Skip to main content
CERTIFICATIONS & VALIDATION

Third-party validated. Continuously tested.

Independent assessments, structured controls, and regular penetration testing — not just checkboxes.

SOC 2 Type II — Designed-For Controls

Arbitex's infrastructure and operational controls are designed to meet SOC 2 Type II requirements across Trust Services Criteria. The gateway architecture implements controls for security, availability, processing integrity, confidentiality, and privacy — validated through continuous monitoring and documented evidence collection.

Security

Role-based access control, MFA enforcement, SAML 2.0 SSO, SCIM provisioning, and network segmentation enforce least-privilege across every access path.

Availability

Health monitoring, automatic failover routing, and provider degradation detection maintain service continuity without manual intervention.

Processing Integrity

tamper-proof audit logs, deterministic DLP pipeline execution, and immutable event records ensure every request is processed exactly as configured.

Confidentiality

AES encryption at rest, TLS 1.3 minimum in transit, tenant isolation at the database level, and no cross-tenant data leakage by design.

Privacy

No training on customer data, configurable retention policies, right-to-deletion support, and data processing agreements available on request.

SOC 2 Type II audit engagement is underway. Controls are implemented and operating; formal attestation report expected Q3 2026.

NIST Cybersecurity Framework Alignment

Arbitex maps its security program to the NIST Cybersecurity Framework (CSF), covering all five core functions. This alignment provides a structured, repeatable approach to managing cybersecurity risk across the platform.

Identify

Asset inventory, data classification, and risk assessment processes catalog all system components, data flows, and third-party dependencies.

Protect

3-tier DLP pipeline, encryption at rest and in transit, identity federation, and secrets management enforce preventive controls at every layer.

Detect

Real-time anomaly detection, OpenTelemetry instrumentation, SIEM integration, and automated alert rules surface threats as they emerge.

Respond

Documented incident response procedures, severity-based escalation (P0–P3), 24-hour breach notification, and post-mortem review within 5 business days.

Recover

Automated failover routing, provider health recovery, backup and restore procedures, and lessons-learned integration into control improvements.

Penetration Testing & External Validation

Regular third-party penetration testing validates the security posture of the Arbitex Gateway across application, infrastructure, and API layers.

Testing Cadence

Annual third-party penetration tests conducted by qualified security firms. Next scheduled engagement: Q3 2026. Remediation of critical and high findings is completed before the next release cycle.

Scope

Testing covers the full attack surface: web application (OWASP Top 10), API endpoints, authentication and authorization flows, DLP bypass attempts, infrastructure configuration, and container security.

Reporting

Executive summaries and detailed findings are available to enterprise customers under NDA. Remediation timelines and retest results are tracked and shared upon request.

Dependency Security

Continuous npm audit monitoring with zero tolerance for high and critical vulnerabilities. All production dependencies are pinned to exact versions. No GPL, AGPL, or SSPL dependencies permitted.

Responsible Disclosure

Security researchers can report vulnerabilities to [email protected]. Initial response within 48 hours. See our security page for full disclosure policy.

Need our security documentation?

Request our SOC 2 readiness package, penetration test summaries, or security questionnaire responses.