Security, Compliance & Trust

Security, Compliance & Trust — Updated

At ARPIA Technologies, we take security, availability, and responsible AI governance seriously. Our infrastructure, processes, and team follow industry best practices to safeguard customer data, ensure business continuity, and operate AI systems with accountability and transparency.

We maintain a structured compliance and governance program designed to protect customer data, support responsible AI usage, and ensure operational resilience. What follows is both what has been independently audited and what we're actively building.


📜 Compliance Certifications & Attestations — What They Mean

A note on terminology: ISO/IEC 42001 is a certification of our management system. SOC 2 is not a certification — it is an attestation report issued by an independent CPA firm after examining our controls.

SOC 2® Type I — Design Validation (Report issued April 30, 2025)

What it covers: The design of ARPIA's controls relevant to the AICPA Trust Services Criteria for Security, as of April 8, 2025.

What it guarantees: Our control design was suitable as of that date. A Type I report does not test operational effectiveness over time — that is what the Type II report below does.


SOC 2® Type II — Operating Effectiveness (Report issued June 11, 2026)

What it covers: Operating effectiveness of ARPIA's SECURITY controls over a 12-month examination period (April 9, 2025 – March 31, 2026).

Auditor Opinion: Unqualified. The independent service auditor (A-LIGN ASSURANCE) concluded that:

  • The description of ARPIA's system was presented in accordance with AICPA Description Criteria
  • Security controls were suitably designed to provide reasonable assurance that ARPIA's service commitments and system requirements would be achieved
  • Security controls operated effectively throughout the examination period to provide reasonable assurance that service commitments and system requirements were achieved

Key Finding: No exceptions noted across all tested security control activities.

Important Caveats:

  • Scope is SECURITY only – not Availability, Processing Integrity, Confidentiality, or Privacy
  • Infrastructure dependencies – The examination assumes complementary controls are operating effectively at:
    • DigitalOcean (cloud infrastructure platform services)
    • TIGO (cloud hosting services)
    • These subservice organization controls were not independently tested as part of this examination
  • User entity controls – The examination assumes your organization (as a customer) will implement complementary controls for data access, usage policies, and incident response within your environment

Examination Period: April 9, 2025 to March 31, 2026 (12 months) – meaning security controls were operating effectively throughout this period.

Report Issued: June 11, 2026 (Final)


ISO/IEC 42001:2023 — AI Management System (Certified June 15, 2026)

Certificate: AIMS-AR-061526, issued by A-LIGN Compliance and Security, Inc. (ANAB-accredited). Valid until June 15, 2029, subject to annual surveillance audits.

What it means: ARPIA has a documented, structured Artificial Intelligence Management System that addresses:

  • AI risk assessment & treatment (lifecycle governance from conception to deprecation)
  • AI system impact assessment (consequences for individuals, groups, and societies)
  • Responsible development & deployment (controls built into design and testing)
  • Monitoring & human oversight (continuous performance evaluation, incident response)
  • Vendor & model provenance review (supply chain transparency)

Audit result: Zero major/minor nonconformities. One "Opportunity for Improvement" identified around supplier compliance registry formalization.

Important: ISO/IEC 42001 certifies ARPIA's management system, not individual products. It validates documented governance processes and their implementation, not perfect operational execution at all scales. It means we have the right frameworks in place and demonstrated conformance during audit. It does not guarantee that every AI decision made on ARPIA systems is free from bias, that every impact assessment is perfectly foreseen, or that governance keeps pace with customer use cases in real time.


🔐 What Our Security Posture Actually Covers

✅ Areas Tested in the SOC 2 Type II Examination (April 9, 2025 – March 31, 2026)

Control Environment

  • Code of conduct documented and communicated
  • Reference checks completed prior to employment
  • Organizational hierarchy and role definitions formalized
  • Compliance responsibilities assigned and monitored

Access Controls

  • User access provisioning and de-provisioning procedures operating effectively
  • Authentication and authorization mechanisms tested, including multi-factor authentication
  • Segregation of duties analysis performed, with compensating controls where needed
  • No exceptions noted in testing

Data Protection

  • Encryption of data in transit (TLS and VPN) and during replication between cloud environments
  • Encryption keys protected during generation, storage, use, and destruction
  • Backup and recovery procedures operating effectively (backups monitored, exceptions handled)
  • Data retention policies defined and enforced
  • No exceptions noted

Change Management

  • Change approval process documented and followed during the examination period
  • Emergency change procedures in place
  • Change implementation and testing controls verified
  • Configuration management procedures operating effectively

Vendor & Third-Party Risk Management

  • Third-party agreements documented with defined scope, roles, responsibilities
  • Compliance terms and service levels included in agreements
  • Third-party risk assessments performed annually
  • Exception handling procedures established and followed
  • Vendor onboarding and termination procedures documented
  • No exceptions noted

Incident Response & Logging

  • Incident procedures documented and communicated
  • Audit logging and monitoring controls in place
  • Incident detection and response procedures tested
  • No exceptions noted

⚠️ What We're Building (Active Strategic Priorities)

1. Expanded Trust Services Coverage (Currently: Security only; Target: Availability, Confidentiality in future examinations)

  • Next phase: Formalize controls for Availability and Confidentiality
  • Timeline: Under evaluation; to be confirmed
  • Why: Customers in regulated sectors (healthcare, finance) often require broader Trust Services coverage, not just Security

2. Supplier/Vendor Risk Registry Formalization (Currently: Annual review; Target: Continuous monitoring)

  • All third-party services/tools catalogued with risk scores
  • Compliance status tied to our AI governance requirements
  • Changes in supplier terms/security posture actively monitored
  • Dashboard visibility for management and customers
  • Why: DigitalOcean and TIGO are critical infrastructure dependencies. Formalizing oversight reduces blind spots.

3. Regulatory Compliance Mapping (Currently: ISO 42001 only; Target: Multi-framework)

  • ARPIA's governance mapped to GDPR, HIPAA, SOX, EU AI Act requirements
  • Customer segment → applicable regulations → control alignment
  • Gaps identified and addressed
  • Why: We operate across finance, healthcare, manufacturing, and government. Each sector has distinct requirements beyond SOC 2 and ISO 42001.

4. Residual Risk Transparency (Currently: Tracked internally; Target: Customer-visible)

  • High-level residual risks formally documented and named
  • Risk owners assigned with accountability
  • Escalation path to Board/executive leadership established
  • Why: Customers deserve to know what risks we've identified and accepted. This builds trust and sets expectations for shared responsibility.

5. Multi-Customer Governance Integration (Currently: Single organization AIMS; Target: Customer + ARPIA governance collaboration)

  • When a customer deploys ARPIA's AI system in their environment, governance responsibilities are divided
  • Documented model for how impact assessments are shared
  • Incident communication protocol between ARPIA and customer
  • Why: Our certification is at the platform level. Customer outcomes depend on how the customer uses the platform. We need formalized "governance handoff" procedures.

🤖 What Our AI Governance Actually Covers (& What It Doesn't Yet)

✅ What We've Implemented

AI System Lifecycle Governance:

  • Requirements specification and design review
  • Verification & validation before deployment
  • Continuous monitoring post-deployment
  • Documentation of development artifacts and decision logs

Risk Management:

  • Formal risk assessment (annual, plus ad-hoc for significant changes)
  • Risk classification (very high, high, medium, low, very low levels defined)
  • Risk treatment planning and monthly tracking
  • Residual risk acceptance by designated management

Impact Assessment:

  • Stakeholder analysis (affected groups identified)
  • Consequence evaluation (deployment, intended use, foreseeable misuse impacts)
  • Societal impact assessment (ethics, environmental, trustworthiness)
  • Mitigation measures documented (DPA, DLP, MFA, acceptable use boundaries)

Organizational Governance:

  • AI Governance Committee (monthly): CEO, Product Manager, Product AI Specialist, Senior Developer, Infrastructure Engineer, CISO
  • Management Review (monthly): Risk, compliance, and performance trending
  • Internal Audit (annual): Independent third-party review against ISO 42001 requirements and internal procedures
  • Competency & Training: Documented evidence of AI governance competency across team

Stakeholder Communication:

  • Internal policies available to all staff
  • External communication on AI governance available to customers and prospects
  • Incident reporting and escalation procedures documented

📊 Governance at a Glance

AspectStatusCoverageCadence
SOC 2 Type II (Security)✅ Report issued (unqualified)Design + Operating Effectiveness12-month examination period (complete)
SOC 2 (Availability)🔄 Under evaluationNot yet examinedTo be confirmed
SOC 2 (Confidentiality)🔄 Under evaluationNot yet examinedTo be confirmed
ISO 42001 AI Management System✅ CertifiedAIMS design, implementation, operationAnnual surveillance audits
AI Risk Assessment✅ FormalAnnual + ad-hoc for significant changesAnnual
AI Impact Assessment✅ FormalCustomer use cases sampledAs-needed
Risk Treatment Plan✅ Active11 risks identified (January 2026), all with treatment plansMonthly review
Internal Audit (AI Governance)✅ CompletedISO 42001 clauses and Annex A controlsAnnual
Management Review✅ MonthlyAI Governance Committee oversightMonthly
Supplier/Vendor Risk Registry🔄 In ProgressAnnual formal review; formalization underwayQuarterly (target: continuous)

🎯 What This Means for Customers

For Procurement Teams

What's been verified:

  • ✅ ARPIA's security controls were independently examined and operated effectively throughout the examination period
  • ✅ Infrastructure access, authentication, data protection, backup/recovery, vendor management, and incident response all tested with no exceptions
  • ✅ We have documented AI governance processes and passed an independent Stage 2 certification audit confirming their implementation
  • ✅ We have formal risk assessment, incident response, and management review procedures
  • ✅ We're willing to be audited against formal, rigorous standards

What still needs independent verification:

  • ⏳ Availability controls (not yet examined)
  • ⏳ Confidentiality controls (not yet examined)
  • ⏳ Your specific regulatory requirements (e.g., HIPAA for healthcare, GLBA for finance)

For Product Teams

What ARPIA commits to:

  • We provide governance frameworks and documentation to help you understand consequences of deploying our AI systems
  • We maintain monitoring and logging that supports your audit and compliance needs
  • We have formal processes for addressing concerns or changes to AI systems
  • We participate in a shared governance model where both ARPIA and your organization have defined responsibilities

What you must own:

  • Compliance with your specific regulations (we provide frameworks; you apply them to your context)
  • Use-case governance within your environment (we provide tools; you define policies)
  • End-user communication about how AI is being used (we document our platform; you communicate your deployment)

What These Certifications and Attestations Do NOT Guarantee

  • That every AI outcome is perfect, fair, or free from bias
  • That every possible real-world use case was foreseen in our impact assessment
  • That infrastructure services (DigitalOcean, TIGO) never have incidents (we monitor them and review their assurance information as part of our vendor management)
  • That governance keeps pace with your evolving product roadmap without your active participation
  • That controls in one customer environment don't create risks in another (segregation of duties and data isolation are controls we've tested, but you must verify them in your deployment)

🔄 Our Commitment to Evolving Governance

Our SOC 2 Type II attestation and ISO 42001 certification are foundations, not destinations. Regulatory landscapes are shifting (EU AI Act enforcement in 2026+, US sectoral rules emerging, international standards converging). Our governance system is designed to adapt.

What we commit to:

  • Regular reassessment of our security controls and AI governance against emerging regulatory frameworks
  • Transparency about gaps we identify and how we're addressing them (including this strategic priorities list)
  • Continuous improvement of supplier risk visibility and customer governance collaboration
  • Honest conversation with customers about shared responsibility for security and AI governance
  • Maintaining our ISO 42001 certification through annual surveillance audits, and demonstrating continued control effectiveness through periodic independent examinations

We're not claiming to have all the answers. We're claiming to have structured processes for asking the right questions, acting on what we learn, and being audited against rigorous third-party standards to demonstrate we're doing what we say.


📥 Questions? Let's Talk.

If you're a client, partner, or prospective customer and need to understand our compliance posture, audit results, or governance approach:

Email: [email protected]

Please include:

  • Your name and organization
  • What you're trying to understand (e.g., "Can you support HIPAA?" "What's your approach to residual risk?" "How do you handle supplier risk?")
  • Any specific frameworks or regulations you're evaluating against
  • Whether you need our SOC 2 Type II report, which is available to customers, partners, and qualified prospects under a non-disclosure agreement (NDA), consistent with the report's restricted-use terms
  • Timeline for review

Certification evidence: Our ISO/IEC 42001 certificate can be shared on request and verified with the certification body. Detailed ISO 42001 audit reports are confidential and are not distributed.

Typical response time: 1–2 business days

Note: We're building dedicated resources for regulated sectors (finance, healthcare, government). If you operate in one of these domains, let us know—we can walk through applicability and any sector-specific governance gaps.


Last updated: September 23, 2026
Next review: Q4 2026 (ISO 42001 annual update, SOC 2 renewal planning)

Audit milestones:

  • SOC 2 Type I (Security): Report issued April 30, 2025 — Design as of April 8, 2025
  • SOC 2 Type II (Security): Report issued June 11, 2026 — Operating effectiveness for April 9, 2025 – March 31, 2026
  • ISO/IEC 42001:2023: Certified June 15, 2026 — Certificate AIMS-AR-061526, valid until June 15, 2029

Did this page help you?