# ARADIA - Standards & Compliance Matrix

Effective Date: June 1, 2026  
Last Updated: August 18, 2026  
Specification Version: 2.4.0  

---

# ARCHITECTURAL COMPLIANCE THESIS

Traditional SaaS AI systems create compounding regulatory liabilities by routing sensitive corporate intellectual property, medical records, and legal work product across multi-tenant cloud APIs. Aradia eliminates cloud supply-chain exposure by deploying **dedicated, air-gapped AI Agentic Systems on NVIDIA DGX appliances** directly onto the client's private physical network.

Our compliance framework operates across four defense tiers: from web accessibility and cryptographic protocol standards, to operating system hardening, hardware-rooted encryption, and statutory industry sector frameworks.

---

# TIER 01 // WEB & DATA INGESTION PERIMETER

Universal accessibility, payment boundary isolation, and open protocol governance across all public and machine-to-machine interfaces.

## ADA Title III & W3C WCAG 2.2 Level AA Compliance [= 100% Conformance]
Aradia digital web surfaces adhere strictly to **W3C Web Content Accessibility Guidelines (WCAG) 2.2 Level AA** standards and the Americans with Disabilities Act (ADA) Title III requirements:
+ **High Contrast Ratios:** Text typography maintains a contrast ratio exceeding 7:1 against pure white and zinc backgrounds (exceeding the 4.5:1 AA minimum).
+ **Keyboard Navigability:** 100% of interactive elements, forms, and dialogs are fully navigable via standard Tab/Shift-Tab keybindings with high-visibility focus rings.
+ **Semantic DOM & ARIA 1.2:** Native HTML5 landmark regions (`<header>`, `<main>`, `<footer>`, `<nav>`) paired with explicit ARIA attributes for screen reader engines (NVDA, JAWS, VoiceOver).
+ **Motion & Visual Safety:** Zero content flashes more than three times per second. Respects `prefers-reduced-motion` operating system flags.
+ **Dual-Stream Plain-Text Twins:** Every public route publishes an unstyled, pure-text Markdown twin (`.md`) for direct, frictionless screen magnification and Braille terminal ingestion.
+ **Target Sizes:** Interactive touch targets exceed the WCAG 2.2 Success Criterion 2.5.8 minimum dimension of 24x24 CSS pixels.

## PCI-DSS v4.0 — Out-of-Scope via Complete Perimeter Isolation [= SAQ A / Zero Cardholder Exposure]
Aradia enforces strict architectural segmentation ensuring that **zero Primary Account Numbers (PAN), Cardholder Data (CHD), or Sensitive Authentication Data (SAD)** ever enters, transits, or resides on Aradia servers, local appliances, or web environments:
+ **Fiat & Wire Isolation (Stripe):** All fiat credit card, ACH, and institutional wire checkouts are handled exclusively via direct client-browser sessions securely hosted by **Stripe (PCI Level 1 Service Provider)**. Card details are tokenized directly within Stripe's infrastructure, rendering Aradia fully eligible for PCI-DSS Self-Assessment Questionnaire A (SAQ A).
+ **Cryptographic Settlement Isolation:** Digital asset and cryptocurrency settlements (Bitcoin on-chain, Lightning Network, and stablecoins) are executed via a dedicated, self-hosted, non-custodial sovereign gateway. Crypto payments operate on independent cryptographic verification rails with zero exposure to payment card infrastructure.

## Open Protocol & RFC Standards Governance
Aradia’s public infrastructure enforces strict compliance across **15+ formal IETF, W3C, and AI-Agent specifications**, guaranteeing deterministic machine discovery, cryptographic attestation, and zero-leakage data transit:
+ **Machine Discovery & Capability Catalogs:** Full adherence to **IETF RFC 9727** (API Catalog Linksets), **RFC 8414** (OAuth 2.0 Authorization Server Metadata), and **RFC 9728** (Protected Resource Metadata) for deterministic, machine-readable service discovery and permission scoping.
+ **Cryptographic Attestation & Transport Security:** End-to-end request verification enforcing **IETF RFC 9421/9422** (HTTP Message Signatures with asymmetric Ed25519 verification), **RFC 8461** (MTA-STS Strict Mail Transport), and **RFC 9460** (DNSSEC-signed HTTPS service bindings).
+ **Autonomous Agent & MCP Interoperability:** Compliance with **SEP-1649** (Model Context Protocol Server Card Standard), **Agent Skills Discovery RFC (v0.2.0)** with cryptographic SHA-256 digests, and emerging **W3C / Chrome WebMCP** browser context interfaces.
+ **Machine Payments & Context Integrity:** Implementation of open machine commerce rails (**Stripe MPP**, **x402 Protocol**, **Universal Commerce Protocol**, **Agentic Commerce Protocol**), structured **llmstxt.org** RAG indexing, and Cloudflare **Content-Signal** model training barriers (`search=yes, ai-input=yes, ai-train=no`).

---

# TIER 02 // SOVEREIGN SOFTWARE & AI RUNTIME

Artificial intelligence management systems, model risk governance, and kernel-level container sandboxing.

## ISO/IEC 42001:2023 (Artificial Intelligence Management System)
+ **Deterministic Lineage:** Every model weight deployed has an immutable SHA-256 cryptographic provenance.
+ **No Uncontrolled Training:** Runtimes operate strictly in inference mode. Zero customer data is fed back into baseline models.
+ **Model Transparency:** Full disclosure of quantization algorithms (example: AWQ / AutoRound) and parameter boundaries.

## NIST AI Risk Management Framework (NIST AI RMF 1.0)
+ **Govern:** Role-based access controls and memory retention policies.
+ **Map:** Context-aware task bounding preventing unauthorized tool invocation.
+ **Measure:** Automated perplexity benchmarking and continuous batch latency tracking.
+ **Manage:** Local sandbox containment neutralizing prompt-injection and memory corruption attacks.

## CIS Linux Benchmark (Level 1 & Level 2) Hardening
+ **Zero Inbound Ports:** Outbound-only connectivity; zero listening network daemons.
+ **Kernel Hardening:** Enforced `kptr_restrict=2`, `dmesg_restrict=1`, and disabled unprivileged BPF.
+ **AppArmor & Namespaces:** Containerized vLLM engine runs isolated with read-only root filesystems.

---

# TIER 03 // PHYSICAL HARDWARE & ENCRYPTION AT REST

Silicon-rooted cryptography, full-disk NVMe encryption, electrical safety certifications, and regulatory emissions standards.

## Cryptographic Hardware Root of Trust [= TPM 2.0 / FIPS 140-3]
- ./ TPM 2.0 (Trusted Platform Module): All DGX appliances utilize a dedicated cryptographic microcontroller to enforce Measured Boot, verify BIOS/UEFI integrity via cryptographic hashes, and securely store platform configuration registers (PCRs).
- ./ FIPS 140-3 Level 1/2 Cryptography: Storage subsystems enforce full-disk encryption at rest using AES-256-GCM / XTS-AES-256 (LUKS2). Master cryptographic keys are derived using memory-hard Argon2id and sealed directly into the hardware TPM, preventing data recovery in the event of physical chassis extraction.
- > NVLink Isolation: Model weights and working context reside strictly within unified high-bandwidth memory (up to 1.8 TB/s NVLink bus), bypassing host operating system swap disks.

## Hardware Safety & Electromagnetic Standards [= UL / CE / FCC Part 15]
- ./ UL / IEC 62368-1 Safety Certification: Physical chassis, power supplies, and thermal dissipation systems comply with international safety standards for Audio/Video, Information, and Communication Technology Equipment. Systems include redundant thermal cutoffs and power-surge protection.
- ./ FCC Part 15 (Class A & Class B): Verified compliance with Federal Communications Commission electromagnetic interference (EMI) and radio frequency interference (RFI) standards.
- ./ Environmental RoHS & REACH: Hardware manufacturing adheres to EU Restriction of Hazardous Substances (RoHS) and REACH directives, eliminating lead, mercury, and hazardous halogens.

---

# TIER 04 // REGULATED INDUSTRY SECTOR FRAMEWORKS

How Aradia's sovereign on-premise architecture enables seamless compliance across heavily regulated corporate, legal, financial, healthcare, and civic environments.

## 1. Enterprise GRC [= SOC 2 Type II / ISO 27001:2022]
Because Aradia systems operate locally behind the client's firewall, enterprise **Vendor Risk Management (VRM)** audits are radically simplified. There is no third-party cloud data processing agreement (DPA) required for inference, eliminating supply-chain exposure across SOC 2 Trust Services Criteria (Security, Confidentiality, Processing Integrity, and Privacy):
+ **./ Zero Vendor Data Ingestion:** Aradia has zero access to client logs, model queries, or working memory.
+ **./ Simplified SOC 2 Scope:** AI compute remains inside the enterprise's existing SOC 2 audited perimeter.
+ **./ ISO 27001 Annex A Alignment:** Meets A.8 (Asset Management), A.10 (Cryptography), and A.13 (Communications Security).

## 2. Legal Privilege & Privacy [= ABA 1.6(c) / GDPR / CCPA / SOX]
- **Engineered to Prevent Inadvertent Third-Party Waiver Under ABA Model Rule 1.6(c):** American Bar Association Model Rule 1.6(c) mandates that lawyers make reasonable efforts to prevent the unauthorized access or disclosure of confidential client data. By eliminating third-party cloud data transmission, multi-tenant caching, and vendor telemetry, Aradia ensures confidential legal work product remains strictly within the firm's sovereign custody.
+ **Attorney-Client Privilege Protection:** Sovereign local execution ensures litigation strategies, contracts, and deposition summaries remain protected under the attorney work-product doctrine with zero risk of third-party privilege waiver.
+ **GDPR & CCPA/CPRA Compliance:** Absolute data residency. Zero international data transfers (GDPR Chapter V), no third-party data selling/sharing, and 100% local Right-to-Erasure execution.
+ **Sarbanes-Oxley (SOX Section 404 & 802):** Internal financial records processed by private analyst agents retain verifiable, tamper-evident audit trails on local write-once storage.

## 3. Financial & Banking [= GLBA Safeguards / EU DORA / SEC 17a-4]
Financial institutions, wealth managers, and private family offices must safeguard Nonpublic Personal Information (NPI) under the **Gramm-Leach-Bliley Act (GLBA)** and international operational resilience mandates:
+ **GLBA Safeguards Rule:** NPI is processed strictly within private enclaves, eliminating cloud data leakage to public AI providers.
+ **EU Digital Operational Resilience Act (DORA):** Sovereign on-premise compute mitigates ICT concentration risk by eliminating operational dependency on single-point-of-failure cloud AI infrastructure.
+ **SEC 17a-4 & FINRA 4511:** Agent workflows can integrate with local WORM (Write Once, Read Many) archival storage for compliant electronic record-keeping.

## 4. Healthcare & Life Sciences [= HIPAA Security Rule / HITRUST / 21 CFR Part 11]
**HIPAA & HITECH Act Security Rule:** On-premise DGX hardware guarantees that Protected Health Information (PHI) and electronic PHI (ePHI) never exit the covered entity's physical premises. 
+ **BAA Elimination / Simplicity:** Because zero PHI is transmitted to Aradia or third-party cloud LLM APIs, the attack surface and vendor liability overhead are completely eliminated.
+ **HITRUST CSF Alignment:** Hardware and runtime controls align directly with HITRUST access control, endpoint security, and data protection specifications.
+ **FDA GxP & 21 CFR Part 11:** Pharmaceutical research and clinical triage agents operate with deterministic seeds, producing auditable, reproducible AI outputs for regulatory filings.

## 5. Civic & Government [= CJIS v5.9 / StateRAMP High Baseline]
Municipalities, public safety agencies, and government contractors handling sensitive Criminal Justice Information (CJI) or state records:
+ **FBI CJIS Security Policy (v5.9):** Physical appliance placement inside municipal data centers fulfills CJIS Area 5 (Physical Protection), Area 6 (Personnel Security), and Area 10 (System and Information Integrity).
+ **Zero Persistent Access / Supervised Remote Maintenance:** Aradia personnel have zero persistent network access. On-demand maintenance sessions require client-authorized initiation via outbound WireGuard tunnel and are strictly restricted to container runtime health, with zero vendor access to stored judicial or criminal justice records.
+ **StateRAMP & FedRAMP High Alignment:** Hardware-level isolation satisfies federal baseline controls for high-impact civic workloads.

---

# COMPLIANCE AUDIT & VALIDATION

Every Aradia appliance deployment includes a formal **Staging Studio Validation Report** documenting physical hardware serial numbers, TPM attestation status, full-disk encryption keys, thermal burn-in logs, and quantized model checksums.

---

**Company:** [Home](/) | [About](/about/) | [Solution](/solution/) | [Agents](/agents/) | [Partner Program](/partners/) | [Pricing](/pricing/) | [Compliance](/compliance/) | [Privacy Policy](/privacy-policy/) | [Terms](/terms/) | [Contact](/contact/)

**Agent Discovery:** [llms.txt](/llms.txt) [MD Index] | [llms-full.txt](/llms-full.txt) [Full Site] | [api/pricing.json](/api/pricing.json) | [api/agent-spec.json](/api/agent-spec.json) | [.well-known/mcp.json](/.well-known/mcp.json) | [.well-known/agent-manifest.json](/.well-known/agent-manifest.json)

© 1991-> Aradia LLC All rights reserved. No APIs. Physical Iron. Zero Tech Bro Hype.
