Arkhivio provides operational security controls and audit capabilities. Many storage-level security features — encryption at rest, immutability, lifecycle controls — are provided by the underlying S3-compatible storage platform under a shared responsibility model.
Arkhivio is deliberately designed to delegate storage-level protection to the underlying S3-compatible platform. This is consistent with the anti-lock-in architecture — not a gap.
Arkhivio does not hold and does not claim SOC 2, ISO 27001, HIPAA, GDPR, LGPD, PCI DSS, or any other compliance certification. The compliance reports on this page are technical assessments of how Arkhivio's capabilities map to specific regulatory requirements — not legal certifications. Using Arkhivio does not automatically make your environment compliant with any regulation. Compliance determinations must be validated by qualified legal and compliance specialists.
Arkhivio is designed to support organizations operating in regulated environments by providing: data integrity verification, structured audit logs, access control, credential security, and a resilient recovery path that does not depend on the backup application being available.
Many regulatory requirements — particularly around encryption at rest, immutability, and data retention — can be addressed at the storage layer using the capabilities of the S3-compatible platform and bucket configuration. Arkhivio's architecture is designed to make use of those capabilities rather than replicate them proprietary.
Organizational policies, staff training, risk assessments, DPIAs, and legal contracts remain the responsibility of the operating organization and are outside the scope of any technical product.
Each report assesses Arkhivio's technical and architectural controls against a specific regulatory framework — including what is satisfied by design, what requires operational configuration, and what requires external or legal action.