Skip to main content
TRUST CENTER

Built for Enterprise Trust

Security, compliance, and privacy at the core of every request. Arbitex Gateway was designed as a governance layer — not retrofitted with one.

Security Controls

Security at every layer.

Every component of the Arbitex architecture is built with security-first design. Encryption, authentication, and audit integrity are properties of the system — not add-ons.

SOC 2 Type II

Designed for SOC 2 Type II compliance. Controls mapped across security, availability, and confidentiality trust service criteria. Formal audit engagement planned.

Encryption at Rest

AES encryption at rest with cryptographic integrity verification for stored data. Customer-managed keys (BYOK) supported for enterprise deployments.

Encryption in Transit

TLS 1.2+ enforced on all connections. No plaintext transport paths.

mTLS

Mutual TLS authentication between Outpost deployments and the Arbitex control plane. Both endpoints verified on every connection.

Tamper-proof Audit Trail

Every audit log entry is cryptographically signed and chain-linked to its predecessor. Each entry includes a cryptographic hash of the previous record, creating a tamper-evident sequence. Any insertion, deletion, or modification breaks the chain — detectable by automated integrity verification.

Detection Accuracy

Measured, not assumed.

Every DLP detector is tested against a comprehensive labeled dataset across 40+ entity types. We publish verified accuracy scores — not marketing claims.

Structured Formats

Credit card numbers, SSNs, IBANs, and other checksum-validated formats are arithmetically validated, not just pattern-matched. Format validation plus check-digit verification rules out arbitrary digit strings such as invoice or order numbers.

Contextual Detection

Names, addresses, and medical terms are validated using surrounding context — nearby labels, corroborating entities, and AI-powered analysis. This multi-signal approach delivers high accuracy even on free-text and mixed-context content.

Continuous Validation

Every CI build runs the full detection dataset. Regressions are caught before deployment — no detector ships without passing accuracy gates.

Compliance

12 Compliance Frameworks

Arbitex Gateway maps DLP enforcement and audit controls to the frameworks your compliance team already uses. Each framework maps specific entity types, enforcement actions, and audit evidence to the relevant regulatory requirements.

HIPAA

PHI detection and redaction at the gateway layer. DLP patterns cover 18 HIPAA identifiers including MRN, diagnosis codes, and provider NPIs. Audit logs map to access and disclosure controls required under the Security Rule.

PCI-DSS

Cardholder data detection across prompts and completions with Luhn-validated PAN recognition. Configurable redaction or block policies enforce PCI-DSS Requirement 3 (protect stored data) and Requirement 7 (restrict access).

SOX

Financial data classification and access audit trails aligned to SOX Section 302 and 404 requirements. tamper-proof logs provide the evidence trail for internal control attestation.

GDPR

PII detection across EU personal data categories, right-to-deletion workflows, and data residency controls. DLP enforcement ensures personal data is not sent to AI models without policy approval.

CCPA

California consumer data detection with configurable retention limits. Detection patterns cover the personal information categories defined under CCPA Section 1798.140, with audit evidence for disclosure requests.

GLBA

Financial consumer data protection with detection patterns for nonpublic personal information (NPI) categories defined under the Safeguards Rule. Covers account numbers, SSNs, and financial transaction data.

BSA/AML

Detection patterns for financial instrument identifiers and transaction data relevant to anti-money laundering controls. Supports suspicious activity report (SAR) evidence collection through audit log exports.

SEC Reg FD

Material non-public information detection — insider information and pending regulatory action references are flagged and blocked before reaching a model. Policy controls restrict MNPI handling to authorized groups, with a tamper-evident audit record of every detection.

FERPA

Student education record detection covering student identifiers and transcript data, redacted before reaching a model. Audit evidence supports the disclosure-tracking obligations under 34 CFR Part 99.

EU AI Act

Detection for AI risk classification language, biometric identification references, and social scoring — the practices the Act restricts or prohibits. Content requiring transparency disclosure is flagged for review.

NIST AI RMF

Detection mapped to the GOVERN, MAP, and MANAGE functions — training data and model artifact references, AI service credentials, and prompt injection patterns, each logged with its framework mapping.

ISO/IEC 42001

Detection for AI bias and fairness terminology, incident reporting language, and AI system documentation artifacts, supporting the bias-monitoring and documentation controls of an AI management system.

Privacy

Privacy & Data Handling

Your data stays yours. Arbitex enforces data handling controls at the gateway — not through policy documents alone.

Data Residency

US-hosted SaaS (default). EU data residency available for Enterprise plans.

No Training on Customer Data

Customer prompts, responses, and metadata are never used to train models — ours or any provider's.

Audit Log Retention

Configurable retention periods. Default 90 days for SaaS, unlimited for Outpost self-hosted deployments.

Right to Deletion

Request deletion of all organizational data. Processed within 30 days per our data processing agreement.

Deployment

Availability & Deployment

Deploy in the model that fits your compliance posture. Fully managed cloud, hybrid Outpost, or fully air-gapped — governance is consistent across all three.

Multi-Region SaaS

Cloud-hosted gateway with regional availability. No infrastructure to manage.

Outpost Self-Hosted

Deploy the Arbitex data plane within your own infrastructure. Customer-managed compute, Arbitex-managed control plane.

Air-Gap Deployment

Outpost supports on-premises deployment with local DLP inference and audit storage. Policy bundles sync automatically or can be sideloaded for restricted network environments.

Security Inquiries

For security inquiries, vulnerability reports, or compliance documentation requests.

Security documentation at your fingertips.

Review our security architecture, compliance mappings, and deployment documentation.