Compliance Matrix
Cyber Security
Comprehensive Cybersecurity Compliance Matrix
Complete mapping across NCA ECC-2:2024, CCC-2:2024, DCC-1:2022, SDAIA PDPL, ISO 27001, SOC 2, and EU GDPR.
This document provides the formal Compliance Matrix and Technical Architecture Mapping for the Aarkam platform across international standards, European Union regulations, and Saudi Arabian statutory mandates.
1. Compliance Scorecard Overview
Following an exhaustive 6-phase engineering roadmap, 100% of the platform’s security and sovereignty controls have been implemented natively in code:
┌─────────────────────────────────────────────────────────┐
│ Aarkam IO COMPLIANCE SCORECARD │
├──────────────────────┬──────────────────────────────────┤
│ ✅ PHASE 1 DONE │ 8 items — All critical fixed │
│ ✅ PHASE 2 DONE │ 5 items — High gaps fixed │
│ ✅ PHASE 3 DONE │ 4 items — Medium gaps fixed │
│ ✅ PHASE 4 DONE │ 6 items — Process & Doc gaps │
│ ✅ PHASE 5 DONE │ 4 items — Zero-Trust Network │
│ ✅ PHASE 6 DONE │ 2 items — PDPL & Erasure │
├──────────────────────┼──────────────────────────────────┤
│ TECHNICAL MATURITY │ ████████████████████ 100% │
└──────────────────────┴──────────────────────────────────┘
2. Standards Cross-Reference
| Framework | Version | Governing Authority | Scope |
|---|---|---|---|
| NCA ECC | ECC-2:2024 | National Cybersecurity Authority (KSA) | Critical infrastructure, government & enterprise |
| NCA CCC | CCC-2:2024 | National Cybersecurity Authority (KSA) | Cloud service providers and sovereign tenants |
| NCA DCC | DCC-1:2022 | National Cybersecurity Authority (KSA) | Data protection lifecycle and residency |
| SDAIA PDPL | Royal Decree M/19 | Saudi Data & AI Authority (SDAIA) | Personal data processing & citizen privacy |
| ISO/IEC 27001 | 2022 Revision | International Organization for Standardization | Information security management systems |
| SOC 2 Type II | Trust Services Criteria | AICPA | Security, availability, and confidentiality |
| EU GDPR | Regulation (EU) 2016/679 | European Parliament & Council | Data protection, sovereignty, Right to Erasure |
3. Exhaustive Control Implementation Matrix
Domain 1: Cryptography & Key Custody (ECC 2-8, DCC, ISO 27001 §8.24)
| Requirement | Status | Technical Implementation in Aarkam |
|---|---|---|
| Data at Rest Encryption | ✅ Compliant | Transparent AES-256-GCM chunk encryption at storage node layer and EF Core EncryptionConverter at metadata layer. |
| Data in Transit Encryption | ✅ Compliant | Strict TLS 1.3 enforcement with RequireHttpsMetadata = true, HSTS headers, and ephemeral Diffie-Hellman keys. |
| Automated Key Rotation | ✅ Compliant | EncryptionKey domain entity enforces 90-day maximum lifespan via Rotate() and ShouldRotate(). |
| Zero-Knowledge HSM | ✅ Compliant | Native PKCS#11 and KMIP integration for customer-owned HSMs. Keys never enter Aarkam software boundaries. |
| Timing Attack Defense | ✅ Compliant | Authentication hashes verified using CryptographicOperations.FixedTimeEquals to prevent side-channel timing leaks. |
Domain 2: Identity & Access Management (ECC 2-2, SOC 2 CC6)
| Requirement | Status | Technical Implementation in Aarkam |
|---|---|---|
| Multi-Factor Authentication | ✅ Compliant | Mandatory RFC 6238 TOTP via IMfaService for all administrative and tenant-privileged logins. |
| Password Hygiene (NIST) | ✅ Compliant | Minimum 12 characters, complexity rules, and 120-day password history validator (PasswordHistoryValidator). |
| Account Lockout Policy | ✅ Compliant | Automatic 15-minute account lockout after 5 consecutive failed authentication attempts. |
| Session Concurrency | ✅ Compliant | LoginByUserNameOrEmailHandler restricts accounts to 3 concurrent sessions, pruning the oldest upon violation. |
| Instant Token Revocation | ✅ Compliant | Password modifications trigger immediate revocation of all active JWT refresh tokens. |
Domain 3: Network & Zero Egress (CCC 2-1, DCC, GDPR Art 44-50)
| Requirement | Status | Technical Implementation in Aarkam |
|---|---|---|
| Zero Cross-Border Egress | ✅ Compliant | Data chunks pinned strictly to certified sovereign datacenters with boundary IP filtering. |
| mTLS Internal Service Mesh | ✅ Compliant | All inter-node gRPC channels enforce mutual X.509 certificate authentication over TLS 1.3. |
| Dual-Plane Segmentation | ✅ Compliant | Complete physical network segregation between Public/DMZ client edge and internal storage backplanes. |
Domain 4: Data Governance & Privacy (SDAIA PDPL, EU GDPR Art 17)
| Requirement | Status | Technical Implementation in Aarkam |
|---|---|---|
| Right to Erasure | ✅ Compliant | Cryptographic partition shredding destroys per-object DEKs, rendering purged data mathematically unrecoverable. |
| WORM Audit Trails | ✅ Compliant | Append-only FullAuditingLog locked for 12 months with database-level update/delete restrictions. |
Aarkam Sovereign Data Fabric — https://aarkam.io
Aarkam Wiki • Enterprise Technical Documentation