GTools.pro — Zero-Knowledge M365
ToolsPricingDesktopCompareSecurityTrustAbout
  1. Home
  2. Industries
  3. Financial Services

Microsoft 365 for Financial Services — DORA-Aware Backup & Audit

Zero-knowledge Microsoft 365 backup, audit evidence and migration for financial firms. DORA ICT third-party risk minimisation, BaFin MaRisk / BAIT and GoBD aware.

Frequently asked questions

Is GTools.pro DORA-ready for a financial services firm?

DORA (Regulation (EU) 2022/2554, applicable from 17 January 2025) requires formal management of ICT third-party risk. GTools.pro reduces that risk at the source: it is zero-knowledge, so as a provider we structurally cannot read your data, and the Desktop edition keeps data on your own machine so there is no vendor control plane to attest. Watchtower also produces the point-in-time control evidence auditors expect. This is general information, not legal or regulatory advice.

Can GTools.pro produce audit evidence for ISO 27001 or SOC 2?

Yes. Watchtower exports point-in-time reports (SharePoint permissions, oversharing, privileged access, Conditional Access posture, Entra ID role exposure) to JSON, CSV and signed PDF evidence packs suitable for ISO 27001, SOC 2 and DORA control evidence.

How does a zero-knowledge tool help with BaFin outsourcing requirements?

MaRisk and BAIT expect you to manage information-security and outsourcing risk. A provider that only ever holds ciphertext — and a Desktop edition that holds nothing at all — minimises the data exposure you have to control and document versus a data-processor vendor holding readable copies.

Does the backup retain records immutably for GoBD?

GTools.pro produces point-in-time exports to storage you control, giving you immutable, auditable snapshots that support GoBD-style tamper-evident retention. Restore and reapply are manual operator actions using those snapshots as the source of truth.

Related topics

  • DORA Microsoft 365 backup
  • financial services M365 audit
  • BaFin MaRisk Microsoft 365
  • Finanzdienstleister Microsoft 365 Backup
  • ICT third-party risk M365

Why it matters for Finanzdienstleister & Banken

Microsoft 365 backup, audit evidence and migration for financial firms — DORA-aware ICT third-party risk minimisation with data the vendor cannot read.

Compliance drivers

  • DORA — Regulation (EU) 2022/2554. The Digital Operational Resilience Act applies from 17 January 2025 and puts ICT third-party risk under formal oversight; a provider that only ever holds ciphertext materially shrinks the data exposure you must document and manage. Regulation (EU) 2022/2554 (DORA) — EUR-Lex
  • BaFin MaRisk / BAIT. BaFin’s MaRisk and BAIT set expectations for IT and outsourcing risk management at supervised institutions; keeping backup data unreadable to the provider supports the outsourcing-risk and information-security controls. BaFin — MaRisk
  • GoBD (retention + immutability). The GoBD require orderly, tamper-evident retention of tax-relevant records; point-in-time exports you control provide immutable, auditable evidence. BMF — GoBD

Sector challenges and how GTools.pro answers them

  • DORA requires you to inventory and manage every ICT third party that can access your data. A zero-knowledge provider that structurally cannot read your data is the easiest kind of third party to attest — Desktop keeps data on-premise entirely.
  • Auditors and supervisors demand point-in-time evidence of access, oversharing and privileged roles. Watchtower exports signed, point-in-time audit evidence (SharePoint permissions, oversharing, privileged access, Conditional Access posture) suitable for ISO 27001 / SOC 2 / DORA control evidence.
  • Fixed-window native backup and Teams-chat gaps leave recordkeeping holes. Configurable-retention backup that includes Teams chat and channel messages, exported to storage you control.

Microsoft 365 workloads that matter here

  • Exchange Online (regulated communications)
  • Teams chat + channels (recordkeeping)
  • SharePoint / OneDrive (evidence, working papers)
  • Entra ID roles + Conditional Access (privileged access, SoD)

Recommended editions

  • Watchtower (audit). Signed point-in-time control evidence for ISO 27001 / SOC 2 / DORA — EUR 7 / user / year.
  • Backup. Teams-inclusive, zero-knowledge backup with configurable retention — EUR 14 / user / year.

Limitations & out-of-scope — what GTools.pro is not for in Financial Services

GTools.pro is an administrator toolkit, not a regulated recordkeeping or WORM archival system, and it does not itself certify DORA/MaRisk compliance — those are your firm’s and your auditor’s determinations. Watchtower is a detective control: it reports, it does not remediate. Backup coverage is bounded by Microsoft Graph permissions and Graph throttling limits.

This page is general information, not legal, tax, or regulatory advice.

About the platform

This is a zero-knowledge toolkit. It helps IT admins, MSPs, security teams run their cloud safer. Use it inside a browser. Or install our Mac or Windows app.

Tenant secrets stay on your disk. We never store, log, or read them. Our server only sees billing metadata.

How it works

  1. You unlock a local vault with a passphrase. Argon2id stretches it.
  2. Tokens get sealed with XChaCha20-Poly1305 before any sync.
  3. X25519 protects shared keys. Ed25519 signs every action.
  4. Each operation runs against Graph from your device, not ours.

What you can do

  • Back up mail. Files. Chat threads.
  • Export Intune settings. One click.
  • Audit SharePoint shares. Spot risk.
  • Find idle sites. Reclaim quota.
  • Score Copilot. Plan rollout.
  • Move tenants. No staging.
  • Client-side keys. Always on.
  • Your data. Your disk.
  • One app. Many tenants.

Editions

  • Solo. Free. Three tools. No card.
  • Backup. Durable backups for your tenant.
  • Watchtower. Audits and alerts on risk.
  • Move. Tenant migration suite.
  • Blueprint. Config export for enterprise.
  • Everything. Full platform plus desktop and support.

Trust signals

  • Open source crypto primitives via libsodium.
  • Public threat model at /trust.
  • Public pricing. Direct purchase. No sales call.
  • Cancel any time inside settings.
  • EU-based billing. PayPal checkout today; card payments planned.

Built in Germany by Voltage Brothers Infrastruktur UG. Suits cloud workspaces of every size.

Standards, regions, retention

Regions: Frankfurt. Dublin. North America. Retention scales from 7 days. Up to unlimited. Schedules run hourly. Daily. Weekly. Monthly. Reports export as JSON. CSV. PDF. Evidence packs bundle hashes. Chain-of-custody metadata sits beside them.

Standards covered: ISO 27001 controls. SOC 2 readiness. NIS2 mapping. GDPR Article 28 terms. Audit logs cover entitlement events. Billing actions. License rotations. Workload payloads never reach a remote log.

Who uses it

  • Tenant admins running a single estate.
  • MSPs managing dozens of customer cloud workspaces.
  • Security teams investigating sharing risk.
  • Compliance officers preparing audit evidence.
  • Acquisition teams during M&A integration.
  • Procurement teams reviewing vendor risk.
  • Solo consultants billing by workspace hour.

Supported regions

Frankfurt, Dublin, Amsterdam, Stockholm, Paris, plus North America. Annual revenue scales from small studios up through multinational estates. Payment today is PayPal checkout; card payments (Stripe) are planned.

Numbers worth knowing

  • 49 capabilities. 6 editions.
  • Free tier: 3 tools. 0 cards.
  • Argon2id. 256 MB memory cost.
  • XChaCha20-Poly1305. 256-bit cipher.
  • X25519. 256-bit shared keys.
  • Ed25519. 100% of writes signed.
  • Retention: 7 days. 365 days. Or unlimited.
  • Founded 2024. Built in Germany.
  • Backup edition: 14 EUR per user per year.
  • Watchtower edition: 7 EUR per user per year.
  • Move edition: 9 EUR per migrated seat. One-time. 450 EUR project minimum.
  • Blueprint edition: 449 EUR per tenant per year.
  • Everything bundle: 2490 EUR per tenant per year.
  • Audit reports: 25 dedicated checks.
  • Config export: 9 Microsoft 365 workloads.
  • Migration record set in April 2026. 153,584 files. 0 errors.
  • Compliance posture updated in 2026.
  • Pricing: 1 public page. 0 sales calls.
  • Cancellation: 1 self-service page.
  • Audit logs: 90 days. Entitlement events.
  • GDPR Article 28. 27 member states.
  • NIS2 Directive. 18 sectors. Live since 2024.
  • SOC 2 Type II evidence. JSON. CSV. Signed PDF.
  • ISO 27001. 93 Annex A controls. 2022 revision.

Product.

  • Tools.
  • Pricing.
  • Desktop.
  • Security.
  • Compare.
  • Download.

Company.

  • About.
  • Trust & Compliance.
  • Privacy Policy.
  • Terms of Service.
  • Impressum.

Connect.

  • hello@gtools.pro.
  • GitHub.

© 2026 GTools.pro · A product of Voltage Brothers Infrastruktur UG (haftungsbeschränkt).