Compliance & Attestation¶
CyberArmor maps enforceable controls to established regulatory frameworks and preserves tenant-scoped assessment evidence in PostgreSQL — evidence bound to the control decision that produced it, not gathered after the fact.
Framework policy packs¶
The compliance engine ships 17 framework policy packs:
| Category | Frameworks |
|---|---|
| AI governance | ISO/IEC 42001, NIST AI RMF |
| Financial regulators | SEC Cyber, FINRA Cyber, NYDFS 500 |
| Security & privacy | SOC 2, ISO 27001, PCI DSS, HIPAA Security Rule, GDPR, CCPA |
| Government / controls | NIST CSF, NIST 800-53, CMMC L3, CIS Controls, CSA CCM |
| Application security | OWASP |
An eighteenth framework, SANS/CWE Top 25, ships its controls and assessment but deliberately has no policy pack. Its controls are secure-coding practices in the customer's own SDLC — memory safety, SAST configuration, parameterised queries — which this product cannot observe in AI traffic. It is satisfied by uploaded attestation documents rather than by an enforced policy, and is counted separately for that reason.
Each pack provides enforceable control templates that map compliance requirements to runtime policy — controls that become executable decisions, not documents.
Evidence & assessments¶
Evidence and assessment reports are DB-backed and tenant-scoped:
- per-request evidence submission and retrieval
- per-framework assessment reports, scored and stored
- evidence tied to the enforcement decision (actor, request, policy, response)
| Endpoint | Purpose |
|---|---|
GET /frameworks |
list available frameworks |
GET /frameworks/{id}/policy-pack |
control templates for a framework |
GET /frameworks/{id}/controls |
controls with evidence keys |
| submit / get evidence per request | attach and retrieve request-scoped evidence |
Out-of-band verification for payment instructions¶
A payment instruction above a threshold the firm sets is held until somebody
phones the counterparty back on a number from the firm's own directory of
record, and two named people who are not the initiator confirm it. Completing
that callback satisfies FINRA-FRAUD-1 on platform-observed evidence.
The directory is the control¶
A deepfake-enabled wire-fraud call works by supplying a plausible callback number alongside the instruction. Verifying against a number the requester gave you verifies nothing.
There is no code path anywhere in the product that turns a caller-supplied number into a callback target. A counterparty absent from the directory produces a held payment and an explicit refusal to place the call — which is a different operational state from a payment awaiting one, and is reported as such. Changing a number of record is restricted to a tenant administrator and attributed.
Lifecycle¶
required → pending → attested | refused | expired
An abandoned attestation recomputes to expired from the clock rather than
waiting for a sweep. The compliance evidence key is set only by a completed,
re-verified attestation — a tenant that asserts this control passed is
overridden by the platform's own reading of its records, per the provenance
ranking above.
| Endpoint | Purpose |
|---|---|
POST /payments/events |
observe a payment instruction; returns whether it is held |
GET /attestations |
the approver queue for a tenant |
GET /attestations/{id} |
one attestation and its state |
POST /attestations/{id}/callback/begin |
record that a callback was placed |
POST /attestations/{id}/callback/complete |
record its outcome |
GET /attestations/directory/{tenant_id} |
the directory of record |
PUT /attestations/directory/{tenant_id} |
amend it (tenant administrator only) |
GET /payments/{external_ref}/resolution |
release / hold / cancel / unknown_to_us |
Approvers are emailed when a payment is held, and the queue records whether that notification actually went out — a notification that silently failed must not read as one that was delivered. Every state change is written to the signed audit chain.
CyberArmor holds no funds
Recording an outcome produces the evidence. Releasing or cancelling the payment happens in the system that holds it; the resolution endpoint exists so that system can poll for the answer. Nothing here moves money.
This control requires no media analysis and works whether or not the voice on the call was synthetic. See Media Authenticity for what can and cannot be established about a file.
Validation checklist¶
GET /frameworksreturns all 18 registered frameworks (17 of them with policy packs) includingiso42001,sec-cyber, andfinra-cyberGET /frameworks/iso42001/policy-packreturns enforceable control templates- submitted evidence for a request is retrievable and persists across a service restart
- a payment above the tenant's threshold returns held, and one below it does not
- a counterparty absent from the directory returns held with an explicit refusal to place a call, not held-awaiting-callback
FINRA-FRAUD-1reportsplatform_observedafter a completed callback, and is not satisfied by a tenant asserting it
See also Evidence Export.