Skip to main content
Control

Prove every decision. Pass every audit.

Log every AI request with Immutable, tamper-proof audit trails, activate compliance Policy Packs for 12 regulatory frameworks, and stream events to your SIEM — automatically.

Capabilities

Tamper-Evident Audit Logs

Immutable, tamper-proof logs record every request, every policy decision, and every enforcement action. Each entry is cryptographically linked to the previous one — tampering with any record breaks the chain and is detectable immediately. Signed audit exports provide verifiable evidence for external auditors and regulators.

12 Compliance Frameworks

12 regulatory frameworks including PCI-DSS, HIPAA, GDPR, GLBA, SOX, CCPA, BSA/AML, SEC Reg FD, FERPA, EU AI Act, NIST AI RMF, ISO/IEC 42001 — each mapped to detection rules and enforcement actions in the Arbitex Gateway. Activate a framework and governance follows automatically. Compliance bundles connect DLP inspection to the specific data types and retention requirements each regulation demands.

Compliance Pack Default Rules

Compliance packs ship with recommended default rules for PCI-DSS, HIPAA, and GDPR. Organization admins manage activation and configuration to match their regulatory requirements. Each pack bundles detection patterns, enforcement actions, and retention settings into a single policy object — activate a framework and governance follows automatically.

Centralized DLP Rule Distribution

Distribute DLP rules across environments from a central policy console. Manage detection logic once and push it everywhere — no per-environment configuration drift, no version mismatches. Policy updates propagate across all connected environments without redeployment.

OpenTelemetry Observability

OpenTelemetry instrumentation exports traces and metrics to any OTLP-compatible backend. Pre-built Grafana dashboard definitions and Prometheus alert rules cover system health, DLP trigger rates, compliance status, and cost by provider. Deploy to your existing observability stack — no new infrastructure required.

SIEM Direct Sink — 7 Connectors

Forward audit events directly to your SIEM. Seven connectors: Splunk HEC (OCSF sourcetype), Microsoft Sentinel via DCR ingestion API, Elasticsearch Bulk API, Datadog, Sumo Logic, generic webhook, and JSON Lines for file-based ingestion. Events are batched for efficiency and retried on delivery failure. Configuration lives in the policy bundle — no per-node environment changes.

How it works

01

Activate compliance frameworks

Select which regulatory standards apply to your organization. Arbitex Gateway maps each framework to the corresponding DLP detection rules, enforcement actions, and retention policies. Audit anomaly detection activates automatically to flag unusual patterns.

02

Log and retain

Every request is logged with full context: actor identity, timestamp, source IP, policy evaluated, action taken, and content hash. Configure retention at 30 days, 90 days, or 1 year and beyond based on your regulatory requirements. Logs are immutable and cannot be deleted or modified by any user, including admin accounts. Every administrative action is logged separately with before-and-after change deltas.

03

Report and export

Export gateway activity as SOC 2 audit evidence — structured, signed log packages covering the controls in scope for your audit preparation. Audit logs are not a completed SOC 2 report; they are the evidence base your auditors will review. Anomaly detection alerts flag unusual access patterns, volume spikes, and policy override frequency so compliance teams respond before auditors ask.

Policy Packs

Activate compliance in one step

Policy Packs bundle the detection rules, enforcement actions, and retention settings for each regulatory framework into a single configuration object. Turn them on — Arbitex Gateway handles the mapping.

PCI-DSS

Card data, CVV, track data — recommended default rules, admin-configurable.

HIPAA

PHI, diagnosis codes, patient identifiers — recommended default rules, admin-configurable.

GDPR

EU personal data, special categories, consent-dependent processing.

GLBA

Customer financial records and non-public personal information.

SOX

Financial reporting data, audit evidence, and access controls.

BSA/AML

Transaction monitoring, SAR-relevant patterns, and beneficial ownership data.

CCPA

California resident data, opt-out signals, and sale-of-data restrictions.

SEC Reg FD

Immutable records, WORM-compliant retention, and broker-dealer communications.

SIEM Integration

Stream audit events to your security stack

Every policy decision, enforcement action, and anomaly alert flows directly into your existing SIEM — no log forwarders, no custom ETL.

Splunk HEC
Microsoft Sentinel
Elastic SIEM
Datadog
Sumo Logic
Webhook
JSON Lines

All connectors use native APIs — HEC, Data Collection Rules, Bulk API, HTTP Sources, and structured JSON output. IBM QRadar support in development.

Related Resources

DLP Protection

Inspect every AI prompt for sensitive data

Audit Log

Tamper-proof activity trail

Healthcare

HIPAA compliance and PHI detection

Financial Services

PCI-DSS and SOX compliance

Government

FedRAMP and FISMA compliance

Read the compliance mapping guide

Audit-ready from day one.