA-protected, no commitment.

Schedule a briefing →
EU JURISDICTION · CYPRUSGDPR ART. 28 DPA-READY · BY DESIGNNIS2-ALIGNED · BY DESIGNEU AI ACT ART. 12 LOGGING SUPPORT · BY DESIGNRISC-V NATIVE · OPEN ISA

Design-alignment statements for a pre-construction facility — not certifications or attestations. Basis: compliance FAQ, § 08. Careers: we aim for 50-50 gender balance across hiring cohorts.

AGICY.AI

Advanced Governance & Intelligence Cyprus

The sovereign architecture for the Cyprus mind.
Humanitarian mandate: civilian public benefit only — healthcare, education, civil resilience. Civilian / humanitarian mandate only.
Office: 8 John Kennedy Street, Iris House, 7th floor, 3106 Limassol, Cyprus
+357 95 572 777 · 08:30 – 19:00 · agi@agicy.ai
VASILIKOS ENERGY CENTRE, LIMASSOL DISTRICT · PRE-CONSTRUCTION
34.7246°N · 33.2247°E
Principal campus: Cyprus Vasilikos (Phase 1). Parallel HoldCo path: sovereign compute project in Greece (TARGET / planning) — ~20 MW-class Tenstorrent / air-cooled inference positioning for EU diversification; separate CapEx, no offtake claimed.

The Ledger — monthly briefing
  • CopperwayEU-sovereign OpenAI-compatible gateway
  • Try PlaygroundNewLive Copperway demo · PII vault
  • Compression & PII vaultNewSovereign path controls in Playground
  • Sovereign Exchange5-year cross-org sovereign plan
  • ComputeBare-metal EU inference & training
  • UPDATED on GitHubAGICY AI desktop beta · source
  • Reserve CapacityPre-construction LOI tiers
  • MarketplaceCompute marketplace
  • AI Video SearchNewFind AI videos · avatars · films · ads
  • Sui Agent RailsPrivacy · Walrus · wallet connect
  • GPUs Rent LiveLiveEU partner GPU now · until COD
  • Compute VouchersSovereign compute credits
  • Model LeaderboardFrontier model rankings
  • PricingSubscription tiers
  • Research HubWave-1 publications index
  • Data CentersWorldwide map & tracker
  • Vasilikos Campus42MW sovereign campus briefing
  • Copperway vs gatewaysConcessive pricing & capability evidence
  • OpenRouter alternativesLiteLLM · Portkey · Copperway
  • EU alternative to OpenRouterCLOUD Act / sovereignty buyer guide
  • Copperway vs LLM gatewaysCapability evidence & SRA economics
  • GDPR-compliant AI hostingEU residency & processing path
  • Cerebras vs GroqInference speed & sovereign options
  • CLOUD Act riskUS parented API exposure
  • AI Act Digital OmnibusArticle 50 transparency duties
  • Sovereign cloud truthLabel vs residency — buyer checklist
  • EU AI ActRegulatory mapping & controls
  • AboutProject identity & status
  • GitHubAGICY AI public source · AGiOS-Ai-EU
  • MissionCharter & sovereignty
  • CareersCulture, benefits & hiring ethos
  • Open PositionsEngineering, research & operations roles
  • Ethics & CharterAnti-misconduct & responsible AI
  • Editorial & MethodologySources, claims, corrections
  • Trust CenterSecurity portal · docs · status
  • InvestInstitutional data room & deal flow
  • Living in EUIndividuals & FOs · Class B allocation
  • International investorsPlan B · Greece / Cyprus rails · Class B
  • Equity participation (legacy)CY & GR individual interest · counsel-gated
  • AcademyAI training programs
  • ContactBriefings & inquiries
  • Privacy PolicyGDPR · data processing
  • Terms of ServicePlatform usage terms
  • Cookie PolicyTracking & consent
  • SRA TermsReserve capacity agreement
  • Gateway Pricing DisclaimerCopperway pricing basis
© 2026 AGICY· PROJECT / BRAND OPERATOR · AGICY HOLDINGS LTD — NAME REGISTRATION APPLICATION COMPLETED · AWAITING APPROVAL · CORP DOCS TO FOLLOWDOC: AGICY.AI · REV 2.0 · SOVEREIGN LEDGER
AGICY