Skip to main content
Platform

Compliance Coverage Matrix

A detailed requirement-by-requirement mapping for 7 of the frameworks Arbitex supports, showing which detectors resolve each requirement. This is a point-in-time engineering artifact, not the full marketed framework list.

7
Compliance frameworks
135
Requirements mapped in this matrix

This matrix is a point-in-time snapshot, generated on 2026-05-07. It was produced by tools/dlp/generate-coverage-matrix.py from the detector registry and the active compliance pack files, and it has not been regenerated since. Individual statuses below may no longer reflect the current registry. Aggregate coverage percentages are deliberately not published here: we will not restate a summary figure we cannot currently reproduce. Pack-omission and detector-missing items are tracked and resolved through normal sprint cadence.

Status legend

  • Covered

    Detector exists and is mapped into the framework's compliance pack.

  • Pack omission

    Detector exists in the registry; the compliance pack does not yet list it. Pack edit pending.

  • Detector missing

    No canonical detector exists for this requirement. Registry expansion in flight.

  • Intentional gap

    Out of scope for content-DLP detection per framework rationale (process requirement, image modality, open-ended descriptors, etc.).

  • Unresolved

    Alias map could not resolve the required type. Map update pending.

EU AI Act

EU Artificial Intelligence Act (Regulation (EU) 2024/1689)

Authoritative source
13 covered8 pack omission1 detector missing3 intentional gap

Art. 10 — Special Categories of Personal Data

Required typeResolved detectorsStatus
racial_ethnic_origin
  • racial_ethnic_origin
Covered
political_opinion
  • political_opinion
Pack omission
religious_beliefs
  • religious_beliefs
Covered
trade_union_membership
  • trade_union_membership
Covered
genetic
  • genetic
Covered
biometric
  • biometric
Covered
health_info
  • health_info
Covered
sex_life
  • sex_life
Pack omission
sexual_orientation
  • sexual_orientation
Covered
reproductive_health
  • reproductive_health
Pack omission
mental_health_flag
  • mental_health_flag
Pack omission
hiv_status
  • hiv_status
Pack omission

Art. 10 — Personal Data in Training

Required typeResolved detectorsStatus
name
  • name
Covered
email
  • email
Covered
telephone
  • telephone
Pack omission
addressDetector missing
date_of_birth
  • date_of_birth
Pack omission
national_id_number
  • ssn
  • uk_nino
  • indian_aadhaar
  • indian_pan
  • au_tfn
  • canadian_sin
  • itin
Pack omission
ip_address
  • ip_address
Covered
online_identifier
  • ip_address
Covered

Annex III — Biometric Identification

Required typeResolved detectorsStatus
biometric
  • biometric
Covered

Annex III — Law Enforcement / Criminal

Required typeResolved detectorsStatus
criminal_convictions
  • criminal_convictions
Covered

Art. 50 — Deepfake Disclosure

Required typeResolved detectorsStatus
ai_generated_content_markerIntentional gap

Art. 50 mandates DISCLOSURE of AI-generated content, not detection of inbound content. Producer-side labeling obligation, not a DLP detection target.

Critical Infrastructure

Required typeResolved detectorsStatus
critical_infra_ot_signalsIntentional gap

OT/ICS protocol detection (Modbus, BACnet) and SCADA telemetry are infrastructure-modality data, not text-DLP targets.

Workers Management

Required typeResolved detectorsStatus
hr_decision_inputsIntentional gap

HR decision factors (tenure, performance scores) are open-ended business data, not regex-detectable. Tier-3 contextual validation handles via context.

GDPR

General Data Protection Regulation (EU 2016/679)

Authoritative source
15 covered5 pack omission1 detector missing2 intentional gap

Art. 4 — Personal Data

Required typeResolved detectorsStatus
name
  • name
Covered
email
  • email
Covered
telephone
  • telephone
Covered
addressDetector missing
date_of_birth
  • date_of_birth
Covered
national_id_number
  • ssn
  • uk_nino
  • indian_aadhaar
  • indian_pan
  • au_tfn
  • canadian_sin
  • itin
Covered

Pack lists subset (au_tfn, canadian_sin, indian_aadhaar, indian_pan, ssn, uk_nino); itin absent (partial — non-blocking).

government_issued_id
  • drivers_license
  • passport
  • uk_nhs_number
Covered
online_identifier
  • ip_address
Covered
location_data
  • geolocation
  • ip_address
Intentional gap

Covered by geolocation detector (registry alias) and ip_address; treated as ALIAS-RESOLVED, not gap.

cultural_social_economic_identity_factorsIntentional gap

Art. 4(1) mentions 'factors specific to cultural or social identity' — open-ended descriptors not amenable to deterministic detection. Tier-3 contextual validation handles open-ended text.

Art. 9 — Special Categories of Personal Data

Required typeResolved detectorsStatus
racial_ethnic_origin
  • racial_ethnic_origin
Covered
political_opinion
  • political_opinion
Pack omission
religious_beliefs
  • religious_beliefs
Covered
trade_union_membership
  • trade_union_membership
Covered
genetic
  • genetic
Covered
biometric
  • biometric
Covered
health_info
  • health_info
Covered
sex_life
  • sex_life
Pack omission
sexual_orientation
  • sexual_orientation
Covered
reproductive_health
  • reproductive_health
Pack omission
mental_health_flag
  • mental_health_flag
Pack omission
hiv_status
  • hiv_status
Pack omission

Art. 10 — Criminal Convictions

Required typeResolved detectorsStatus
criminal_convictions
  • criminal_convictions
Covered

HIPAA

Health Insurance Portability and Accountability Act — Privacy Rule (45 CFR Parts 160, 164)

Authoritative source
10 covered11 pack omission1 detector missing4 intentional gap

Safe Harbor — 18 Identifiers (§ 164.514(b)(2))

Required typeResolved detectorsStatus
name
  • name
Covered
addressDetector missing
date_of_birth
  • date_of_birth
Covered
telephone
  • telephone
Covered
fax
  • telephone
Covered
email
  • email
Covered
ssn
  • ssn
Covered
medical_record_number
  • medical_record_number
Pack omission
health_plan_member_id
  • health_plan_member_id
Pack omission
account_number
  • bank_account_number
Pack omission
drivers_license
  • drivers_license
Covered
dea_number
  • dea_number
Pack omission
vin
  • vin
Pack omission
license_plate
  • license_plate
Pack omission
ip_address
  • ip_address
Pack omission
biometric
  • biometric
Covered
npi
  • npi
Covered
claim_number
  • claim_number
Pack omission
rx_ndc
  • rx_ndc
Pack omission
subscriber_group_id
  • subscriber_group_id
Pack omission
policy_number
  • policy_number
Pack omission
device_identifiers_serial_numbersIntentional gap

Safe Harbor (M) — open-ended formats with no canonical regex; tier-3 contextual validation handles via context.

web_urlsIntentional gap

Safe Harbor (N) — URLs are not PII per se; redaction is a separate URL-stripping concern.

full_face_photographsIntentional gap

Safe Harbor (Q) — image modality, out of scope for text DLP.

any_other_unique_code_catchallIntentional gap

Safe Harbor (R) is a catch-all clause — coverage is best-effort via enumerated specific identifiers + tier-3 contextual validation.

Protected Health Information (PHI)

Required typeResolved detectorsStatus
health_info
  • health_info
Covered

ISO/IEC 42001

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Authoritative source
11 covered5 pack omission1 detector missing5 intentional gap

Personal Data Inputs

Required typeResolved detectorsStatus
name
  • name
Covered
email
  • email
Covered
telephone
  • telephone
Pack omission
addressDetector missing
date_of_birth
  • date_of_birth
Pack omission
ssn
  • ssn
Covered

Special Categories

Required typeResolved detectorsStatus
health_info
  • health_info
Covered
biometric
  • biometric
Covered
genetic
  • genetic
Covered
racial_ethnic_origin
  • racial_ethnic_origin
Covered
religious_beliefs
  • religious_beliefs
Pack omission

Secrets & Credentials

Required typeResolved detectorsStatus
api_key
  • api_key
Covered
bearer_token
  • bearer_token
Covered
private_key
  • private_key
Covered
connection_string
  • connection_string
Pack omission

Financial Data

Required typeResolved detectorsStatus
credit_card
  • credit_card
Covered
bank_account_number
  • bank_account_number
Pack omission

Management System Process Requirements

Required typeResolved detectorsStatus
clause_4_context_of_organizationIntentional gap

Clauses 4-7 (context, leadership, planning, support) are management-system structural requirements. Not detection-shaped.

clause_9_performance_evaluationIntentional gap

Clause 9 (monitoring, measurement, internal audit) is process. Compliance proven via audit artifacts.

clause_10_improvementIntentional gap

Clause 10 (continual improvement) — process requirement. No detection target.

a_5_policies_for_ai_systemsIntentional gap

Annex A.5 — policies for AI systems. Documentation requirement; tracked via policy management.

a_8_information_for_interested_partiesIntentional gap

Annex A.8 — transparency to deployers, users, affected persons. Disclosure obligation.

NIST AI RMF

NIST AI Risk Management Framework 1.0 (AI 100-1)

Authoritative source
11 covered8 pack omission1 detector missing4 intentional gap

PII Data Inventory

Required typeResolved detectorsStatus
name
  • name
Covered
email
  • email
Covered
telephone
  • telephone
Covered
addressDetector missing
date_of_birth
  • date_of_birth
Pack omission
ssn
  • ssn
Covered
ip_address
  • ip_address
Covered

Credentials & Secrets

Required typeResolved detectorsStatus
api_key
  • api_key
Covered
bearer_token
  • bearer_token
Covered
private_key
  • private_key
Covered
connection_string
  • connection_string
Covered
username_password_combo
  • username_password_combo
Pack omission

Special Category Inputs

Required typeResolved detectorsStatus
health_info
  • health_info
Covered
biometric
  • biometric
Covered
genetic
  • genetic
Pack omission
racial_ethnic_origin
  • racial_ethnic_origin
Pack omission
religious_beliefs
  • religious_beliefs
Pack omission
political_opinion
  • political_opinion
Pack omission

Financial Data

Required typeResolved detectorsStatus
bank_account_number
  • bank_account_number
Pack omission
credit_card
  • credit_card
Pack omission

Governance Process Requirements

Required typeResolved detectorsStatus
govern_1_1_legal_regulatory_complianceIntentional gap

GOVERN 1.1 — legal and regulatory requirements understanding. Process requirement, not a data type.

govern_3_2_workforce_diversityIntentional gap

GOVERN 3.2 — workforce diversity, equity, inclusion. Org-design requirement, not detection.

govern_4_1_organizational_risk_toleranceIntentional gap

GOVERN 4.1 — organizational practices for AI risk. Documentation requirement.

TEVV — Data Quality & Traceability

Required typeResolved detectorsStatus
data_lineage_metadataIntentional gap

Data lineage is metadata maintained by ML training pipelines, not detected at content-DLP tier.

PCI-DSS

Payment Card Industry Data Security Standard v4.0

Authoritative source
5 covered2 pack omission1 detector missing1 intentional gap

Cardholder Data

Required typeResolved detectorsStatus
credit_card
  • credit_card
Covered
payment_card_pan
  • credit_card
Covered

Sensitive Authentication Data

Required typeResolved detectorsStatus
cvv
  • cvv
Covered
magstripeDetector missing
pin_pin_blockIntentional gap

PINs are 4-6 digit numbers indistinguishable from arbitrary numerics by regex alone; covered by tier-3 contextual validation when emitted alongside PAN context.

Bank Routing Data

Required typeResolved detectorsStatus
bank_account_number
  • bank_account_number
Covered
ach_data
  • ach_data
Covered
swift_bic
  • swift_bic
Pack omission
uk_sort_code
  • uk_sort_code
Pack omission

SOX / SEC Reg FD

Sarbanes-Oxley Act / SEC Regulation FD — Material Non-Public Information

Authoritative source
6 covered

Financial Disclosure (Pre-Release)

Required typeResolved detectorsStatus
earnings_announcement
  • earnings_announcement
Covered

M&A Activity

Required typeResolved detectorsStatus
merger_acquisition
  • merger_acquisition
Covered

Insider Information

Required typeResolved detectorsStatus
insider_info
  • insider_info
Covered

Material Contracts

Required typeResolved detectorsStatus
material_contract
  • material_contract
Covered

Regulatory Actions

Required typeResolved detectorsStatus
regulatory_action
  • regulatory_action
Covered

Executive Personnel Changes

Required typeResolved detectorsStatus
executive_change
  • executive_change
Covered

Methodology

The matrix is generated programmatically from three sources of truth: the canonical detector registry that defines every entity Arbitex can detect, the per-framework requirements derived from each regulation's authoritative text, and the active compliance pack files that wire detectors into runtime policy. The generator runs in CI on every detector or pack change, so the matrix never drifts from the shipping product.

Pack omission means the detector exists and is shipping; the pack edit to surface it in policy is a routine sprint task. Detector missing means a small number of categories where a registry entry has not yet been added — these are scheduled in the validation-corpus expansion roadmap. Intentional gap means a requirement is out of scope for content-DLP detection (process-only, image modality, open-ended descriptors, etc.) and is satisfied by other controls.

Customer requirements that land outside this matrix are accepted into the registry expansion backlog. Contact [email protected] to flag a regulation, jurisdiction, or data type you need covered.

Matrix freshness: 2026-05-07.

Coverage you can audit.

Every detector. Every framework. Every status. Published openly so audit teams, compliance officers, and security leaders can verify what Arbitex covers — and what it does not.