KINGDOM OF SAUDI ARABIA REGULATORY MANDATES

Sovereign Trust, NCA & SDAIA Compliance, & Zero Compromise

Engineered from first principles to strictly satisfy the regulatory standards of the National Cybersecurity Authority (NCA) and the Saudi Data and AI Authority (SDAIA).

NCA

National Cybersecurity Authority Alignment

ECC-1:2018 · CSCC-1:2019 · CCC-1:2020
ECC §2-3: CRYPTOGRAPHIC DEFENSE

Envelope Encryption at Edge

AES-256-GCM encryption executes client-side before any chunk leaves the gateway perimeter. Physical storage hosts only ever persist ciphertext blocks.

CCC §1-2: CLOUD ISOLATION

Air-Gapped Sovereign Mode

Operates completely severed from external public networks. Zero cloud-vendor dependencies, telemetry backdoors, or international DNS/NTP lookups.

ECC §2-8: CYBER AUDITING

Tamper-Proof WORM Logging

Immutable append-only audit records for every bucket access, chunk commit, and policy modification with automated Syslog/SIEM forwarding.

SDAIA

Saudi Data & AI Authority (PDPL)

Personal Data Protection Law Compliance
ARTICLE 29: DATA RESIDENCY

Strict National Boundary Pinning

Primary data and Cauchy parity blocks are physically restricted to certified Saudi datacenter nodes. Prohibits cross-border egress or overseas mirroring.

ARTICLE 4: RIGHT TO ERASURE

Cryptographic Partition Shredding

Per-object Data Encryption Key (DEK) destruction ensures deleted records are mathematically scrambled and unrecoverable across all Cauchy stripes.

ARTICLE 19: CONFIDENTIALITY

Customer HSM Key Custody

Master keys are held exclusively within customer-managed Hardware Security Modules (PKCS#11 / KMIP). Neither Aarkam engineers nor external operators have plaintext access.

HSM

Cryptographic Custody & Air-Gapped Architecture

FIPS 140-3 Hardware Key Isolation & National Autonomy

Aarkam provides enterprise and government sector operators with complete cryptographic isolation. Data encryption keys (DEKs) are generated client-side and encrypted with key-encryption keys (KEKs) hosted strictly within customer-owned Hardware Security Modules.

Native support for S3 Object Lock in Compliance Mode enforces non-erasable, non-overwritable WORM (Write Once, Read Many) policies required for legal audit archives, financial recordkeeping, and national registries.