Compliance Coverage Matrix
A detailed requirement-by-requirement mapping for 7 of the frameworks Arbitex supports, showing which detectors resolve each requirement. This is a point-in-time engineering artifact, not the full marketed framework list.
This matrix is a point-in-time snapshot, generated on 2026-05-07. It was produced by tools/dlp/generate-coverage-matrix.py from the detector registry and the active compliance pack files, and it has not been regenerated since. Individual statuses below may no longer reflect the current registry. Aggregate coverage percentages are deliberately not published here: we will not restate a summary figure we cannot currently reproduce. Pack-omission and detector-missing items are tracked and resolved through normal sprint cadence.
Status legend
- Covered
Detector exists and is mapped into the framework's compliance pack.
- Pack omission
Detector exists in the registry; the compliance pack does not yet list it. Pack edit pending.
- Detector missing
No canonical detector exists for this requirement. Registry expansion in flight.
- Intentional gap
Out of scope for content-DLP detection per framework rationale (process requirement, image modality, open-ended descriptors, etc.).
- Unresolved
Alias map could not resolve the required type. Map update pending.
Frameworks at a glance
EU AI Act
EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
- Requirements
- 25
- Covered
- 13
- Pack omission
- 8
- Detector missing
- 1
- Intentional gap
- 3
- Detector-backed (in-scope)
- 95%
GDPR
General Data Protection Regulation (EU 2016/679)
- Requirements
- 23
- Covered
- 15
- Pack omission
- 5
- Detector missing
- 1
- Intentional gap
- 2
- Detector-backed (in-scope)
- 95%
HIPAA
Health Insurance Portability and Accountability Act — Privacy Rule (45 CFR Parts 160, 164)
- Requirements
- 26
- Covered
- 10
- Pack omission
- 11
- Detector missing
- 1
- Intentional gap
- 4
- Detector-backed (in-scope)
- 95%
ISO/IEC 42001
ISO/IEC 42001:2023 — Artificial Intelligence Management System
- Requirements
- 22
- Covered
- 11
- Pack omission
- 5
- Detector missing
- 1
- Intentional gap
- 5
- Detector-backed (in-scope)
- 94%
NIST AI RMF
NIST AI Risk Management Framework 1.0 (AI 100-1)
- Requirements
- 24
- Covered
- 11
- Pack omission
- 8
- Detector missing
- 1
- Intentional gap
- 4
- Detector-backed (in-scope)
- 95%
PCI-DSS
Payment Card Industry Data Security Standard v4.0
- Requirements
- 9
- Covered
- 5
- Pack omission
- 2
- Detector missing
- 1
- Intentional gap
- 1
- Detector-backed (in-scope)
- 88%
SOX / SEC Reg FD
MNPI SuiteSarbanes-Oxley Act / SEC Regulation FD — Material Non-Public Information
- Requirements
- 6
- Covered
- 6
- Pack omission
- 0
- Detector missing
- 0
- Intentional gap
- 0
- Detector-backed (in-scope)
- 100%
EU AI Act
EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
Art. 10 — Special Categories of Personal Data
| Required type | Resolved detectors | Status |
|---|---|---|
racial_ethnic_origin |
| Covered |
political_opinion |
| Pack omission |
religious_beliefs |
| Covered |
trade_union_membership |
| Covered |
genetic |
| Covered |
biometric |
| Covered |
health_info |
| Covered |
sex_life |
| Pack omission |
sexual_orientation |
| Covered |
reproductive_health |
| Pack omission |
mental_health_flag |
| Pack omission |
hiv_status |
| Pack omission |
Art. 10 — Personal Data in Training
| Required type | Resolved detectors | Status |
|---|---|---|
name |
| Covered |
email |
| Covered |
telephone |
| Pack omission |
address | — | Detector missing |
date_of_birth |
| Pack omission |
national_id_number |
| Pack omission |
ip_address |
| Covered |
online_identifier |
| Covered |
Annex III — Biometric Identification
| Required type | Resolved detectors | Status |
|---|---|---|
biometric |
| Covered |
Annex III — Law Enforcement / Criminal
| Required type | Resolved detectors | Status |
|---|---|---|
criminal_convictions |
| Covered |
Art. 50 — Deepfake Disclosure
| Required type | Resolved detectors | Status |
|---|---|---|
ai_generated_content_marker | — | Intentional gap Art. 50 mandates DISCLOSURE of AI-generated content, not detection of inbound content. Producer-side labeling obligation, not a DLP detection target. |
Critical Infrastructure
| Required type | Resolved detectors | Status |
|---|---|---|
critical_infra_ot_signals | — | Intentional gap OT/ICS protocol detection (Modbus, BACnet) and SCADA telemetry are infrastructure-modality data, not text-DLP targets. |
Workers Management
| Required type | Resolved detectors | Status |
|---|---|---|
hr_decision_inputs | — | Intentional gap HR decision factors (tenure, performance scores) are open-ended business data, not regex-detectable. Tier-3 contextual validation handles via context. |
GDPR
General Data Protection Regulation (EU 2016/679)
Art. 4 — Personal Data
| Required type | Resolved detectors | Status |
|---|---|---|
name |
| Covered |
email |
| Covered |
telephone |
| Covered |
address | — | Detector missing |
date_of_birth |
| Covered |
national_id_number |
| Covered Pack lists subset (au_tfn, canadian_sin, indian_aadhaar, indian_pan, ssn, uk_nino); itin absent (partial — non-blocking). |
government_issued_id |
| Covered |
online_identifier |
| Covered |
location_data |
| Intentional gap Covered by geolocation detector (registry alias) and ip_address; treated as ALIAS-RESOLVED, not gap. |
cultural_social_economic_identity_factors | — | Intentional gap Art. 4(1) mentions 'factors specific to cultural or social identity' — open-ended descriptors not amenable to deterministic detection. Tier-3 contextual validation handles open-ended text. |
Art. 9 — Special Categories of Personal Data
| Required type | Resolved detectors | Status |
|---|---|---|
racial_ethnic_origin |
| Covered |
political_opinion |
| Pack omission |
religious_beliefs |
| Covered |
trade_union_membership |
| Covered |
genetic |
| Covered |
biometric |
| Covered |
health_info |
| Covered |
sex_life |
| Pack omission |
sexual_orientation |
| Covered |
reproductive_health |
| Pack omission |
mental_health_flag |
| Pack omission |
hiv_status |
| Pack omission |
Art. 10 — Criminal Convictions
| Required type | Resolved detectors | Status |
|---|---|---|
criminal_convictions |
| Covered |
HIPAA
Health Insurance Portability and Accountability Act — Privacy Rule (45 CFR Parts 160, 164)
Safe Harbor — 18 Identifiers (§ 164.514(b)(2))
| Required type | Resolved detectors | Status |
|---|---|---|
name |
| Covered |
address | — | Detector missing |
date_of_birth |
| Covered |
telephone |
| Covered |
fax |
| Covered |
email |
| Covered |
ssn |
| Covered |
medical_record_number |
| Pack omission |
health_plan_member_id |
| Pack omission |
account_number |
| Pack omission |
drivers_license |
| Covered |
dea_number |
| Pack omission |
vin |
| Pack omission |
license_plate |
| Pack omission |
ip_address |
| Pack omission |
biometric |
| Covered |
npi |
| Covered |
claim_number |
| Pack omission |
rx_ndc |
| Pack omission |
subscriber_group_id |
| Pack omission |
policy_number |
| Pack omission |
device_identifiers_serial_numbers | — | Intentional gap Safe Harbor (M) — open-ended formats with no canonical regex; tier-3 contextual validation handles via context. |
web_urls | — | Intentional gap Safe Harbor (N) — URLs are not PII per se; redaction is a separate URL-stripping concern. |
full_face_photographs | — | Intentional gap Safe Harbor (Q) — image modality, out of scope for text DLP. |
any_other_unique_code_catchall | — | Intentional gap Safe Harbor (R) is a catch-all clause — coverage is best-effort via enumerated specific identifiers + tier-3 contextual validation. |
Protected Health Information (PHI)
| Required type | Resolved detectors | Status |
|---|---|---|
health_info |
| Covered |
ISO/IEC 42001
ISO/IEC 42001:2023 — Artificial Intelligence Management System
Personal Data Inputs
| Required type | Resolved detectors | Status |
|---|---|---|
name |
| Covered |
email |
| Covered |
telephone |
| Pack omission |
address | — | Detector missing |
date_of_birth |
| Pack omission |
ssn |
| Covered |
Special Categories
| Required type | Resolved detectors | Status |
|---|---|---|
health_info |
| Covered |
biometric |
| Covered |
genetic |
| Covered |
racial_ethnic_origin |
| Covered |
religious_beliefs |
| Pack omission |
Secrets & Credentials
| Required type | Resolved detectors | Status |
|---|---|---|
api_key |
| Covered |
bearer_token |
| Covered |
private_key |
| Covered |
connection_string |
| Pack omission |
Financial Data
| Required type | Resolved detectors | Status |
|---|---|---|
credit_card |
| Covered |
bank_account_number |
| Pack omission |
Management System Process Requirements
| Required type | Resolved detectors | Status |
|---|---|---|
clause_4_context_of_organization | — | Intentional gap Clauses 4-7 (context, leadership, planning, support) are management-system structural requirements. Not detection-shaped. |
clause_9_performance_evaluation | — | Intentional gap Clause 9 (monitoring, measurement, internal audit) is process. Compliance proven via audit artifacts. |
clause_10_improvement | — | Intentional gap Clause 10 (continual improvement) — process requirement. No detection target. |
a_5_policies_for_ai_systems | — | Intentional gap Annex A.5 — policies for AI systems. Documentation requirement; tracked via policy management. |
a_8_information_for_interested_parties | — | Intentional gap Annex A.8 — transparency to deployers, users, affected persons. Disclosure obligation. |
NIST AI RMF
NIST AI Risk Management Framework 1.0 (AI 100-1)
PII Data Inventory
| Required type | Resolved detectors | Status |
|---|---|---|
name |
| Covered |
email |
| Covered |
telephone |
| Covered |
address | — | Detector missing |
date_of_birth |
| Pack omission |
ssn |
| Covered |
ip_address |
| Covered |
Credentials & Secrets
| Required type | Resolved detectors | Status |
|---|---|---|
api_key |
| Covered |
bearer_token |
| Covered |
private_key |
| Covered |
connection_string |
| Covered |
username_password_combo |
| Pack omission |
Special Category Inputs
| Required type | Resolved detectors | Status |
|---|---|---|
health_info |
| Covered |
biometric |
| Covered |
genetic |
| Pack omission |
racial_ethnic_origin |
| Pack omission |
religious_beliefs |
| Pack omission |
political_opinion |
| Pack omission |
Financial Data
| Required type | Resolved detectors | Status |
|---|---|---|
bank_account_number |
| Pack omission |
credit_card |
| Pack omission |
Governance Process Requirements
| Required type | Resolved detectors | Status |
|---|---|---|
govern_1_1_legal_regulatory_compliance | — | Intentional gap GOVERN 1.1 — legal and regulatory requirements understanding. Process requirement, not a data type. |
govern_3_2_workforce_diversity | — | Intentional gap GOVERN 3.2 — workforce diversity, equity, inclusion. Org-design requirement, not detection. |
govern_4_1_organizational_risk_tolerance | — | Intentional gap GOVERN 4.1 — organizational practices for AI risk. Documentation requirement. |
TEVV — Data Quality & Traceability
| Required type | Resolved detectors | Status |
|---|---|---|
data_lineage_metadata | — | Intentional gap Data lineage is metadata maintained by ML training pipelines, not detected at content-DLP tier. |
PCI-DSS
Payment Card Industry Data Security Standard v4.0
Cardholder Data
| Required type | Resolved detectors | Status |
|---|---|---|
credit_card |
| Covered |
payment_card_pan |
| Covered |
Sensitive Authentication Data
| Required type | Resolved detectors | Status |
|---|---|---|
cvv |
| Covered |
magstripe | — | Detector missing |
pin_pin_block | — | Intentional gap PINs are 4-6 digit numbers indistinguishable from arbitrary numerics by regex alone; covered by tier-3 contextual validation when emitted alongside PAN context. |
Bank Routing Data
| Required type | Resolved detectors | Status |
|---|---|---|
bank_account_number |
| Covered |
ach_data |
| Covered |
swift_bic |
| Pack omission |
uk_sort_code |
| Pack omission |
SOX / SEC Reg FD
Sarbanes-Oxley Act / SEC Regulation FD — Material Non-Public Information
Financial Disclosure (Pre-Release)
| Required type | Resolved detectors | Status |
|---|---|---|
earnings_announcement |
| Covered |
M&A Activity
| Required type | Resolved detectors | Status |
|---|---|---|
merger_acquisition |
| Covered |
Insider Information
| Required type | Resolved detectors | Status |
|---|---|---|
insider_info |
| Covered |
Material Contracts
| Required type | Resolved detectors | Status |
|---|---|---|
material_contract |
| Covered |
Regulatory Actions
| Required type | Resolved detectors | Status |
|---|---|---|
regulatory_action |
| Covered |
Executive Personnel Changes
| Required type | Resolved detectors | Status |
|---|---|---|
executive_change |
| Covered |
Methodology
The matrix is generated programmatically from three sources of truth: the canonical detector registry that defines every entity Arbitex can detect, the per-framework requirements derived from each regulation's authoritative text, and the active compliance pack files that wire detectors into runtime policy. The generator runs in CI on every detector or pack change, so the matrix never drifts from the shipping product.
Pack omission means the detector exists and is shipping; the pack edit to surface it in policy is a routine sprint task. Detector missing means a small number of categories where a registry entry has not yet been added — these are scheduled in the validation-corpus expansion roadmap. Intentional gap means a requirement is out of scope for content-DLP detection (process-only, image modality, open-ended descriptors, etc.) and is satisfied by other controls.
Customer requirements that land outside this matrix are accepted into the registry expansion backlog. Contact [email protected] to flag a regulation, jurisdiction, or data type you need covered.
Matrix freshness: 2026-05-07.
Coverage you can audit.
Every detector. Every framework. Every status. Published openly so audit teams, compliance officers, and security leaders can verify what Arbitex covers — and what it does not.