AV AlgoVoi Store
For MiCA & DORA reviews · CASPs & trust services · Self-hosted

Walk into your MiCA or DORA review with evidence, not assertions

A fixed-scope $150 audit of your signed-record archive: it verifies every signature, flags the weak, expired, broken-chain and quantum-exposed ones, and produces a signed, auditor-ready report your auditor or regulator verifies themselves, offline, with a free tool. Runs on your own infrastructure. Nothing is uploaded. No sales call.

Start the audit, pay by card ($150) See a sample report first

One time, no subscription. Prefer crypto, or want the free scan first? See all options.

The problem this solves

Under MiCA, crypto-asset service providers must retain records for at least five years (up to seven at a competent authority's request). Under DORA, financial entities must keep secure, tamper-resistant records of ICT-related incidents. When a review, remediation plan, audit, or regulator evidence request lands, the question is not whether you kept the records, it is whether you can prove they are intact, complete, and have not been altered since they were signed, in a way the other side can check without taking your word for it.

A folder of signed PDFs does not answer that question. Some signatures may use a weak digest, some certificates may have expired, some signatures may cover only part of the document, and all of the classical RSA/ECDSA ones are becoming forgeable as quantum capability advances. You need a verifiable statement of what the archive actually contains.

What you get

Every signature verified

Classical RSA/ECDSA and post-quantum, across the whole archive, not a sample.

Every weakness flagged

Weak digest (SHA-1), expired certificate, broken trust chain, partial-coverage (shadow) PDF, and post-quantum exposure, per document.

A signed, auditor-ready report

Sealed with a post-quantum attestation so your auditor confirms it is authentic and unaltered themselves, offline.

Repeatable each cycle

Re-run against the baseline to prove nothing changed between reviews, which is what a regulator wants to see over time.

How it works

  1. Scan free first. The open av-reseal-verify tool inspects a single document at no cost, so you can see exactly what the audit reads before you pay.
  2. Run the audit on your own infrastructure. Point it at your archive. It reads your documents in place, verifies every signature, and writes the report locally. It uploads nothing; your records never leave your estate.
  3. Hand the signed report to your auditor. They verify it themselves with the free tool, with no AlgoVoi licence and no trust in us required. The evidence stands on its own.

Why the report can be trusted without trusting us

The report is signed with a post-quantum reseal envelope (Falcon-1024 and ML-DSA-65). Anyone you hand it to confirms it is authentic and unaltered using the free, open av-reseal-verify tool, offline, with no licence. That is the whole point: you are not asking your regulator to trust AlgoVoi, you are giving them evidence they can check for themselves. See a real sample report.

Who this is for

Heads of Compliance, MLROs, and CTOs at crypto-asset service providers, exchanges, and trust-service providers with an active or upcoming MiCA or DORA review, remediation plan, audit, or regulator evidence request. If a deadline is driving this, the audit gives you a defensible, independently verifiable answer this week.

Scope, stated honestly

This produces cryptographic evidence artifacts about your signed records. It is not legal advice and not a determination of regulatory compliance or legal admissibility. It is read-only: it verifies and reports, and never stores, mutates, or governs your documents. The compliance judgement remains with you and your auditor; what this gives both of you is verifiable fact instead of assertion. It is the same engine as AlgoVoi Evidence Auditor, scoped and priced for a single archive review.

Frequently asked questions

What do I get for $150?

A fixed-scope audit of your signed-record archive and a signed, auditor-ready report: every signature verified, every weak, expired, broken-chain or quantum-exposed one flagged, and a report your auditor verifies themselves offline with the free tool. One time, no subscription, no sales call.

Do I have to upload my records to AlgoVoi?

No. The audit runs on your own infrastructure and uploads nothing; your documents never leave your estate. The report is signed so the party you hand it to can confirm it is authentic and unaltered without trusting AlgoVoi and without a licence.

Is this legal or regulatory advice?

No. It produces cryptographic evidence artifacts about your signed records; it is not legal advice and not a determination of regulatory compliance or legal admissibility. It gives your auditor verifiable evidence; the judgement remains theirs and yours.

What if I need more than one archive, or ongoing sealing?

The Verifiable Compliance Suite adds write-once storage, retention, legal holds, a console, SIEM forwarding, key custody, and sealing at scale. Start with the single-archive audit; move up only if you need to.

Start the audit, pay by card ($150) See a sample report

Instant licence on payment. Prefer crypto or want the free single-document scan first? See all options.