Security Model & Compliance

Arkhivio provides operational security controls and audit capabilities. Many storage-level security features — encryption at rest, immutability, lifecycle controls — are provided by the underlying S3-compatible storage platform under a shared responsibility model.

What Arkhivio controls, and what the storage layer controls

Arkhivio is deliberately designed to delegate storage-level protection to the underlying S3-compatible platform. This is consistent with the anti-lock-in architecture — not a gap.

Arkhivio — Application Layer
Credential encryption. S3 credentials stored locally are encrypted with Fernet (AES-128-CBC + HMAC). A MongoDB breach alone cannot reach S3 data.
External secrets management. Credentials can be pulled from AWS Secrets Manager, Azure Key Vault, GCP, IBM, HashiCorp Vault, or OpenBao — never stored on disk.
Role-based access control. Web dashboard enforces admin and operator roles. Authentication via local credentials or Active Directory (LDAP).
TLS enforcement. All S3 transfers use HTTPS (TLS 1.2+). Startup warns if TLS is disabled on a non-local MongoDB connection.
Integrity verification. CRC32 checksums computed at scan, stored in MongoDB and S3 metadata, verified at audit and restore. Drift is detected automatically.
Audit trail. Structured UTC-timestamped JSON logs for all operations. Immutable when forwarded to a SIEM. Named audit events on privileged actions.
Minimal data model. MongoDB stores only file metadata (path, size, mtime, CRC32) — no file content is ever stored in the operational database.
S3-Compatible Storage — Storage Layer
Encryption at rest. Configure SSE-KMS or equivalent on the bucket. Available on AWS S3, Cloudflare R2 (enabled by default), and most enterprise S3-compatible platforms.
Object versioning. Enable versioning on the bucket to retain prior versions of files across backup runs.
Object Lock (WORM). Configure S3 Object Lock for immutable backup retention. Available where supported by the platform.
Lifecycle policies. Automatically transition objects to lower-cost storage tiers or expire them according to retention policy.
Cross-region replication. Configure replication for geographic redundancy where available.
Available capabilities vary by S3-compatible provider and bucket configuration. Review your chosen platform's documentation for specific feature availability.

Important: No certifications claimed

Arkhivio does not hold and does not claim SOC 2, ISO 27001, HIPAA, GDPR, LGPD, PCI DSS, or any other compliance certification. The compliance reports on this page are technical assessments of how Arkhivio's capabilities map to specific regulatory requirements — not legal certifications. Using Arkhivio does not automatically make your environment compliant with any regulation. Compliance determinations must be validated by qualified legal and compliance specialists.

Compliance positioning

Arkhivio is designed to support organizations operating in regulated environments by providing: data integrity verification, structured audit logs, access control, credential security, and a resilient recovery path that does not depend on the backup application being available.

Many regulatory requirements — particularly around encryption at rest, immutability, and data retention — can be addressed at the storage layer using the capabilities of the S3-compatible platform and bucket configuration. Arkhivio's architecture is designed to make use of those capabilities rather than replicate them proprietary.

Organizational policies, staff training, risk assessments, DPIAs, and legal contracts remain the responsibility of the operating organization and are outside the scope of any technical product.


Compliance capability assessments

Each report assesses Arkhivio's technical and architectural controls against a specific regulatory framework — including what is satisfied by design, what requires operational configuration, and what requires external or legal action.