generated: '2026-08-02' method: searched source: https://www.aryaka.com/blog/aryaka-has-successfully-completed-soc-2-and-iso-27001-recertification-audits/ docs: - https://www.aryaka.com/faq/ - https://www.aryaka.com/fips-compliance-readiness-for-federal-customers/ - https://docs.aryaka.com/space/KNOW/289505287/Configure+SIEM+integration note: >- Aryaka publishes no machine-readable API contract, so nothing here is derived from a spec. Every entry below is either a certification/compliance claim Aryaka publishes on its own site, or a recorded absence. Aryaka's llms.txt links a "Trust & Security Center" at https://www.aryaka.com/legal/security-compliance/ — that URL returns the site's "Page Not Found" page, so no dedicated trust-center artifact was written. standards: - id: soc2-type-ii conforms: true evidence: >- Aryaka states it has completed SOC 2 Type II audits and recertification without observations, and has maintained SOC 2 Type 2 reports since 2015. A SOC 2 badge is rendered in the site-wide footer. source: https://www.aryaka.com/blog/aryaka-has-successfully-completed-soc-2-and-iso-27001-recertification-audits/ - id: iso-27001 conforms: true evidence: >- ISO/IEC 27001 certification (initial certification 2020, recertification audit completed without observations). ISO and ISO-27001 badges are rendered in the site-wide footer. source: https://www.aryaka.com/blog/aryaka-has-successfully-completed-soc-2-and-iso-27001-recertification-audits/ - id: gdpr conforms: true evidence: GDPR badge in the site-wide footer; privacy program described in the privacy policy. source: https://www.aryaka.com/privacy-policy/ - id: ccpa conforms: true evidence: CCPA badge in the site-wide footer. source: https://www.aryaka.com/privacy-policy/ - id: csa-ccm conforms: true evidence: >- Aryaka states it maintains and updates a Cloud Security Alliance Cloud Controls Matrix (CCM) so customers can review its security controls. source: https://www.aryaka.com/blog/aryaka-has-successfully-completed-soc-2-and-iso-27001-recertification-audits/ - id: fips-140 conforms: partial evidence: >- Aryaka publishes a "FIPS Compliance Readiness for Federal Customers" page describing readiness rather than an awarded FIPS 140 validation. source: https://www.aryaka.com/fips-compliance-readiness-for-federal-customers/ - id: iso-42001 conforms: unverified evidence: >- The AI>Secure security FAQ names ISO 42001 (AI Management System), the EU AI Act and the NIST AI Risk Management Framework as frameworks the service aligns to. Alignment is claimed; certification is not. source: https://www.aryaka.com/faq/ - id: pci-dss conforms: false evidence: no published PCI DSS claim found - id: hipaa conforms: false evidence: >- No HIPAA claim found on aryaka.com. (Aryaka's llms.txt asserts HIPAA on a trust page that returns 404; the claim could not be substantiated on any live page.) - id: fedramp conforms: false evidence: no FedRAMP authorization found; only the FIPS readiness page - id: oauth2 conforms: false evidence: no public OAuth 2.0 API surface documented - id: oidc conforms: true evidence: >- Aryaka Identity Management (AIM) and MyAryaka SSO support SAML 2.0 and OIDC via Microsoft Entra, Okta, Cisco Duo, Active Directory and LDAP. This is end-user SSO to the portal, not API authorization. source: https://docs.aryaka.com/space/KNOW/1510247/Aryaka+Identity+Management - id: saml2 conforms: true evidence: SAML 2.0 SSO documented for Entra, Okta and Duo in the MyAryaka help space. source: https://docs.aryaka.com/space/KNOW/196771853 - id: scim conforms: false evidence: no SCIM 2.0 provisioning endpoint documented - id: rfc9457-problem-details conforms: false evidence: no public API contract to evaluate - id: openapi conforms: false evidence: no OpenAPI/Swagger document found on any Aryaka host (see well-known/aryaka-well-known.yml) - id: asyncapi conforms: false evidence: no AsyncAPI document found; the event surface is SIEM log forwarding (see asyncapi/aryaka-siem-log-streaming.yml) - id: syslog-rfc5424 conforms: true evidence: >- SIEM integration forwards security, flow and Private Access logs to customer SIEMs, with per-log-type attribute references published in the documentation. source: https://docs.aryaka.com/space/KNOW/289505287/Configure+SIEM+integration