CLOUD Act Exposure
US-headquartered vendors fall under the CLOUD Act regardless of where data is stored. Your data may be accessible to US authorities.
Built by a team in Finland. Hosted 100% in the EU. GDPR, NIS2, and CLOUD Act immunity by architecture — not by checkbox. The platform your IT and compliance teams can approve without caveats.
Hosting
100% EU
CLOUD Act
Immune
API Access
Open
Security & Compliance
Compliance Posture
GDPR
CLOUD Act
NIS2 / DORA
Data Residency
REST / GraphQL API
Compliance teams veto vendors over data sovereignty gaps. Regulations are tightening, not relaxing.
“Legal vetoed our last vendor because of CLOUD Act exposure. We need a platform we can actually approve.”
European procurement now requires real data sovereignty — not a checkbox in a US-hosted platform.
What compliance teams face
Vendors with CLOUD Act exposure.
GDPR treated as checkbox, not architecture.
NIS2, DORA, EU Data Act deadlines approaching.
US-headquartered vendors fall under the CLOUD Act regardless of where data is stored. Your data may be accessible to US authorities.
Most platforms treat GDPR as configuration, not architecture. Data residency “options” are not real sovereignty.
Limited API access creates vendor lock-in. Data export is restricted and integrations require expensive custom work.
NIS2, DORA, and the EU Data Act raise the bar for data governance and portability. Platforms that aren't ready now will create gaps.
Every layer — hosting, APIs, audit trails, access control — is European by default.
Step 01
100% EU-hosted. Data never leaves European jurisdiction. Immune to the U.S. CLOUD Act.
Step 02
Full API access to your stack. Connect to any LMS, CRM, or accounting system. Data always exportable.
Step 03
Every action recorded in an immutable audit trail. Full provenance for regulatory review.
Step 04
Granular permissions at organisation, department, and role level. SSO + BankID + FTN + regional e-ID.
CompetenceFlow addresses these requirements by architecture, not as add-ons.
NIS2 Directive
DORA
EU Data Act
Region-specific compliance, identity, and integrations — covered.
Identity
Swedish BankID, Norwegian BankID, Finnish Trust Network (FTN)
Finance Integration
Visma (Netvisor, Tripletex, e-conomic) • Fortnox
Credential Registers
Taitorekisteri (Finland) • SSG Skillnation • ID06
Compliance
GoBD-compliant audit trails • BSI C5 ready • AZAV workflow support
Finance Integration
DATEV • SKR03/04 • ZUGFeRD e-invoicing
Data Governance
Immutable journal entries • Full provenance chain
Cloud Standard
SecNumCloud alignment • EU-hosted infrastructure
Quality Framework
Qualiopi audit-ready workflows • Evidence trail generation
E-Invoicing
Factur-X • Peppol • Machine-readable formats
No hidden costs. No vendor lock-in. Full data export at any time. Annual contracts with a standard exit clause.
See Pricing arrow_forwardFull access to your data. Connect to any system in your stack.
CompetenceFlow API
v2 • REST • GraphQL
JSON-native • OAuth 2.0 • Webhook support • Full data export in JSON/CSV
Data Export
Full — anytime
No-Code Builder
Drag-and-drop connectors
Vendor Lock-in
Zero
Answers to the concerns we hear most from training providers evaluating a platform change.
Built by a team in Finland. Hosted in Europe. Compliant with European regulation. See it in action.