ARXIMUS COMPLIANCE & ASSURANCE
COMPLIANCE
Engineered for Regulated AI
Arximus is engineered for environments where machine authority,
infrastructure security, regulatory requirements and evidence
must remain under explicit control. Detailed compliance,
security and data-processing documentation is available for
customer, security and procurement review.
REGULATORY ENGINEERING
STANDARDS
EU DEPLOYMENT
DATA CONTROL
EVIDENCE
ASSURANCE
DOCUMENTATION
REGULATED AI INFRASTRUCTURE
Architecture built for regulatory compliance.
Arximus is engineered around the security, governance, resilience, evidence and data-control requirements surrounding consequential AI systems.
Regulatory compliance and standards conformity are stated individually below. Certification, independent assurance and testing status are presented separately under Assurance Documentation.
01
AI Governance
EU AI Act
COMPLIANCE STATUS
FULL COMPLIANCE
ISO/IEC 42001
CONFORMITY STATUS
FULL CONFORMITY
Arximus enforces explicit authority, deterministic decisioning, human approval paths, controlled policy change, runtime evidence and defined responsibility boundaries around consequential AI activity.
- Explicit authority
- Human approval
- Controlled change
- Runtime evidence
02
Information Security
NIS2
COMPLIANCE STATUS
FULL COMPLIANCE
ISO/IEC 27001
CONFORMITY STATUS
FULL CONFORMITY
SOC 2
CONTROL STATUS
FULL ALIGNMENT
Arximus applies security-domain separation, tenant isolation, least authority, privileged-access separation, signed runtime configuration, default-deny internal access and integrity-protected evidence so no single compromise gains authority over the entire system.
- Tenant isolation
- Least privilege
- Signed configuration
- Evidence integrity
03
Operational Resilience
DORA
COMPLIANCE STATUS
FULL COMPLIANCE
Arximus maintains explicit failure behavior, trusted known-good runtime policy, capacity controls, independent emergency authority, protected recovery and defined Enterprise service boundaries so security behavior remains controlled during operational failure.
- Failure control
- Known-good policy
- Emergency authority
- Recovery isolation
04
Data Protection
GDPR
COMPLIANCE STATUS
FULL COMPLIANCE
EHDS
COMPLIANCE STATUS
FULL COMPLIANCE
Arximus minimizes unnecessary data exposure through zero-retention AI content by default, separate security-evidence handling, explicit retention controls, controlled forensic capture and defined regional boundaries while preserving accountability.
- Data minimization
- Zero retention
- Controlled capture
- Defined retention
05
Digital Trust & Product Security
CRA
COMPLIANCE STATUS
FULL COMPLIANCE
eIDAS 2.0
COMPLIANCE STATUS
FULL COMPLIANCE
Arximus uses cryptographic identity, signed configuration, exact-operation binding, short-lived release authority, replay resistance and verifiable evidence to protect the integrity of consequential machine-driven operations.
- Cryptographic trust
- Exact binding
- Replay resistance
- Verifiable evidence
ASSURANCE DOCUMENTATION
Review the evidence behind the Arximus compliance posture.
Arximus provides security, privacy, data-processing,
regulatory and assurance documentation to prospective
customers, customers, partners and auditors.
Security-sensitive and proprietary material may require
appropriate confidentiality protections or a standard NDA.
Request documentation
↗
PRIVACY & DATA PROCESSING
Privacy & Data Processing
DPA
AVAILABLE ON REQUEST
Data Processing Agreement
Controller, processor and subprocessor terms
covering documented instructions, security,
subprocessors, transfers, data-subject assistance,
deletion and audit rights.
SUBPROCESSORS
AVAILABLE ON REQUEST
Subprocessor Register
Current subprocessors relevant to Customer
Personal Data, including their processing role
and information required for customer
data-protection review.
SECURITY CONTROLS
AVAILABLE ON REQUEST
Technical & Organizational Measures
Technical and organizational measures covering
access management, isolation, cryptographic
protection, integrity, secure development,
monitoring, resilience and incident response.
DATA LOCATION
AVAILABLE ON REQUEST
Data Residency & Transfer Information
Processing locations, residency boundaries,
international-transfer information and
deployment-specific processing details required
for customer legal and procurement review.
SECURITY
Security
SECURITY
UNDER NDA
Security Overview
Detailed security posture covering trust
boundaries, identity and access management,
infrastructure controls, cryptographic protection,
monitoring, vulnerability management and
operational security.
ARCHITECTURE
UNDER NDA
Architecture & Control Overview
Detailed security architecture, control inventory,
separation model, privileged-access boundaries,
data flows and technical control information used
during enterprise security review.
INCIDENT RESPONSE
UNDER NDA
Incident Response Summary
Customer-facing information covering security-event
identification, investigation, containment,
escalation, remediation, evidence preservation
and applicable customer notification.
RESILIENCE
UNDER NDA
Business Continuity & Recovery Summary
Customer-facing information covering continuity,
recovery, resilience, backup protection, service
restoration and response to significant service
or infrastructure disruption.
REGULATORY & ASSURANCE
Regulatory & Assurance
CONTROL MAPPING
AVAILABLE ON REQUEST
Regulatory & Standards Mapping
Detailed mappings covering the regulatory
requirements and standards identified by Arximus,
including the EU AI Act, NIS2, DORA, GDPR, EHDS,
CRA, eIDAS 2.0, ISO/IEC 27001 and ISO/IEC 42001.
SOC 2 ATTESTATION
NOT YET COMPLETED
SOC 2 Report
Applicable SOC 2 assurance documentation will be
made available when the relevant independent
attestation has been completed.
ISO 27001 / 42001
NOT YET CERTIFIED
ISO Certification Documentation
Applicable ISO/IEC 27001 and ISO/IEC 42001
certification documentation will be made
available when the relevant independent
certification has been completed.
INDEPENDENT SECURITY TESTING
Independent Security Testing
PENETRATION TESTING
WHEN COMPLETED
Independent Penetration Test Summary
Independent penetration-testing results and
remediation status will be made available to
customers and prospective customers under
appropriate confidentiality protections when
the applicable assessment has been completed.
SECURITY REPORTING
AVAILABLE ON REQUEST
Vulnerability Disclosure
Information for reporting suspected security
vulnerabilities, including the applicable
reporting process, handling expectations and
coordinated security-review procedures.
EUROPEAN DEPLOYMENT
Run the Arximus security path inside the European Union.
Arximus operates its European production infrastructure in Frankfurt, Germany, with deployment architecture built around explicit regional, data and operational boundaries.
01 / CUSTOMER
Customer AI Environment
Existing applications and systems
→
02 / EU PRODUCTION
Arximus Infrastructure
European production infrastructure
→
03 / AUTHORITY
Runtime Authorization
Deterministic policy decides
→
04 / RELEASE
Protected Release
Exact authorized operation
→
05 / EXECUTION
Customer Executor
Execution authority remains customer-side