Skip to main content

158 posts tagged with "Compliance"

Regulatory compliance and legal frameworks

View all tags

Toward a World Where Builds Don't Exist: What Railway's VM-Powered Thesis Gives Up in Provenance
·Dora Noda·9 min

Toward a World Where Builds Don't Exist: What Railway's VM-Powered Thesis Gives Up in Provenance

Railway wants a world where builds don't exist and your app is just live. But the build produces the digest, SBOM, provenance, and rollback artifact that incident response and the EU's new reporting rules depend on — here is the full inventory of what disappears with it.

PaaS
self-hosting
security
compliance
The Self-Hosted Governance Gap: Why Your Compliance Team Says No to Coolify, Dokku, CapRover, and Dokploy
·Dora Noda·11 min

The Self-Hosted Governance Gap: Why Your Compliance Team Says No to Coolify, Dokku, CapRover, and Dokploy

Coolify, Dokku, CapRover, and Dokploy win engineering evaluations and lose security reviews: no enterprise SSO, no audit trail. A capability-by-capability look at what compliance-bound teams need and what a self-hosted PaaS must build to win them.

self-hosting
PaaS
governance
compliance
+1
After Bitcoin 2026: What Paul Atkins Said and What the SEC Actually Filed
·Dora Noda·11 min

After Bitcoin 2026: What Paul Atkins Said and What the SEC Actually Filed

A sourced timeline separates Paul Atkins's Bitcoin 2026 remarks from the SEC, CFTC, and congressional actions that followed—and identifies which crypto rules remained unfinished by August 30.

regulation
policy
securities
tokenization
+1
Bitcoin Lending After the Collapse: A Practical Test of Four Institutional Controls
·Dora Noda·10 min

Bitcoin Lending After the Collapse: A Practical Test of Four Institutional Controls

Evaluate institutional Bitcoin loans after the 2022 failures with a four-control framework, an LTV stress test, and a six-point diligence checklist.

Bitcoin
DeFi
fintech
compliance
TRM’s Co-Case Agent Turns a Crypto Investigation Into a Reviewable Workflow—Not an Autonomous Verdict
·Dora Noda·9 min

TRM’s Co-Case Agent Turns a Crypto Investigation Into a Reviewable Workflow—Not an Autonomous Verdict

TRM’s Co-Case Agent speeds crypto case preparation with tracing, graph audits, and audit logs. See the human-review workflow that turns AI assistance into defensible investigation work.

AI
compliance
cybersecurity
blockchain
The EU Just Legislated Who Can Sell Cloud to Its Governments: What CADA's Four Tiers Mean for Your PaaS Choice
·Dora Noda·14 min

The EU Just Legislated Who Can Sell Cloud to Its Governments: What CADA's Four Tiers Mean for Your PaaS Choice

On June 3, 2026 the EU turned its SEAL-0 to SEAL-4 sovereignty grades into procurement law. A concrete map of CADA's four assurance levels, where US hyperscalers hit a structural wall, and why a fleet on owned Hetzner/OVHcloud/Scaleway hardware clears a bar a US-headquartered PaaS cannot.

self-hosting
PaaS
infrastructure
compliance
+1
Sovereign Means More Than Where the Disks Sit: What OVHcloud and Scality's Joint Storage SKU Reveals About European Digital Sovereignty
·Dora Noda·15 min

Sovereign Means More Than Where the Disks Sit: What OVHcloud and Scality's Joint Storage SKU Reveals About European Digital Sovereignty

OVHcloud and Scality shipped a joint S3-compatible sovereign storage platform on July 1, 2026 — with dedicated cloud and on-prem options, multi-AZ replication, and no hyperscaler dependency. A teardown of what sovereignty actually requires beyond data residency, mapped against the EU's SEAL grading and CADA procurement tiers.

self-hosting
cloud infrastructure
infrastructure
compliance
AWS European Sovereign Cloud: Why a Separate German Region Still Can't Close the CLOUD Act Gap
·Dora Noda·13 min

AWS European Sovereign Cloud: Why a Separate German Region Still Can't Close the CLOUD Act Gap

AWS went GA in Brandenburg on January 15, 2026 with a separate German entity, 90 services, and €7.8B behind it. Why physically separate still isn't legally sovereign — scored through the EU's SEAL 0–4 framework and the CLOUD Act's corporate-jurisdiction test.

self-hosting
PaaS
infrastructure
security
+1
OVHcloud's SecNumCloud GA in June 2026: Why 'EU-Headquartered' Isn't a Sovereignty Certification
·Dora Noda·17 min

OVHcloud's SecNumCloud GA in June 2026: Why 'EU-Headquartered' Isn't a Sovereignty Certification

OVHcloud's SecNumCloud-qualified instances went GA in June 2026 on ANSSI's 360-control visa. What certified immunity, operational separation, and capital caps require beyond an EU headquarters — and when your PaaS needs to name the visa.

infrastructure
security
compliance
regulation
+1
Showing 10–18 of 158 posts