Overview
Self-hosted, DORA-compliant third-party risk management - govern your ICT providers and produce the register of information you have to file.
tprm.mlab.sh covers ICT third-party risk end to end: due diligence, contracts, services, assessments, audits, exits and incidents, and the production of the register of information required by DORA Article 28(3). It runs entirely on your infrastructure, and the only outbound call is license validation.
The register exports as the 15 EBA ITS templates (Reporting Framework 4.0) with controlled codes, integrity validation and a deposit-ready xBRL-CSV package.
Getting started
Quick start
Docker Compose, first login, your first provider and register.
Installation
Docker Compose, requirements, MySQL + ClickHouse, reverse proxy.
Configuration
Environment variables, license token, RBAC, API keys.
Core
DORA mapping
Every module mapped to its DORA article and EBA template.
EBA export
The 15 templates, validation and the xBRL-CSV deposit package.
Licensing
Free vs Licensed, validation, the 48h grace period.
API reference
Token auth, providers, contracts, assessments, incidents.
Operate
Update
Pull, restart, auto-migrations on startup.
Troubleshooting
Common errors and how to fix them.
FAQ
Quick answers to the questions we hear most.
Glossary
DORA and TPRM terms used across the product.
Need help?
If you're stuck, the fastest path is [email protected]. Licensed plans include priority email support. License management for your organisation lives on mlab.sh.