Skip to main content
COMPLIANCE

Framework support, built into the gateway.

Arbitex is designed for regulated environments. The DLP pipeline, audit logging, and data residency controls map directly to the requirements of major compliance frameworks. This page documents what the gateway supports and how.

Frameworks

How Arbitex supports each framework.

Arbitex is not a certification authority. It is infrastructure that gives your compliance team the controls, evidence, and audit trail they need to meet framework requirements. For the AI governance frameworks — the EU AI Act, NIST AI RMF, and ISO/IEC 42001 — what Arbitex provides is detection coverage mapped to framework requirements. That is not a certification and not an attestation.

PCI-DSS

Payment card data protection

Gateway Controls

  • Luhn-validated card number detection in the regex pipeline. Primary Account Numbers (PANs), expiration dates, and CVVs detected and blocked or redacted before reaching any model.
  • PCI-DSS compliance bundle enforces detection on both input and output.

Evidence & Audit

Immutable audit log records every detection event with pattern type, enforcement action, and timestamp.

HIPAA

Protected Health Information (PHI)

Gateway Controls

  • PHI detection via ML-based entity recognition — medical record numbers, patient names, dates of birth, and other identifiers flagged and enforced.
  • HIPAA compliance bundle in the DLP layer. Business Associate Agreement (BAA) available.

Evidence & Audit

Audit log retention configurable to meet 45 CFR §164.312 requirements. All detection and enforcement actions logged with full chain-of-custody metadata.

SOX

Financial reporting data controls

Gateway Controls

  • Financial data detection rules in the DLP pipeline.
  • Policy engine enforces access controls by team and role. All policy changes logged with before/after deltas.

Evidence & Audit

tamper-proof audit trail provides tamper-evident records of every AI request involving financial data. On-demand compliance reports for audit cycles.

GLBA

Financial privacy and safeguards

Gateway Controls

  • Consumer financial information detection in the DLP pipeline.
  • Safeguards rule mapped to gateway data handling controls — encryption in transit (TLS 1.3), AES encryption with customer-managed key support at rest, access restricted by IAM grant.

Evidence & Audit

Audit log captures every access event. Data residency controls ensure financial data stays within designated boundaries.

GDPR

EU data protection and privacy

Gateway Controls

  • GDPR compliance bundle in the DLP layer. PII detection and enforcement on all requests.
  • Data residency options: deployed in your region or customer VPC via Hybrid Outpost — data never crosses region boundaries without explicit configuration.
  • Data Processing Agreement (DPA) available. Sub-processor list published quarterly with 30-day advance notice of changes.

Evidence & Audit

Data subject rights workflows supported. Deletion certificates available on account termination.

CCPA

California consumer privacy

Gateway Controls

  • Mapped to GDPR controls. Consumer data detection in the DLP pipeline.
  • Same enforcement actions, same audit trail.

Evidence & Audit

Audit records support consumer data access and deletion requests.

BSA/AML

Anti-money laundering and transaction monitoring

Gateway Controls

  • BSA/AML compliance bundle in the DLP layer.
  • Transaction-related data flagged and enforced per policy. Suspicious activity indicators detected in AI request content.

Evidence & Audit

Immutable audit log with configurable retention for regulatory review periods.

SEC Reg FD

Material non-public information and selective disclosure

Gateway Controls

  • Material non-public information detected in the DLP pipeline — insider information and pending regulatory action references are flagged and blocked before reaching any AI model.
  • Policy engine enforces access controls by team and role, so MNPI handling is restricted to authorized groups.

Evidence & Audit

Immutable audit log records every detection event with pattern type, enforcement action, and timestamp.

FERPA

Student education records

Gateway Controls

  • Student education record identifiers detected in the DLP pipeline — student IDs and transcript data are redacted before reaching any AI model.
  • FERPA compliance bundle seeded as a system policy pack, enforced on both input and output.

Evidence & Audit

Audit log records every detection and enforcement action with full chain-of-custody metadata.

EU AI Act

AI system risk classification and prohibited practices

Gateway Controls

  • AI risk classification language detected and flagged, mapped to the Act’s risk-tier requirements.
  • Biometric identification and social scoring references detected and blocked, mapped to the prohibited-practice provisions.
  • Content requiring AI transparency disclosure is flagged for review.

Evidence & Audit

Every detection is recorded in the immutable audit log with its framework reference, supporting AI governance documentation.

NIST AI RMF

AI risk management across GOVERN, MAP, and MANAGE functions

Gateway Controls

  • Training data and model artifact references detected and flagged, addressing data and IP leakage.
  • AI service credentials detected and redacted before reaching a model.
  • Prompt injection patterns detected and flagged as an adversarial robustness control.

Evidence & Audit

Detection events are logged with their framework mapping, providing evidence for AI risk management reviews.

ISO/IEC 42001

AI management system controls

Gateway Controls

  • AI bias and fairness terminology detected and flagged, supporting bias monitoring.
  • AI incident reporting language and data quality documentation references detected and flagged.
  • AI system documentation artifacts identified in AI request content.

Evidence & Audit

Detection events are logged with their control mapping, supporting AI management system documentation.

At a Glance

Framework coverage summary.

FrameworkDLP DetectionControlAudit TrailData Residency
PCI-DSSLuhn-validated PANs, CVVsBlock / Redacttamper-proofVPC / SaaS
HIPAAPHI via ML entity recognitionBlock / RedactConfigurable retentionVPC / SaaS
SOXFinancial data rulesAccess controlsBefore/after deltasVPC / SaaS
GLBAConsumer financial infoSafeguards enforcementAccess event loggingVPC / SaaS
GDPRPII detectionBlock / RedactData subject workflowsUS / EU / VPC
CCPAMapped to GDPRMapped to GDPRConsumer request supportUS / VPC
BSA/AMLTransaction indicatorsFlag / EnforceLong-term retentionVPC / SaaS
SEC Reg FDMaterial non-public informationBlocktamper-proofVPC / SaaS
FERPAStudent education recordsRedactChain-of-custodyVPC / SaaS
EU AI ActRisk classification, biometric, social scoringBlock / FlagFramework-referencedVPC / SaaS
NIST AI RMFTraining data, model artifacts, AI credentialsRedact / FlagFramework-referencedVPC / SaaS
ISO/IEC 42001Bias, incident, and documentation signalsFlagControl-mappedVPC / SaaS
Certifications

Where we are on the compliance journey.

SOC 2 Type II

Designed for SOC 2 Type II. Controls mapped and audit evidence automated. Formal attestation in progress.

HIPAA BAA

Business Associate Agreement available on Enterprise plans. PHI detection and enforcement enforced via the HIPAA compliance bundle.

PCI DSS

DLP pipeline supports Luhn-validated PAN detection, CVV identification, and magnetic stripe data enforcement. Compliance bundle ships with the gateway.

ISO 27001

Information security management system aligned to ISO 27001 Annex A controls. Formal certification on the roadmap.

Data Residency

Your data stays where you put it.

US SaaS

Default deployment in US-based Azure infrastructure. All data processed and stored domestically.

Hybrid Outpost

Deploy the data plane in your own environment. Prompts and responses never leave your network. Control plane sync is outbound-only HTTPS.

Learn about Outpost

Sovereign Deployment

For organizations with strict data sovereignty requirements. Outpost supports fully air-gapped operation with offline AI detection and local audit storage.

Audit Trail

Tamper-evident by construction.

  • tamper-proof audit records (v2) — every record cryptographically linked to the previous, making tampering detectable.
  • Every request logged with detection events, policy actions, and timestamps. No gaps in the chain.
  • Retention configurable up to 365 days. Retention periods set per organization in the admin portal.
  • Export to SIEM via Splunk, Microsoft Sentinel, or Elastic. OCSF-formatted records for cross-platform compatibility.
  • Signed audit exports available for external verification and regulatory submission.
BAA

Business Associate Agreements.

Arbitex offers Business Associate Agreements (BAAs) on Enterprise plans. The BAA covers the gateway's processing of Protected Health Information (PHI) as defined under HIPAA. PHI detection and enforcement are handled by the HIPAA compliance bundle in the DLP pipeline. Contact the sales team to initiate a BAA.

Talk to Sales

Arbitex provides infrastructure controls and audit evidence designed to support compliance with the frameworks listed above. Arbitex does not certify, attest, or guarantee compliance on behalf of customers. Compliance is the responsibility of the deploying organization. Customers should consult their legal and compliance teams to determine how Arbitex controls map to their specific obligations.

Read the compliance framework docs

Map your compliance requirements.

Walk through the framework controls with an Arbitex engineer. We will show you exactly how the gateway supports your regulatory obligations.