Could you draw your ICT
supply chain right now?
Most teams can't — it's scattered across spreadsheets. DORAVISUAL maps every ICT provider and subcontractor on one screen, and turns it into an audit-ready DORA register in minutes, not weeks.
shots/hero-network.png hereThe problem
Spreadsheets can't show you risk.
DORA holds you accountable for a supply chain most teams can't actually see.
-
🕸 You can't see the chain
Rows in a spreadsheet don't show who depends on whom — or which fourth parties sit two tiers down, behind your direct suppliers.
-
⚠ Concentration risk stays hidden
Five "different" suppliers all running on the same hyperscaler? You'd never spot it in a table — until it takes them all down at once.
-
⏳ Audit prep eats weeks
Every information request becomes a manual scramble across files, owners and versions — and you're still not sure the register is complete.
See it in action
Three quick demos
Each clip is around 30 seconds. They only play while visible — no battery drain, no wasted bandwidth.
-
Map your ecosystem
Add suppliers tier by tier. Auto-layout keeps everything readable.
-
2D & 3D views
Canvas-based 2D and Three.js-powered WebGL 3D — switch instantly.
-
Concentration risk
Top critical suppliers, country and sector breakdown in one click.
What it does
Your supplier ecosystem on one interactive canvas
DORAVISUAL gives organisations clear insight into supplier dependencies, concentration risks, operational impact, and ecosystem vulnerabilities through advanced interactive network visualisations.
From your own organisation (Tier 0) to direct suppliers, sub- suppliers and fourth-party providers, every relationship and risk indicator lives on a single animated canvas — purpose-built for procurement, risk, compliance, IT, and audit teams in any regulated or supplier-dependent industry.
Why teams switch
Answers in seconds, not weeks.
The questions that used to take a week of emails — answered with a click.
- "What breaks if this provider fails?" One click highlights every business process that depends on it.
- "Where is my concentration risk?" A heatmap surfaces it instantly — by provider, country and sector.
- "Is my register complete?" Live gap analysis flags every missing field before the auditor does.
- "Generate the EBA submission." One export — DORA 4.0 (EUCLID) report package, ready to file.
No catch
No IT project required.
-
🚫 No server
Runs in your browser or as a desktop app. Nothing to install or maintain on a server.
-
🔒 Your data stays yours
Everything runs locally — no cloud, no upload. Your register never leaves your device.
-
✅ Regulator-ready
Export is EBA DORA 4.0 (EUCLID) conformant — the exact format the submission expects.
-
📥 Use your register
Already keep one in Excel or XBRL? Import it and see your whole chain on screen in minutes.
Industries
Built for any ICT-dependent organisation
Pre-built demo models ship with the product, illustrating very different supplier ecosystems. The underlying engine is industry-agnostic — any organisation that depends on a network of suppliers can be modelled.
-
🏦 Financial services
Banks, insurers, payment institutions and investment firms. Model core banking & payments, cloud & IT infrastructure, cybersecurity & data, and markets & treasury — with a registered contract on every connection for DORA Article 28 reporting.
-
🏭 Semiconductor & manufacturing
Hardware, advanced manufacturing, and industrial supply chains. Map dozens of Tier-1 suppliers and their Tier-2 sub-suppliers across multiple processes — exposing deep, technology-critical dependencies several tiers down.
-
💊 Pharmaceutical & life sciences
Drug development, manufacturing, and clinical IT — mapping R&D systems, GxP-validated infrastructure, clinical platforms, and contract manufacturing across the supply chain.
-
⚡ Energy & utilities
Grid operators, generators, and utilities mapping OT/IT supplier dependencies, cloud providers, SCADA vendors, and metering platforms across the value chain.
-
🏥 Healthcare & public sector
Hospitals, ministries, and agencies mapping vendor ecosystems against NIS2, sector-specific regulation, and internal procurement governance.
-
🛒 Retail, logistics & beyond
Any organisation with a non-trivial supplier network — retail platforms, logistics operators, telcos, professional services. Same engine, your taxonomy.
Key features
Everything you need. Nothing you don't.
From live graph editing to regulatory exports — DORAVISUAL covers the full third-party risk workflow in a single environment.
-
See the whole chain — report only what counts
Map your entire ICT ecosystem on one canvas — including financial counterparties and out-of-scope entities you need for context — while your DORA Register of Information stays clean. Only critical and non-critical ICT providers (and their contracts) flow into the register table, coverage analysis and EBA submission. Mark any node Financial or Non-DORA and it stays visible on the map but drops out of the register and export automatically. Import an XBRL register and every provider is classified critical or non-critical for you — so what you see and what you file never drift apart.
-
Multi-tier network visualisation
Map suppliers, partners, systems and dependencies across Tier 0 through Tier 4. A sector-based ring layout with BFS-assigned tiers and barycenter-optimised ordering keeps the structure readable at any scale.
-
Dynamic 2D and 3D visualisation
High-performance Canvas-based 2D and Three.js-powered WebGL 3D rendering. Rotate, zoom, present from any angle — and export the 3D view as a slide or GLTF model.
-
Search, filter, cluster & spotlight
Advanced search, filtering, clustering and spotlight functionality. Filter by tier, sector, process, or DORA / compliance status. Process filter centres the view automatically on visible nodes.
-
Risk heatmaps & concentration analysis
Surface critical suppliers, country concentration, sector exposure, and shared dependencies. Make hidden risks visible before the audit — or before they fail.
-
Dependency, impact & process mapping
Visualise direct and indirect dependencies, operational impact, and process- and service-chain mapping across third- and fourth-party relationships. See exactly which business processes break if a supplier fails.
-
LEI & EUID validation
One-click LEI validation via the GLEIF API. Auto-fill ultimate parent name and LEI, and walk the full ownership chain (up to 10 hops) with flags, status, and add-to-model buttons. EUID supported alongside.
-
Contract Registry
A dedicated registry of every contract across every connection — supplier pair, reference, DORA / non-DORA badge, expiry with traffic-light status, auto-renewal flag, notice period, ICT service category, and annual cost.
-
Node Browser
A full-screen overlay of every node as a rich card — independent of the canvas. Filter, search, and bulk-assign processes or sector to multiple nodes at once. Ideal for cleaning up freshly imported registers.
-
Focus & comparison mode
Isolate a single branch, or compare two branches side by side. Shared suppliers automatically reposition to the circular average of their parents. Escape returns to the full network.
-
Multi-select & bulk operations
Shift-drag a rubber-band lasso to select. Shift-click to toggle. Bulk delete with the FAB button or Delete key — with a live counter. The camera auto-frames the selection.
-
Collapse subtree & shuffle
Right-click any node to collapse its descendants behind a count badge — collapsed branches survive filter changes. One-click Shuffle recomputes tiers and minimises edge crossings with a smooth spring animation.
-
Auto ball-size optimisation
Node radius scales exponentially with annual contract cost — from €25K (size 1) to €10M (size 10). Ring radii expand automatically to prevent overlap; label font auto-fits the largest readable size.
-
Undo / redo & quick save
30 levels of undo and redo (Ctrl+Z, Ctrl+Y). Quick Save (Ctrl+S) writes directly to a fixed .xlsx location via the File System Access API — first time picks the file, subsequent saves are silent.
-
Bulk editing & Excel import
Import existing supplier, contract, and risk datasets via a 25-column Nodes sheet. Backward-compatible with files exported from older versions (21–24 columns). Bulk-edit operations make large registers manageable.
-
Multi-format export
Export to Excel (full register or verification report), PowerPoint (native editable shapes, 2D and 3D), PNG, GLTF 3D model, Visio, and a self-contained interactive HTML model with logos and contracts embedded.
-
Keyboard-first workflow
Press ? at any time for the keyboard shortcut overview. Power users move through large networks without ever reaching for the mouse.
Why DORAVISUAL
Beyond spreadsheets and static reports.
Unlike traditional spreadsheets and static reporting tools, DORAVISUAL combines interactive network visualisation, dependency analysis, contract management, and risk intelligence within a single intuitive environment. Any organisation with a complex supplier ecosystem can rapidly identify hidden dependencies, concentration risks, and operational vulnerabilities — enabling faster decision-making and stronger operational resilience.
- Faster decisions. Visual signal beats spreadsheet noise.
- Stronger resilience. Hidden dependencies surface before they fail.
- One environment. Visualisation, contracts, analysis, and reporting in one place.
See your own supply chain — in one screen.
Book a 20-minute demo and we'll map a slice of your register live, on your data.
Analysis & monitoring
Identify and analyse the risks that matter
DORAVISUAL supports organisations in identifying and analysing critical ecosystem risks — from individual supplier exposure to structural concentration patterns across the full ecosystem, whatever the industry or regulatory regime.
- Critical supplier identification. Tier 1 critical providers grouped by Legal Entity Identifier and ultimate parent.
- Chain dependency analysis. Trace direct and indirect dependencies through every tier.
- Concentration risk visualisation. Country, sector, and supplier concentration in one view.
- Compliance & governance analysis. Map ICT third-party data to specific obligations — DORA, NIS2, sector regulation, or internal frameworks.
- Contract lifecycle tracking. Expiry traffic-lights, auto-renewal flags, notice periods, ICT service categories.
- Impact assessment visualisation. See which business processes break if a single supplier fails.
- Executive and board-level reporting. Audit-ready outputs without manual chart-building.
- Interactive ecosystem visualisation. Drill into any node, any relationship, any time.
Export
Excel, PowerPoint, PNG, 3D, Visio — every format your workflow needs
From regulatory reports to board presentations to read-only viewers for external stakeholders — DORAVISUAL exports to the right format every time.
-
.pptx
PowerPoint — native shapes
Fully editable vector slide with your supply chain as native PowerPoint shapes and colour-coded nodes. Real objects you can move and style — not a screenshot.
-
.pptx
3D PowerPoint
Capture the 3D view as a presentation slide for board-level meetings.
-
.xlsx
Verification Report
Full Excel verification overview for all Tier 1 critical suppliers, or per individual node. Includes LEI, ultimate parent, contract data, regulatory status, and linked processes.
-
.xlsx
Supplier dataset (25 columns)
Full Nodes, Connections, and Processes sheets — exports the complete model for import into another instance or backup. Backward-compatible with older 21–24 column files.
-
.png
PNG snapshot
High-resolution canvas snapshot with title and date watermark — perfect for emails and reports.
-
.gltf
3D model (GLTF)
Export the 3D graph as a GLTF model for use in other 3D applications, WebGL projects, or as an archival format.
-
.html
VIEWER / locked model
A self-contained, read-only HTML file with all data and logos embedded — safe to distribute to auditors, management, or regulators. Pan, zoom, filter, inspect contracts — but no editing.
-
.vsdx
Visio diagram
Export the supply chain as a native Visio file for teams that work in the Visio diagramming toolchain.
Deployment
Open the HTML file. That's it.
DORAVISUAL is a single-file HTML application. No server. No installation. No cloud storage. Three distribution variants cover every scenario — from individual analysts to organisation-wide rollouts.
-
Slim (~0.5 MB)
Uses external
lib/folder — ideal when you control the hosting environment and want the smallest payload. -
Fat (~4.3 MB)
All libraries inlined — fully self-contained. Works anywhere without companion files. Email it, drop it on a USB, host it on SharePoint.
-
VIEWER (~4.3 MB)
Same as Fat but read-only — editing, export and demo functions are no-ops. A 👁 VIEWER badge is permanently displayed. Perfect for distribution.
Run it locally with a double-click, host the single file on your own infrastructure for team-wide access, or install the native Mac desktop build.
-
Local (Windows / Mac)
Double-click the standalone HTML file — no install, no admin rights, no companion files.
-
Self-hosted
Drop the single file on any web host or inside your tenant (Azure, Cloudflare, intranet) — one URL, organisation-wide access, no install for end users.
-
Teams & SharePoint
Once hosted, link it from SharePoint or embed the URL as a tab in Teams for direct team-wide access.
-
Mac desktop app
Native Electron build for macOS — logos stored as files on disk, GLEIF API works without CORS restrictions, app data in
~/Library/Application Support/dora-visual/.
Security & architecture
No server. No cloud. Your data never leaves your device.
A browser-native architecture is the security model. Sensitive supplier, contract, and risk data stays on the user's machine or inside your own infrastructure — never on a vendor backend.
- No server, no cloud storage. The application is a single HTML file — there is no backend to breach.
- Data stays on your device. Models are saved as local files; nothing is uploaded.
- Browser-native architecture. No client install, no admin rights, no agent.
- Offline capable. Continue working without active connectivity (LEI lookups require internet).
- High-performance Canvas + WebGL. Renders large ecosystems smoothly.
- 3D powered by Three.js. Interactive WebGL graph rendering.
- File System Access API. Quick Save writes directly to a chosen .xlsx location.
- Optional private hosting. Host the HTML inside your tenant (Azure, SharePoint, intranet) for organisation-wide distribution.
- VIEWER for external sharing. Read-only HTML with editing disabled — safe to send to auditors and regulators.
- 419 static checks. Every release passes the full
test_doravisual.pyQA suite before shipping.
- Single-file HTML
- Canvas + WebGL
- Three.js
- GLEIF API
- File System Access API
- No install required
- Electron (macOS)
- Self-hostable (Azure / Cloudflare)
Use cases
One platform, many ways to use it
DORAVISUAL fits the workflows of procurement, risk, compliance, IT, audit, and executive teams — across regulated and unregulated industries alike.
- ICT supplier network mapping
- Third- and fourth-party risk management
- Concentration & country risk analysis
- Cloud & SaaS dependency mapping
- Contract registry & lifecycle tracking
- Critical supplier identification
- Vendor due diligence & onboarding
- Process & impact mapping
- DORA, NIS2 & sector compliance
- Procurement & outsourcing oversight
- Executive, audit & board reporting
- Auditor & regulator distribution (VIEWER)
Additional services
Bring your data — we'll do the rest
Provide your existing contract database, vendor register, or DORA / NIS2 register, and we'll set up the analysis and visualisation for you.
-
Contract & supplier data import
Import and analysis of your existing contract and supplier datasets — no manual re-entry. We map your columns to the 25-column model.
-
Custom ecosystem setup
Tailored visualisation configured around your organisation's structure, processes, and risk taxonomy.
-
Tailored dependency mapping
Custom dependency and risk modelling specific to your operating model and critical functions.
-
Data enrichment
LEI validation, ultimate-parent resolution, ownership-chain walking, and relationship modelling on your live register.
-
Executive reporting environments
Pre-built executive-ready visual reporting environments configured for your governance forums.
-
Custom integrations
Custom data integration support available upon request — connect DORAVISUAL to your existing systems.
FAQ
Wait, but…
Is my data sent anywhere?
No. DORAVISUAL runs locally — in your browser or as a desktop app. Your supplier, contract and register data stays on your device; there is no vendor backend to upload to.
Does the export match what the regulator expects?
Yes. The register exports as an EBA DORA 4.0 (EUCLID) report package — the structured format used for the supervisory submission.
We already keep a register in Excel. Can we use it?
Yes. Import your Excel file or an EBA XBRL register and your full supply chain is on screen in minutes — no manual re-entry.
Do we need IT to set this up?
No server, no installation project. Open the file and go — or roll it out via SharePoint, Teams, or a desktop build.
Can it handle subcontractors (fourth parties)?
Yes. It maps the chain tier by tier (T0–T4), so dependencies hiding two levels down become visible — and feed the supply-chain template in the register.
How do we get started?
Book a demo and we'll show it on your own data, or start a free 30-day evaluation. You can also try the public demo with no signup.
Pricing
Buy a licence, or request a quote
The desktop app for Mac and Windows is sold per seat. For organisation-wide rollout, the single-file edition is available under an enterprise-wide licence, quoted to your organisation.
-
Desktop app — Mac & Windows
€995 one-off · per seat
- Native installers for macOS and Windows.
- Fully offline — no server, no cloud; data stays on the device.
- All features: 2D & 3D, Contract Registry, EBA & XBRL export, VIEWER.
- Logos stored on disk; GLEIF lookups without CORS limits.
- Perpetual licence — the version you buy is yours to keep.
Secure checkout — card payment, instant download & licence key.
-
Enterprise-wide licence
Custom quote-based
- One organisation-wide licence — unlimited internal users.
- Delivered as the standalone single-file edition — host it yourself.
- Site-wide / tenant deployment (Azure, Cloudflare, intranet).
- Tailored onboarding and optional custom data analysis.
We’ll prepare an enterprise-wide offer for your organisation.
Licensing & deployment, available on request
Contact us for pricing, enterprise licensing, deployment information, or to request a live demo. You can also submit your contract database or supplier / DORA register for a customised analysis and visualisation service.