Aarkam / Aarkam Wiki / Cyber Security / Comprehensive Cybersecurity Compliance Matrix
Compliance Matrix Cyber Security

Comprehensive Cybersecurity Compliance Matrix

Complete mapping across NCA ECC-2:2024, CCC-2:2024, DCC-1:2022, SDAIA PDPL, ISO 27001, SOC 2, and EU GDPR.

Last updated: Sep 23, 2026

This document provides the formal Compliance Matrix and Technical Architecture Mapping for the Aarkam platform across international standards, European Union regulations, and Saudi Arabian statutory mandates.


1. Compliance Scorecard Overview

Following an exhaustive 6-phase engineering roadmap, 100% of the platform’s security and sovereignty controls have been implemented natively in code:

┌─────────────────────────────────────────────────────────┐
│              Aarkam IO COMPLIANCE SCORECARD             │
├──────────────────────┬──────────────────────────────────┤
│  ✅ PHASE 1 DONE     │  8 items — All critical fixed    │
│  ✅ PHASE 2 DONE     │  5 items — High gaps fixed       │
│  ✅ PHASE 3 DONE     │  4 items — Medium gaps fixed     │
│  ✅ PHASE 4 DONE     │  6 items — Process & Doc gaps    │
│  ✅ PHASE 5 DONE     │  4 items — Zero-Trust Network    │
│  ✅ PHASE 6 DONE     │  2 items — PDPL & Erasure        │
├──────────────────────┼──────────────────────────────────┤
│  TECHNICAL MATURITY  │  ████████████████████ 100%       │
└──────────────────────┴──────────────────────────────────┘

2. Standards Cross-Reference

Framework Version Governing Authority Scope
NCA ECC ECC-2:2024 National Cybersecurity Authority (KSA) Critical infrastructure, government & enterprise
NCA CCC CCC-2:2024 National Cybersecurity Authority (KSA) Cloud service providers and sovereign tenants
NCA DCC DCC-1:2022 National Cybersecurity Authority (KSA) Data protection lifecycle and residency
SDAIA PDPL Royal Decree M/19 Saudi Data & AI Authority (SDAIA) Personal data processing & citizen privacy
ISO/IEC 27001 2022 Revision International Organization for Standardization Information security management systems
SOC 2 Type II Trust Services Criteria AICPA Security, availability, and confidentiality
EU GDPR Regulation (EU) 2016/679 European Parliament & Council Data protection, sovereignty, Right to Erasure

3. Exhaustive Control Implementation Matrix

Domain 1: Cryptography & Key Custody (ECC 2-8, DCC, ISO 27001 §8.24)

Requirement Status Technical Implementation in Aarkam
Data at Rest Encryption ✅ Compliant Transparent AES-256-GCM chunk encryption at storage node layer and EF Core EncryptionConverter at metadata layer.
Data in Transit Encryption ✅ Compliant Strict TLS 1.3 enforcement with RequireHttpsMetadata = true, HSTS headers, and ephemeral Diffie-Hellman keys.
Automated Key Rotation ✅ Compliant EncryptionKey domain entity enforces 90-day maximum lifespan via Rotate() and ShouldRotate().
Zero-Knowledge HSM ✅ Compliant Native PKCS#11 and KMIP integration for customer-owned HSMs. Keys never enter Aarkam software boundaries.
Timing Attack Defense ✅ Compliant Authentication hashes verified using CryptographicOperations.FixedTimeEquals to prevent side-channel timing leaks.

Domain 2: Identity & Access Management (ECC 2-2, SOC 2 CC6)

Requirement Status Technical Implementation in Aarkam
Multi-Factor Authentication ✅ Compliant Mandatory RFC 6238 TOTP via IMfaService for all administrative and tenant-privileged logins.
Password Hygiene (NIST) ✅ Compliant Minimum 12 characters, complexity rules, and 120-day password history validator (PasswordHistoryValidator).
Account Lockout Policy ✅ Compliant Automatic 15-minute account lockout after 5 consecutive failed authentication attempts.
Session Concurrency ✅ Compliant LoginByUserNameOrEmailHandler restricts accounts to 3 concurrent sessions, pruning the oldest upon violation.
Instant Token Revocation ✅ Compliant Password modifications trigger immediate revocation of all active JWT refresh tokens.

Domain 3: Network & Zero Egress (CCC 2-1, DCC, GDPR Art 44-50)

Requirement Status Technical Implementation in Aarkam
Zero Cross-Border Egress ✅ Compliant Data chunks pinned strictly to certified sovereign datacenters with boundary IP filtering.
mTLS Internal Service Mesh ✅ Compliant All inter-node gRPC channels enforce mutual X.509 certificate authentication over TLS 1.3.
Dual-Plane Segmentation ✅ Compliant Complete physical network segregation between Public/DMZ client edge and internal storage backplanes.

Domain 4: Data Governance & Privacy (SDAIA PDPL, EU GDPR Art 17)

Requirement Status Technical Implementation in Aarkam
Right to Erasure ✅ Compliant Cryptographic partition shredding destroys per-object DEKs, rendering purged data mathematically unrecoverable.
WORM Audit Trails ✅ Compliant Append-only FullAuditingLog locked for 12 months with database-level update/delete restrictions.