Compliance architecture

Built for
compliance.

Compliance is not a checkbox. It is an architecture decision — and the architecture is that your raw telemetry never leaves the jurisdiction it was collected in.

Licensed

NACSA CSSP No. 20080-01

SOC monitoring service · ap-southeast-3

Eight frameworks. One platform.

PDPA 2010

Personal Data Protection Act 2010

Act 854 compliance is built into the Sidecar. PII is scrubbed at the data boundary before any event leaves your network, with a tamper-evident processing audit trail.

  • PII scrubbing at the edge, before transit
  • No raw personal data stored in the cloud
  • Consent and purpose tracking (Compliance Module, MVP2)
  • Tamper-evident processing audit trail
NACSA

NACSA Guidelines

Aligned to the national cybersecurity baseline and the Cyber Security Act 2024. SOC monitoring is delivered under a NACSA-licensed CSSP.

  • NACSA Licensed CSSP — SOC Monitoring Service
  • Licence No. 20080-01
  • National cybersecurity baseline alignment
  • Sovereign, in-jurisdiction operation
iSMS / JDN

Public-Sector ISMS Reference

Mapped to the JDN iSMS reference for public-sector information security management.

  • Public-sector ISMS control mapping
  • Per-control evidence library
  • Tamper-evident audit trail
  • Role-based access via Zitadel IAM
MAS TRM

Technology Risk Management

Aligned to the MAS Technology Risk Management guidelines for regulated financial institutions.

  • TRM control mapping
  • Audit-ready evidence reporting
  • Encryption in transit and at rest
  • Access governance and monitoring
CSA Act

Cybersecurity Act (CII)

Supports Critical Information Infrastructure obligations under the Singapore Cybersecurity Act.

  • CII monitoring and reporting
  • Incident audit trail
  • Data residency in your jurisdiction
  • Scheduled compliance reports
ISO 27001

ISO/IEC 27001:2022

Architected to ISO/IEC 27001:2022 controls — access control, cryptography, operations security, and audit logging built in, not bolted on.

  • Annex A control mapping available
  • Tamper-evident audit trail (A.12.4)
  • Role-based access via Zitadel IAM (A.9)
  • Encryption in transit and at rest (A.10)
GDPR

General Data Protection Regulation

Structurally compliant: raw data never leaves your jurisdiction in the first place. PII is scrubbed at the Sidecar boundary before any event transits.

  • Data minimisation at the edge (Article 5)
  • 90-day configurable retention TTL (Article 5)
  • Privacy by design (Article 25)
  • EU-jurisdiction deployment available (Article 44)
  • Data Processing Agreement available (Article 28)
NIST CSF

Cybersecurity Framework

The seven-component engine maps to the NIST CSF functions end to end: Identify, Protect, Detect, Respond, Recover.

  • Detect: autonomous multi-engine detection
  • Respond: Fabric response with audit trail
  • Identify: Sovereign Mesh asset topology
  • Recover: rollback-capable action history

Architecture guarantees.

OCSF v1.3

Open Cybersecurity Schema Framework

Every event is normalised to OCSF v1.3 before it enters the detection pipeline or reaches storage. An open standard means no proprietary lock-in: your security data stays portable and queryable by any OCSF-compliant tool.

mTLS

Mutual TLS on Every Connection

Both sides authenticate: the platform cannot be spoofed and the Sidecar cannot be impersonated. Certificates are verified on every connection, not just at handshake time, and rotate without platform downtime.

Zero Raw Log Transfer

Raw Logs Never Leave Your Network

Normalisation and PII scrubbing happen on-premise, inside the Sidecar. Only cleaned OCSF events transit — the raw log never crosses your network boundary at all.

WCAG 2.1 AA

Accessible by Design

The operator console is designed to WCAG 2.1 AA: contrast ratios, keyboard navigation, focus order, and reduced-motion support are design requirements reviewed before merge, not retrofitted afterwards.

Compliance by architecture

Data-protection compliance is not retrofitted here. PII is scrubbed at the Sidecar boundary before a single event transits, and raw logs never leave your network at all. That is a design requirement from day one, not a reporting feature bolted on afterwards.

Reclaim your security data.

60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.

Start Free TrialTalk to Sales →
Chat with us