ARXIMUS COMPLIANCE & ASSURANCE

COMPLIANCE
Engineered for Regulated AI

Arximus is engineered for environments where machine authority, infrastructure security, regulatory requirements and evidence must remain under explicit control. Detailed compliance, security and data-processing documentation is available for customer, security and procurement review.

REGULATORY ENGINEERING STANDARDS EU DEPLOYMENT DATA CONTROL EVIDENCE ASSURANCE DOCUMENTATION
REGULATED AI INFRASTRUCTURE

Architecture built for regulatory compliance.

Arximus is engineered around the security, governance, resilience, evidence and data-control requirements surrounding consequential AI systems.

Regulatory compliance and standards conformity are stated individually below. Certification, independent assurance and testing status are presented separately under Assurance Documentation.

01

AI Governance

EU AI Act
COMPLIANCE STATUS FULL COMPLIANCE
ISO/IEC 42001
CONFORMITY STATUS FULL CONFORMITY

Arximus enforces explicit authority, deterministic decisioning, human approval paths, controlled policy change, runtime evidence and defined responsibility boundaries around consequential AI activity.

  • Explicit authority
  • Human approval
  • Controlled change
  • Runtime evidence
02

Information Security

NIS2
COMPLIANCE STATUS FULL COMPLIANCE
ISO/IEC 27001
CONFORMITY STATUS FULL CONFORMITY
SOC 2
CONTROL STATUS FULL ALIGNMENT

Arximus applies security-domain separation, tenant isolation, least authority, privileged-access separation, signed runtime configuration, default-deny internal access and integrity-protected evidence so no single compromise gains authority over the entire system.

  • Tenant isolation
  • Least privilege
  • Signed configuration
  • Evidence integrity
03

Operational Resilience

DORA
COMPLIANCE STATUS FULL COMPLIANCE

Arximus maintains explicit failure behavior, trusted known-good runtime policy, capacity controls, independent emergency authority, protected recovery and defined Enterprise service boundaries so security behavior remains controlled during operational failure.

  • Failure control
  • Known-good policy
  • Emergency authority
  • Recovery isolation
04

Data Protection

GDPR
COMPLIANCE STATUS FULL COMPLIANCE
EHDS
COMPLIANCE STATUS FULL COMPLIANCE

Arximus minimizes unnecessary data exposure through zero-retention AI content by default, separate security-evidence handling, explicit retention controls, controlled forensic capture and defined regional boundaries while preserving accountability.

  • Data minimization
  • Zero retention
  • Controlled capture
  • Defined retention
05

Digital Trust & Product Security

CRA
COMPLIANCE STATUS FULL COMPLIANCE
eIDAS 2.0
COMPLIANCE STATUS FULL COMPLIANCE

Arximus uses cryptographic identity, signed configuration, exact-operation binding, short-lived release authority, replay resistance and verifiable evidence to protect the integrity of consequential machine-driven operations.

  • Cryptographic trust
  • Exact binding
  • Replay resistance
  • Verifiable evidence
ASSURANCE DOCUMENTATION

Review the evidence behind the Arximus compliance posture.

Arximus provides security, privacy, data-processing, regulatory and assurance documentation to prospective customers, customers, partners and auditors. Security-sensitive and proprietary material may require appropriate confidentiality protections or a standard NDA.

Request documentation
PRIVACY & DATA PROCESSING

Privacy & Data Processing

DPA AVAILABLE ON REQUEST

Data Processing Agreement

Controller, processor and subprocessor terms covering documented instructions, security, subprocessors, transfers, data-subject assistance, deletion and audit rights.

SUBPROCESSORS AVAILABLE ON REQUEST

Subprocessor Register

Current subprocessors relevant to Customer Personal Data, including their processing role and information required for customer data-protection review.

SECURITY CONTROLS AVAILABLE ON REQUEST

Technical & Organizational Measures

Technical and organizational measures covering access management, isolation, cryptographic protection, integrity, secure development, monitoring, resilience and incident response.

DATA LOCATION AVAILABLE ON REQUEST

Data Residency & Transfer Information

Processing locations, residency boundaries, international-transfer information and deployment-specific processing details required for customer legal and procurement review.

SECURITY

Security

SECURITY UNDER NDA

Security Overview

Detailed security posture covering trust boundaries, identity and access management, infrastructure controls, cryptographic protection, monitoring, vulnerability management and operational security.

ARCHITECTURE UNDER NDA

Architecture & Control Overview

Detailed security architecture, control inventory, separation model, privileged-access boundaries, data flows and technical control information used during enterprise security review.

INCIDENT RESPONSE UNDER NDA

Incident Response Summary

Customer-facing information covering security-event identification, investigation, containment, escalation, remediation, evidence preservation and applicable customer notification.

RESILIENCE UNDER NDA

Business Continuity & Recovery Summary

Customer-facing information covering continuity, recovery, resilience, backup protection, service restoration and response to significant service or infrastructure disruption.

REGULATORY & ASSURANCE

Regulatory & Assurance

CONTROL MAPPING AVAILABLE ON REQUEST

Regulatory & Standards Mapping

Detailed mappings covering the regulatory requirements and standards identified by Arximus, including the EU AI Act, NIS2, DORA, GDPR, EHDS, CRA, eIDAS 2.0, ISO/IEC 27001 and ISO/IEC 42001.

SOC 2 ATTESTATION NOT YET COMPLETED

SOC 2 Report

Applicable SOC 2 assurance documentation will be made available when the relevant independent attestation has been completed.

ISO 27001 / 42001 NOT YET CERTIFIED

ISO Certification Documentation

Applicable ISO/IEC 27001 and ISO/IEC 42001 certification documentation will be made available when the relevant independent certification has been completed.

INDEPENDENT SECURITY TESTING

Independent Security Testing

PENETRATION TESTING WHEN COMPLETED

Independent Penetration Test Summary

Independent penetration-testing results and remediation status will be made available to customers and prospective customers under appropriate confidentiality protections when the applicable assessment has been completed.

SECURITY REPORTING AVAILABLE ON REQUEST

Vulnerability Disclosure

Information for reporting suspected security vulnerabilities, including the applicable reporting process, handling expectations and coordinated security-review procedures.

EUROPEAN DEPLOYMENT

Run the Arximus security path inside the European Union.

Arximus operates its European production infrastructure in Frankfurt, Germany, with deployment architecture built around explicit regional, data and operational boundaries.

01 / CUSTOMER Customer AI Environment Existing applications and systems
CONTROL Customer controlled
BOUNDARY Remains outside Arximus infrastructure
02 / EU PRODUCTION Arximus Infrastructure European production infrastructure
COMPANY Sweden
INFRASTRUCTURE Frankfurt, Germany
03 / AUTHORITY Runtime Authorization Deterministic policy decides
INPUT Identity / authority / context
DECISION Deterministic policy
04 / RELEASE Protected Release Exact authorized operation
BINDING Operation / parameters / destination
RELEASE Only the authorized operation
05 / EXECUTION Customer Executor Execution authority remains customer-side
CONTROL Customer controlled
EXECUTION Performed outside Arximus
COMPLIANCE & ASSURANCE

Build regulated AI on explicit trust boundaries.

Arximus combines regulatory compliance, standards conformity, European production infrastructure, controlled machine authority and verifiable evidence into one security layer.

ARXIMUS ASSURANCE MODEL
Explicit boundaries. Verifiable controls.
  • Full compliance with the EU regulatory requirements listed on this page.
  • Full conformity with ISO/IEC 27001 and ISO/IEC 42001.
  • Full SOC 2 control alignment.
  • Certification, independent assurance and testing statuses are stated separately under Assurance Documentation.
  • European production infrastructure in Frankfurt, Germany.
  • Ordinary AI content is not retained by default.
  • Deterministic policy authorizes, Arximus releases and customer-controlled systems execute.
  • Authorization, release and reported execution remain distinct evidence events.