Skip to content

Compliance & Attestation

CyberArmor maps enforceable controls to established regulatory frameworks and preserves tenant-scoped assessment evidence in PostgreSQL — evidence bound to the control decision that produced it, not gathered after the fact.

Framework policy packs

The compliance engine ships 17 framework policy packs:

Category Frameworks
AI governance ISO/IEC 42001, NIST AI RMF
Financial regulators SEC Cyber, FINRA Cyber, NYDFS 500
Security & privacy SOC 2, ISO 27001, PCI DSS, HIPAA Security Rule, GDPR, CCPA
Government / controls NIST CSF, NIST 800-53, CMMC L3, CIS Controls, CSA CCM
Application security OWASP

An eighteenth framework, SANS/CWE Top 25, ships its controls and assessment but deliberately has no policy pack. Its controls are secure-coding practices in the customer's own SDLC — memory safety, SAST configuration, parameterised queries — which this product cannot observe in AI traffic. It is satisfied by uploaded attestation documents rather than by an enforced policy, and is counted separately for that reason.

Each pack provides enforceable control templates that map compliance requirements to runtime policy — controls that become executable decisions, not documents.

Evidence & assessments

Evidence and assessment reports are DB-backed and tenant-scoped:

  • per-request evidence submission and retrieval
  • per-framework assessment reports, scored and stored
  • evidence tied to the enforcement decision (actor, request, policy, response)
Endpoint Purpose
GET /frameworks list available frameworks
GET /frameworks/{id}/policy-pack control templates for a framework
GET /frameworks/{id}/controls controls with evidence keys
submit / get evidence per request attach and retrieve request-scoped evidence

Out-of-band verification for payment instructions

A payment instruction above a threshold the firm sets is held until somebody phones the counterparty back on a number from the firm's own directory of record, and two named people who are not the initiator confirm it. Completing that callback satisfies FINRA-FRAUD-1 on platform-observed evidence.

The directory is the control

A deepfake-enabled wire-fraud call works by supplying a plausible callback number alongside the instruction. Verifying against a number the requester gave you verifies nothing.

There is no code path anywhere in the product that turns a caller-supplied number into a callback target. A counterparty absent from the directory produces a held payment and an explicit refusal to place the call — which is a different operational state from a payment awaiting one, and is reported as such. Changing a number of record is restricted to a tenant administrator and attributed.

Lifecycle

required → pending → attested | refused | expired

An abandoned attestation recomputes to expired from the clock rather than waiting for a sweep. The compliance evidence key is set only by a completed, re-verified attestation — a tenant that asserts this control passed is overridden by the platform's own reading of its records, per the provenance ranking above.

Endpoint Purpose
POST /payments/events observe a payment instruction; returns whether it is held
GET /attestations the approver queue for a tenant
GET /attestations/{id} one attestation and its state
POST /attestations/{id}/callback/begin record that a callback was placed
POST /attestations/{id}/callback/complete record its outcome
GET /attestations/directory/{tenant_id} the directory of record
PUT /attestations/directory/{tenant_id} amend it (tenant administrator only)
GET /payments/{external_ref}/resolution release / hold / cancel / unknown_to_us

Approvers are emailed when a payment is held, and the queue records whether that notification actually went out — a notification that silently failed must not read as one that was delivered. Every state change is written to the signed audit chain.

CyberArmor holds no funds

Recording an outcome produces the evidence. Releasing or cancelling the payment happens in the system that holds it; the resolution endpoint exists so that system can poll for the answer. Nothing here moves money.

This control requires no media analysis and works whether or not the voice on the call was synthetic. See Media Authenticity for what can and cannot be established about a file.

Validation checklist

  • GET /frameworks returns all 18 registered frameworks (17 of them with policy packs) including iso42001, sec-cyber, and finra-cyber
  • GET /frameworks/iso42001/policy-pack returns enforceable control templates
  • submitted evidence for a request is retrievable and persists across a service restart
  • a payment above the tenant's threshold returns held, and one below it does not
  • a counterparty absent from the directory returns held with an explicit refusal to place a call, not held-awaiting-callback
  • FINRA-FRAUD-1 reports platform_observed after a completed callback, and is not satisfied by a tenant asserting it

See also Evidence Export.