Sovereign Trust, NCA & SDAIA Compliance, & Zero Compromise
Engineered from first principles to strictly satisfy the regulatory standards of the National Cybersecurity Authority (NCA) and the Saudi Data and AI Authority (SDAIA).
National Cybersecurity Authority Alignment
ECC-1:2018 · CSCC-1:2019 · CCC-1:2020Envelope Encryption at Edge
AES-256-GCM encryption executes client-side before any chunk leaves the gateway perimeter. Physical storage hosts only ever persist ciphertext blocks.
Air-Gapped Sovereign Mode
Operates completely severed from external public networks. Zero cloud-vendor dependencies, telemetry backdoors, or international DNS/NTP lookups.
Tamper-Proof WORM Logging
Immutable append-only audit records for every bucket access, chunk commit, and policy modification with automated Syslog/SIEM forwarding.
Saudi Data & AI Authority (PDPL)
Personal Data Protection Law ComplianceStrict National Boundary Pinning
Primary data and Cauchy parity blocks are physically restricted to certified Saudi datacenter nodes. Prohibits cross-border egress or overseas mirroring.
Cryptographic Partition Shredding
Per-object Data Encryption Key (DEK) destruction ensures deleted records are mathematically scrambled and unrecoverable across all Cauchy stripes.
Customer HSM Key Custody
Master keys are held exclusively within customer-managed Hardware Security Modules (PKCS#11 / KMIP). Neither Aarkam engineers nor external operators have plaintext access.
Cryptographic Custody & Air-Gapped Architecture
FIPS 140-3 Hardware Key Isolation & National AutonomyAarkam provides enterprise and government sector operators with complete cryptographic isolation. Data encryption keys (DEKs) are generated client-side and encrypted with key-encryption keys (KEKs) hosted strictly within customer-owned Hardware Security Modules.
Native support for S3 Object Lock in Compliance Mode enforces non-erasable, non-overwritable WORM (Write Once, Read Many) policies required for legal audit archives, financial recordkeeping, and national registries.