Built for Enterprise Trust
Security, compliance, and privacy at the core of every request. Arbitex Gateway was designed as a governance layer — not retrofitted with one.
Security at every layer.
Every component of the Arbitex architecture is built with security-first design. Encryption, authentication, and audit integrity are properties of the system — not add-ons.
SOC 2 Type II
Designed for SOC 2 Type II compliance. Controls mapped across security, availability, and confidentiality trust service criteria. Formal audit engagement planned.
Encryption at Rest
AES encryption at rest with cryptographic integrity verification for stored data. Customer-managed keys (BYOK) supported for enterprise deployments.
Encryption in Transit
TLS 1.2+ enforced on all connections. No plaintext transport paths.
mTLS
Mutual TLS authentication between Outpost deployments and the Arbitex control plane. Both endpoints verified on every connection.
Tamper-proof Audit Trail
Every audit log entry is cryptographically signed and chain-linked to its predecessor. Each entry includes a cryptographic hash of the previous record, creating a tamper-evident sequence. Any insertion, deletion, or modification breaks the chain — detectable by automated integrity verification.
Measured, not assumed.
Every DLP detector is tested against a comprehensive labeled dataset across 40+ entity types. We publish verified accuracy scores — not marketing claims.
Structured Formats
Credit card numbers, SSNs, IBANs, and other checksum-validated formats are arithmetically validated, not just pattern-matched. Format validation plus check-digit verification rules out arbitrary digit strings such as invoice or order numbers.
Contextual Detection
Names, addresses, and medical terms are validated using surrounding context — nearby labels, corroborating entities, and AI-powered analysis. This multi-signal approach delivers high accuracy even on free-text and mixed-context content.
Continuous Validation
Every CI build runs the full detection dataset. Regressions are caught before deployment — no detector ships without passing accuracy gates.
12 Compliance Frameworks
Arbitex Gateway maps DLP enforcement and audit controls to the frameworks your compliance team already uses. Each framework maps specific entity types, enforcement actions, and audit evidence to the relevant regulatory requirements.
HIPAA
PHI detection and redaction at the gateway layer. DLP patterns cover 18 HIPAA identifiers including MRN, diagnosis codes, and provider NPIs. Audit logs map to access and disclosure controls required under the Security Rule.
PCI-DSS
Cardholder data detection across prompts and completions with Luhn-validated PAN recognition. Configurable redaction or block policies enforce PCI-DSS Requirement 3 (protect stored data) and Requirement 7 (restrict access).
SOX
Financial data classification and access audit trails aligned to SOX Section 302 and 404 requirements. tamper-proof logs provide the evidence trail for internal control attestation.
GDPR
PII detection across EU personal data categories, right-to-deletion workflows, and data residency controls. DLP enforcement ensures personal data is not sent to AI models without policy approval.
CCPA
California consumer data detection with configurable retention limits. Detection patterns cover the personal information categories defined under CCPA Section 1798.140, with audit evidence for disclosure requests.
GLBA
Financial consumer data protection with detection patterns for nonpublic personal information (NPI) categories defined under the Safeguards Rule. Covers account numbers, SSNs, and financial transaction data.
BSA/AML
Detection patterns for financial instrument identifiers and transaction data relevant to anti-money laundering controls. Supports suspicious activity report (SAR) evidence collection through audit log exports.
SEC Reg FD
Material non-public information detection — insider information and pending regulatory action references are flagged and blocked before reaching a model. Policy controls restrict MNPI handling to authorized groups, with a tamper-evident audit record of every detection.
FERPA
Student education record detection covering student identifiers and transcript data, redacted before reaching a model. Audit evidence supports the disclosure-tracking obligations under 34 CFR Part 99.
EU AI Act
Detection for AI risk classification language, biometric identification references, and social scoring — the practices the Act restricts or prohibits. Content requiring transparency disclosure is flagged for review.
NIST AI RMF
Detection mapped to the GOVERN, MAP, and MANAGE functions — training data and model artifact references, AI service credentials, and prompt injection patterns, each logged with its framework mapping.
ISO/IEC 42001
Detection for AI bias and fairness terminology, incident reporting language, and AI system documentation artifacts, supporting the bias-monitoring and documentation controls of an AI management system.
Privacy & Data Handling
Your data stays yours. Arbitex enforces data handling controls at the gateway — not through policy documents alone.
Data Residency
US-hosted SaaS (default). EU data residency available for Enterprise plans.
No Training on Customer Data
Customer prompts, responses, and metadata are never used to train models — ours or any provider's.
Audit Log Retention
Configurable retention periods. Default 90 days for SaaS, unlimited for Outpost self-hosted deployments.
Right to Deletion
Request deletion of all organizational data. Processed within 30 days per our data processing agreement.
Availability & Deployment
Deploy in the model that fits your compliance posture. Fully managed cloud, hybrid Outpost, or fully air-gapped — governance is consistent across all three.
Multi-Region SaaS
Cloud-hosted gateway with regional availability. No infrastructure to manage.
Outpost Self-Hosted
Deploy the Arbitex data plane within your own infrastructure. Customer-managed compute, Arbitex-managed control plane.
Air-Gap Deployment
Outpost supports on-premises deployment with local DLP inference and audit storage. Policy bundles sync automatically or can be sideloaded for restricted network environments.
Security Inquiries
For security inquiries, vulnerability reports, or compliance documentation requests.
Security documentation at your fingertips.
Review our security architecture, compliance mappings, and deployment documentation.