Compliance Framework Alignment
No reference architecture is automatically compliant with or certified against SOC 2, HIPAA, GDPR, CCPA, PCI DSS, FedRAMP, or another framework. The customer should identify applicable obligations, data classes, control owners, and evidence requirements with qualified assessors and counsel. An engagement can map architecture and implementation work to those requirements, but compliance conclusions depend on the actual environment, operations, contracts, and evidence.
Data Encryption and Transit Security
Encryption and key management are selected for the target environment and documented in the engagement's security design. Use currently approved protocols and algorithms, separate trust boundaries where the risk model requires it, and define key ownership, access, rotation, backup, and revocation. Do not infer that an on-premises or air-gapped topology is secure by itself; its local key and update infrastructure also needs review and testing.
Audit Logging and Evidence
Define which events require a decision record and capture actor identity, authorization context, action, target, timestamp, source references, approvals, verification, and outcome as appropriate. Hidden model reasoning is not reliable audit evidence. Integrity protection, retention, redaction, and export to the customer's SIEM or governance tooling are deployment-specific controls. Evidence formats should be agreed with the customer's control owners or assessor; ActiveMotion does not claim prebuilt auditor reports.
Access Control and Segregation
Access control should cover configuration, integrations, policies, operational records, and deployment actions. Use scoped identities and separate duties according to the customer's risk model. If a multi-tenant design is selected, isolation at storage, network, identity, and compute layers must be demonstrated for that implementation. Approval requirements for privileged changes belong in the customer's change process and should be tested.