Information Security Policy

Organization-wide security controls, risk management, and governance framework.

NIST controls:AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PS, RA, SA, SC, SI
Last updated:2026-03-15
Category:Governance
# Information Security Policy **Document ID**: KD-POL-001 **Owner**: Chief Technology Officer **Approved By**: CEO, Arivaran **Effective Date**: 2026-03-19 **Next Review Date**: 2027-03-19 (recomputed 2026-10-02 on the stated semi-annual cycle from the Effective Date; the 2026-09-19 occurrence was not recorded, and this date does not assert that a review has taken place) **Review Cycle**: Semi-annual **Classification**: Internal ## 1. Purpose This policy establishes the information security governance framework for KuiperDesk, Arivaran's backup-as-a-service platform. KuiperDesk processes, stores, and transmits customer backup data across a multi-tenant infrastructure. The confidentiality, integrity, and availability of that data is the foundation of the business. This policy defines the commitments, organizational structure, and accountability mechanisms that ensure security is treated as a continuous operational requirement, not a periodic exercise. ## 2. Scope This policy applies to: - **Systems**: All KuiperDesk infrastructure including the product hub clusters (EU1: kd-prod-b, US1: kd-prod-a — two independent single-node RKE2 with k8gb failover), VPS-3 (monitoring/mail), the aaSatGwSvc cross-node tunnel fabric, all Kubernetes workloads (aaHashSvc, aaTwinSvc, PgEdge/CNPG, SeaweedFS, Keycloak, Forgejo, Mailcow), and the CI/CD pipeline. - **Data**: Customer backup blocks stored in SeaweedFS, hash metadata in PostgreSQL/Citus, digital twin catalog in PostgreSQL/Citus, tenant configuration, PKI material, and all system logs. - **People**: All Arivaran personnel (employees, contractors, interns) who access KuiperDesk systems or data. - **Agents**: The aaagent Windows client software deployed on customer endpoints and its communication channels to KuiperDesk backend services. Out of scope: Customer-side endpoint security beyond the aaagent process boundary, and customer network configurations. ## 3. Policy Statements ### 3.1 Security Governance 3.1.1. Arivaran shall maintain an Information Security Management System (ISMS) aligned with ISO 27001:2022 and SOC 2 Type II Trust Service Criteria. 3.1.2. The CTO is the designated Information Security Officer and is accountable for the effectiveness of the ISMS. Day-to-day security operations are delegated to the infrastructure engineering team. 3.1.3. Security objectives shall be defined annually, tracked quarterly, and reported to company leadership. Objectives must be specific, measurable, and tied to risk treatment decisions. 3.1.4. All security policies shall be reviewed at least semi-annually and updated when there are material changes to the threat landscape, infrastructure architecture, or regulatory requirements. ### 3.2 Risk-Based Approach 3.2.1. Security controls shall be selected and prioritized based on a formal risk assessment process (see KD-POL-006 Risk Management Policy). Controls must address identified risks, not just compliance checkboxes. 3.2.2. Residual risk must be formally accepted by the CTO with documented justification. No risk acceptance is valid for more than 12 months without re-evaluation. ### 3.3 Defense in Depth 3.3.1. KuiperDesk infrastructure shall implement layered security controls: - **Network layer**: TLS-encrypted aaSatGwSvc tunnel for cross-node communication, Cilium NetworkPolicy for pod-to-pod traffic, firewalld on all hosts. - **Identity layer**: Keycloak SSO with OIDC for all administrative services, mTLS for agent-to-service communication, individual admin accounts with audit trails. - **Data layer**: TLS 1.3 for all data in transit, FIPS 140-2 validated cryptographic modules, content-addressed storage with SHA-256 integrity verification. - **Host layer**: SELinux enforcing on all nodes, FIPS mode enabled, CIS-benchmarked OS hardening. - **Application layer**: Input validation, tenant isolation via Keycloak Organizations, RBAC enforcement at the API gateway. 3.3.2. No single control failure shall result in unauthorized access to customer data. Compensating controls must exist for every critical security function. ### 3.4 Tenant Isolation 3.4.1. KuiperDesk is a multi-tenant platform. Tenant data isolation is enforced at the application layer (tenant_id-scoped queries in PostgreSQL/Citus), the network layer (Kubernetes NetworkPolicy), and the identity layer (Keycloak Organizations with scoped JWT claims). 3.4.2. Tenant isolation controls shall be tested quarterly through automated integration tests that verify cross-tenant access is denied. ### 3.5 Continuous Monitoring 3.5.1. All KuiperDesk systems shall emit structured logs to a centralized logging stack (Loki on VPS-3) with a minimum retention of 90 days. 3.5.2. Security-relevant events (authentication failures, privilege escalation, configuration changes, certificate operations) shall generate alerts via AlertManager with defined response SLAs. 3.5.3. Tetragon shall be deployed on all RKE2 nodes for kernel-level runtime security monitoring, detecting anomalous process execution, file access, and network connections. ### 3.6 Compliance Commitments 3.6.1. Arivaran commits to maintaining SOC 2 Type II certification covering the Security, Availability, and Confidentiality trust service categories. 3.6.2. Arivaran commits to operating the ISMS in conformance with ISO 27001:2022. 3.6.3. For customers subject to GDPR, Arivaran acts as a data processor and maintains a Data Processing Agreement (DPA) that meets Article 28 requirements. ## 4. Roles and Responsibilities | Role | Responsibility | |------|---------------| | CEO | Approve the ISMS scope and risk appetite. Allocate resources for security. | | CTO / Information Security Officer | Own the ISMS. Approve policies. Chair risk review meetings. Report security posture to leadership. | | Infrastructure Engineers | Implement and operate security controls. Respond to security alerts. Maintain evidence for audit. | | All Personnel | Complete security awareness training. Report security incidents. Follow acceptable use requirements. | ## 5. Supporting Policies This policy is the apex document. The following policies provide specific control requirements: | Policy | Document ID | |--------|-------------| | Access Control Policy | KD-POL-002 | | Incident Response Policy | KD-POL-003 | | Data Retention Policy | KD-POL-004 | | Business Continuity Policy | KD-POL-005 | | Risk Management Policy | KD-POL-006 | | Change Management Policy | KD-POL-007 | | Vendor Management Policy | KD-POL-008 | | Encryption Policy | KD-POL-009 | | Human Resources Security Policy | KD-POL-010 | | Media Sanitization Policy | KD-POL-011 | ## 6. Compliance Mapping | Policy Statement | SOC 2 Criteria | ISO 27001:2022 | |-----------------|----------------|----------------| | 3.1 Security Governance | CC1.1, CC1.2 | Clause 5.1, 5.2, 5.3 | | 3.2 Risk-Based Approach | CC3.1 | Clause 6.1 | | 3.3 Defense in Depth | CC1.3, CC6.1 | A.8.9, A.8.20 | | 3.4 Tenant Isolation | CC6.1, CC6.3 | A.8.22, A.8.31 | | 3.5 Continuous Monitoring | CC1.4, CC7.1, CC7.2 | A.8.15, A.8.16 | | 3.6 Compliance Commitments | CC1.5 | Clause 5.2, 9.1 | ## 7. Exceptions Any exception to this policy must be submitted in writing to the CTO, including: - The specific policy statement being excepted - Business justification - Compensating controls in place - Requested duration (maximum 6 months, renewable) - Risk assessment of the exception Approved exceptions are logged in the risk register and reviewed at each quarterly risk meeting. ## 8. Enforcement Violation of this policy may result in disciplinary action up to and including termination of employment or contract. Violations that result in data breaches will be handled under the Incident Response Policy (KD-POL-003) and may involve regulatory notification. ## 9. Revision History | Version | Date | Author | Changes | |---------|------|--------|---------| | 1.0 | 2026-03-19 | CTO | Initial release |

This document is part of the Arivaran Twin compliance program. For questions or the latest version, contact compliance@arivaran.ai.

Release-ready. Saved on this browser.