The Principle
Data is the asset. Not the systems. Not the networks. Not the applications. The systems, networks, and applications exist to serve the data. When a hospital entrusts Ariana Nexus with interpreter session records involving Protected Health Information, that data carries the weight of federal law, patient trust, and clinical outcomes. When a government agency shares Controlled Unclassified Information for a language services engagement, that data carries national security implications. When an AI lab provides training datasets containing linguistic annotations, that data carries the intellectual property of a billion-dollar product line.
Ariana Nexus protects data not by building walls around systems, but by attaching protection to the data itself — classifying it at creation, labeling it for its full lifecycle, controlling who can access it, monitoring how it moves, and ensuring it is destroyed when its purpose is fulfilled. Protection follows the data, not the perimeter.
Data Classification Framework
Ariana Nexus operates a four-tier data classification framework, implemented through Microsoft Purview Information Protection Sensitivity Labels. Every document, email, spreadsheet, presentation, dataset, and file within the Ariana Nexus environment is classified into one of the following tiers:
Tier 1: Public
Definition: Information approved for unrestricted external distribution. Disclosure of Public data poses no risk to Ariana Nexus, its clients, its partners, or individuals.
Examples: Website content, published marketing materials, press releases, publicly available capability descriptions, job postings, published thought leadership, and publicly filed documents.
Controls:
- No encryption required.
- No access restrictions beyond standard authentication.
- Sensitivity Label applied: Public (green visual marking).
- May be shared externally without approval.
Tier 2: Internal
Definition: Information intended for use within Ariana Nexus by authorized personnel. Disclosure to unauthorized parties could cause minor operational disruption but would not constitute a regulatory violation or breach of client trust.
Examples: Internal communications, operational documents, meeting notes, internal policies and procedures, employee training materials, non-sensitive project plans, and internal organizational data.
Controls:
- Sensitivity Label applied: Internal (yellow visual marking).
- Accessible only to authenticated Ariana Nexus employees with valid Microsoft Entra ID credentials.
- Not shared externally without manager approval.
- DLP policies monitor for accidental external transmission and alert the sender.
Tier 3: Confidential
Definition: Information whose unauthorized disclosure could cause significant harm to Ariana Nexus, its clients, or its partners, including competitive disadvantage, reputational damage, financial loss, or breach of contractual obligations.
Examples: Client proposals, engagement agreements, pricing models, financial records, strategic plans, partnership agreements, vendor contracts, internal audit findings, and business development materials.
Controls:
- Sensitivity Label applied: Confidential (orange visual marking).
- Encryption applied automatically upon labeling. Documents remain encrypted at rest and in transit.
- Access restricted to designated Security Groups in Microsoft Entra ID. Only personnel with documented need-to-know may access Confidential data.
- DLP policies block external sharing of Confidential-labeled content via email, Teams, SharePoint, and OneDrive. Attempted violations are logged and escalated.
- Watermarking applied to Confidential documents (header/footer marking visible on print and screen).
- External sharing requires explicit approval from a Tier 1 administrator and is logged in the audit trail.
Tier 4: Restricted
Definition: Information subject to the highest level of protection due to legal, regulatory, contractual, or safety requirements. Unauthorized disclosure could result in regulatory enforcement, criminal liability, harm to individuals, breach of federal law, or compromise of national security.
Examples: Protected Health Information (PHI) governed by HIPAA, Controlled Unclassified Information (CUI) governed by NIST SP 800-171, AI training data containing personally identifiable information, Afghan diaspora data involving vulnerable populations, attorney-client privileged communications, and information subject to government security classification guidance.
Controls:
- Sensitivity Label applied: Restricted (red visual marking).
- Encryption enforced at all times — at rest, in transit, and in use. Documents cannot be opened by unauthorized recipients even if intercepted.
- Access limited to individually named personnel or dedicated Security Groups with verified need-to-know and appropriate contractual authorization (BAA, DPA, NDA, or government security clearance as applicable).
- DLP policies enforce strict blocking of any external transmission. No Restricted data may leave the Ariana Nexus environment without explicit Tier 1 administrator approval and documented regulatory authorization.
- Print restrictions and copy/paste restrictions enforced through Microsoft Purview Information Rights Management (IRM).
- Audit logging captures every access, modification, sharing attempt, and label change for Restricted data.
- Retention and destruction governed by the applicable regulatory requirement (HIPAA: minimum 6 years; FAR 4.703: minimum 3 years after final payment; CUI: per agency instruction).
- Processing occurs exclusively within the United States for CUI. PHI processing occurs only on platforms with executed Business Associate Agreements.
Classification Governance
Who Classifies Data
Every Ariana Nexus team member — employee, contractor, and Collective member — is responsible for classifying the data they create, receive, or process. Classification is not optional. It is an operational requirement enforced through policy, training, and technology.
At Creation: When a team member creates a document, email, or dataset, they are prompted to apply a Sensitivity Label before saving or sending. Microsoft Purview is configured to require label selection for all new content within the Microsoft 365 environment.
At Receipt: When data is received from a client, partner, or external source, the receiving team member classifies it based on the data's content and the applicable contractual or regulatory requirements.
Default Classification: If a team member fails to apply a label, the system applies a default label of Internal to prevent unclassified data from being treated as Public. This default can be overridden to a higher classification but not to a lower one without administrator approval.
Classification Review
Ariana Nexus conducts periodic classification reviews to ensure that data is appropriately labeled:
- Quarterly Reviews: Random sampling of documents across SharePoint, OneDrive, and Exchange to identify misclassified content.
- Engagement Onboarding Reviews: At the start of every new client engagement, a classification assessment is conducted to determine the appropriate tier for all engagement data.
- Incident-Driven Reviews: If a DLP policy triggers on a document, the classification is reviewed and corrected if necessary.
Reclassification
Data may be reclassified upward (from a lower to a higher tier) by any authorized team member. Reclassification downward (from a higher to a lower tier) requires approval from a Tier 1 administrator and documentation of the justification. All reclassification events are logged in the audit trail.
Data Loss Prevention (DLP)
Ariana Nexus deploys Microsoft Purview Data Loss Prevention policies across all data surfaces within the organization. DLP is not a single tool — it is a policy framework that monitors data in motion, data at rest, and data in use across every channel where information could be exposed.
DLP Enforcement Scope
Exchange Online (Email) — DLP Active. Outbound and internal emails scanned for sensitive data patterns, Sensitivity Labels, and classification violations.
SharePoint Online — DLP Active. Documents scanned at upload and during sharing operations for classification compliance and sensitive content.
OneDrive for Business — DLP Active. User file storage monitored for sensitive data patterns and unauthorized sharing attempts.
Microsoft Teams — DLP Active. Chat messages, channel posts, and file sharing scanned for sensitive data patterns and policy violations.
Endpoint Devices — DLP Active. Data on enrolled devices monitored for copy, print, transfer to USB, upload to unauthorized cloud services, and clipboard operations involving sensitive content.
DLP Policy Rules
Ariana Nexus has configured the following DLP policy rules within Microsoft Purview:
PHI Detection: DLP rules detect patterns consistent with Protected Health Information, including medical record numbers, health insurance claim numbers, diagnosis codes, and patient identifiers. When PHI patterns are detected outside of Restricted-labeled environments, the transmission is blocked and the incident is escalated.
PII Detection: DLP rules detect personally identifiable information, including Social Security numbers, passport numbers, financial account numbers, and combinations of name plus sensitive identifier. Policy actions include blocking external sharing, alerting the user, and logging the incident.
CUI Marking Detection: DLP rules detect content bearing CUI markings or classifications. CUI-marked content is restricted from external transmission and from storage in non-authorized environments.
Sensitivity Label Enforcement: DLP rules enforce that Confidential and Restricted labeled content cannot be shared externally via email, Teams, or SharePoint sharing links. Attempted violations trigger user notification, block the action, and generate an incident report.
Custom Rules: Ariana Nexus configures engagement-specific DLP rules for client data that requires additional protection beyond standard tier controls. Custom rules are defined during engagement onboarding and documented in the applicable Data Protection Plan.
DLP Incident Workflow
When a DLP policy is triggered:
- User Notification: The user receives an immediate policy tip explaining that their action has been blocked or flagged, and why.
- Override Request (where applicable): For certain medium-severity violations, the user may submit a business justification override, which is logged and reviewed.
- Incident Logging: Every DLP event is logged in the Microsoft Purview compliance portal with full details: user, action, content, policy matched, and resolution.
- Escalation: High-severity violations (attempted exfiltration of Restricted data, repeated violations by the same user, or violations involving PHI or CUI) are escalated to the Security Office for investigation.
- Remediation: The Security Office investigates, determines root cause, and implements corrective action, which may include reclassification, access revocation, additional training, or disciplinary measures.
Personnel Vetting and Data Handling Standards
Team Vetting
Every individual who accesses the Ariana Nexus environment — regardless of role, location, or engagement type — is vetted before access is provisioned. Ariana Nexus's team comprises professionals educated at the world's most prestigious institutions, including Cornell University, Harvard, Columbia, Oxford, Brown, NYU, UCLA, George Mason, University of Washington, Kabul University, Herat University, and others. Academic credentials are verified. Professional experience is validated. Character and integrity are assessed.
Current Vetting Standards:
- Identity verification and right-to-work confirmation for all personnel.
- Educational credential verification for all professional and subject-matter expert roles.
- Professional reference checks.
- Background screening, including criminal history checks where legally permitted and required by engagement type (e.g., healthcare, government, defense).
- Non-Disclosure Agreement (NDA) execution prior to access to any Confidential or Restricted data.
- Acknowledgment of the Ariana Nexus Acceptable Use Policy and Information Security Policy.
- Completion of data protection and classification training prior to access provisioning.
For Future International Team Members:
As Ariana Nexus expands its workforce to include team members based in Europe and other non-sanctioned countries, the same vetting standards apply universally. Every individual, regardless of geographic location, is subject to:
- Equivalent identity verification and credential validation under applicable local and international law.
- OFAC and applicable sanctions screening.
- NDA execution under the laws of both the United States and the team member's country of residence.
- Compliance with all Ariana Nexus Trust Center policies, the Privacy Policy, the Terms of Use, and all applicable data protection regulations — including U.S. federal law, the GDPR (for EU-based team members), the UK GDPR (for UK-based team members), and any other applicable national data protection law.
- The same Sensitivity Label, DLP, Conditional Access, MFA, and device compliance requirements that apply to U.S.-based personnel.
No exception is made based on geography, nationality, or employment type. Data protection standards are universal.
Data Handling Training
All personnel with access to the Ariana Nexus environment complete data protection and classification training:
- Initial Training: Completed within the first five (5) business days of access provisioning. Covers the four-tier classification framework, Sensitivity Label application, DLP policy awareness, incident reporting procedures, and sector-specific requirements (PHI handling for healthcare engagements, CUI handling for government engagements).
- Annual Refresher Training: Mandatory annual refresher covering policy updates, new regulatory requirements, lessons learned from incidents, and emerging threats.
- Engagement-Specific Training: For engagements involving PHI, CUI, or other regulated data, personnel complete additional training tailored to the specific regulatory and contractual requirements of the engagement.
- Training Records: All training completion records are maintained in the Ariana Nexus compliance management system and are available for client audit upon request.
Data Backup, Retention, and Destruction
Backup Strategy
Ariana Nexus maintains a structured data backup strategy that goes beyond Microsoft 365 default retention:
- Microsoft 365 Native Protection: SharePoint, OneDrive, Exchange, and Teams data is protected by Microsoft's built-in redundancy, versioning, and recycle bin retention.
- Third-Party Backup (Implemented): Ariana Nexus deploys a third-party backup solution that provides independent, encrypted backup of all Microsoft 365 data, including SharePoint libraries, OneDrive accounts, Exchange mailboxes, and Teams data. Backups are stored in a geographically separate, encrypted environment.
- Backup Frequency: Daily incremental backups. Weekly full backups.
- Retention of Backups: Backup data retained in accordance with the engagement-specific retention schedule and applicable regulatory requirements.
- Backup Testing: Restore testing conducted semi-annually to verify backup integrity and recoverability.
Retention Schedules
Data retention at Ariana Nexus is governed by a formal retention schedule aligned with legal, regulatory, and contractual requirements:
- Client Engagement Records — Duration of engagement + 7 years. Governing requirement: Tax, audit, and contractual obligations.
- Protected Health Information (PHI) — 6 years from creation or last effective date. Governing requirement: HIPAA 45 CFR § 164.530(j).
- Controlled Unclassified Information (CUI) — 3 years after final contract payment. Governing requirement: FAR 4.703.
- Government Contract Records — 3 years after final payment (or longer per agency). Governing requirement: FAR 4.703, agency-specific requirements.
- AI Training Data (client-provided) — Per Data Processing Agreement. Governing requirement: Client-specific contractual terms.
- Employee and Contractor Records — Duration of employment/engagement + 7 years. Governing requirement: Employment law, tax obligations.
- Website Visitor Data (cookies, analytics) — Per Cookie Policy (max 26 months for analytics). Governing requirement: GDPR, CCPA/CPRA.
- Contact Form Submissions — 2 years (unless leads to engagement). Governing requirement: Privacy Policy.
- Audit Logs and Compliance Records — 7 years. Governing requirement: Industry best practice, SOC 2 requirements.
- Legal Hold / Litigation Records — Duration of hold + applicable statute of limitations. Governing requirement: Legal obligation.
Data Destruction
When data reaches the end of its retention period and is not subject to a legal hold or regulatory preservation requirement:
- Electronic Data: Securely deleted using methods that render the data unrecoverable. For Restricted-tier data, cryptographic erasure (destroying the encryption keys) is the preferred method.
- Physical Media (if applicable): Destroyed through cross-cut shredding or degaussing in accordance with NIST SP 800-88 Rev. 1 (Guidelines for Media Sanitization).
- Destruction Certification: A record of destruction is maintained, documenting the data destroyed, the method of destruction, the date, and the individual who performed or authorized the destruction.
- Client Notification: For client data subject to Data Processing Agreements, Ariana Nexus provides certification of data destruction upon request.
Alignment with Security and Compliance Frameworks
Ariana Nexus's data protection and classification architecture is designed in alignment with the following recognized frameworks and standards:
NIST SP 800-171 Rev. 2 / Rev. 3 — Media Protection (MP), System and Information Integrity (SI). Aligned — classification, DLP, encryption, and destruction controls implemented (Rev. 2 current for DoD/CMMC; Rev. 3 transition planned per DoD rulemaking).
HIPAA Security Rule (45 CFR § 164.312) — Access controls, audit controls, transmission security, integrity controls. Aligned — Purview DLP, Sensitivity Labels, encryption, and audit logging active.
HIPAA Privacy Rule (45 CFR § 164.530) — Administrative requirements including retention. Aligned — 6-year minimum retention enforced.
NIST SP 800-53 Rev. 5 — SC (System and Communications Protection), MP (Media Protection). Roadmap — alignment planned with E5 upgrade and FedRAMP preparation.
GDPR (Articles 5, 25, 32) — Data minimization, purpose limitation, integrity, security of processing. Aligned — classification, DLP, retention schedules, and encryption implemented.
UK GDPR — Same as GDPR. Aligned.
CCPA/CPRA — Reasonable security measures. Aligned — DLP, encryption, access controls operational.
EU AI Act (Article 10) — Data governance for AI training data. Aligned — Restricted-tier classification for AI data with PII, provenance tracking.
NIST AI RMF — Data quality and integrity in AI lifecycle. Aligned — classification, labeling, and HITL quality controls for AI data.
SOC 2 (Trust Services Criteria) — CC6 (Logical and Physical Access), CC7 (System Operations). Roadmap (2026–2027) — controls operational, audit planned.
ISO 27001:2022 — Annex A.8 — Asset Management, Annex A.8.10 — Information Deletion. Roadmap (2027) — controls aligned, certification planned.
CMMC Level 2 — Media Protection (MP) domain. Roadmap (2027) — controls implemented, certification planned.
FAR 4.703 — Contract records retention. Compliant — 3-year minimum retention enforced.
NIST SP 800-88 Rev. 1 — Media sanitization guidelines. Aligned — destruction methods follow NIST 800-88 guidance.
Terminology:
- Implemented — The control or framework is fully deployed and operational in the current environment.
- Aligned — Ariana Nexus has designed its controls in accordance with the framework and follows its principles, but has not undergone formal third-party certification or audit.
- Compliant — Ariana Nexus meets the specific regulatory requirement as described.
- Roadmap — Ariana Nexus is actively planning or preparing for formal certification, with a target completion date.
Sector-Specific Data Protection
Healthcare (HIPAA)
Protected Health Information processed during interpretation, translation, and cultural competency engagements is classified as Restricted, encrypted at all times, accessible only to BAA-authorized personnel, governed by PHI-specific DLP rules, and retained for the HIPAA-mandated minimum of six (6) years. No PHI is stored on the Website, personal devices, or platforms without executed BAAs.
Government (CUI / NIST 800-171)
Controlled Unclassified Information is classified as Restricted, stored in dedicated SharePoint environments within the United States, accessible only to personnel with verified need-to-know and completed CUI handling training, governed by CUI-specific DLP rules, and retained per FAR 4.703 and agency-specific instructions. CUI is never transferred outside U.S. borders without explicit government authorization.
AI & Technology (AI Data Factory)
AI training data containing personally identifiable information is classified as Restricted. Client-provided datasets are governed by the applicable Data Processing Agreement, with purpose limitation enforced through both contractual obligation and technical control (Sensitivity Labels, DLP, access restrictions). Data provenance records track the origin, consent basis, and annotation history of all AI training data.
Research & Education
Research data involving human subjects or sensitive populations is classified at the Confidential or Restricted tier based on the applicable Institutional Review Board (IRB) protocol and data-use agreement. Access is governed by time-bound permissions scoped to the research team.
What Data Protection Means for Our Clients and Partners
For procurement officers: Every piece of your data that enters the Ariana Nexus environment is classified, labeled, encrypted, and governed by DLP policies from the moment it arrives until the moment it is destroyed. We can produce classification reports, DLP incident summaries, and retention compliance evidence on demand.
For CISOs: Our four-tier classification with automated labeling, full-surface DLP (email, SharePoint, OneDrive, Teams, and endpoint), and structured destruction procedures give you a verifiable data protection chain from ingestion to disposal.
For compliance officers: Our retention schedules are mapped to specific regulatory requirements (HIPAA, FAR, GDPR, CCPA). Destruction is certified and auditable. Classification governance includes quarterly reviews, engagement onboarding assessments, and incident-driven re-evaluation.
For government contracting officers: CUI is segregated, encrypted, restricted to U.S. personnel, and governed by NIST SP 800-171 access control and media protection families. Our System Security Plan is in development, and our CMMC Level 2 certification is on the 2027 roadmap.
If your organization requires data protection documentation, DLP policy evidence, classification architecture briefings, or retention schedule verification, contact trust@ariananexus.com or +1 (202) 771-0224.
Maturity Roadmap
Ariana Nexus views data protection as a multi-year journey. The following roadmap reflects our planned maturation path:
Phase 1: Foundation (Current — 2026)
Four-tier classification operational with Sensitivity Labels deployed. DLP active across all surfaces including endpoint. Structured backup with third-party solution. Formal retention schedules enforced. Personnel vetting and training operational.
Phase 2: Hardening (Q3–Q4 2026)
Automated classification with Microsoft Purview trainable classifiers. Enhanced PHI and CUI detection models. Engagement-specific DLP rule library. International team member vetting and onboarding framework.
Phase 3: Certification (2027)
SOC 2 Type II audit (CC6, CC7). ISO 27001 Annex A.8 certification. CMMC Level 2 Media Protection domain. Data governance maturity assessment.
Phase 4: Advanced Maturity (2028)
Microsoft Purview Data Lifecycle Management automation. Adaptive DLP with risk-based policy enforcement. Data residency controls for multi-jurisdictional engagements. NIST SP 800-53 Rev. 5 alignment for FedRAMP.
Phase 5: Autonomous Data Protection (2030+)
AI-driven data classification and anomaly detection. Real-time data lineage and provenance tracking across all systems. Automated regulatory compliance mapping for emerging data protection laws. Quantum-resistant encryption migration.
Limitation of Liability and Disclaimers
No Guarantee Against Data Loss or Breach. Ariana Nexus implements commercially reasonable data protection measures aligned with recognized industry frameworks. However, no data protection system can guarantee absolute prevention of data loss, unauthorized access, or data breach. Ariana Nexus expressly disclaims any warranty or guarantee of absolute data security.
Framework Alignment vs. Certification. Where this page states "aligned," controls are designed in accordance with the framework but formal third-party certification has not been obtained unless explicitly stated. Where "compliant" is stated, Ariana Nexus meets the specific regulatory requirement as described. Where "roadmap" is stated, certification is planned but not yet achieved.
Roadmap Items. The maturity roadmap reflects current plans as of the Effective Date. Roadmap items are forward-looking statements, not binding commitments. Ariana Nexus reserves the right to modify, defer, or reprioritize roadmap items at its sole discretion.
Third-Party Dependencies. Data protection controls rely on the Microsoft Purview, Microsoft 365, and third-party backup platforms. Ariana Nexus does not control these platforms and disclaims liability for incidents attributable to third-party platform failures.
Client-Specific Obligations. The data protection commitments described on this page represent Ariana Nexus's general organizational posture. Specific data protection obligations for individual client engagements are defined exclusively in the applicable Engagement Agreement, Data Processing Agreement, or Business Associate Agreement. In the event of conflict, the Engagement Agreement controls.
Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, ARIANA NEXUS'S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATED TO DATA PROTECTION AND CLASSIFICATION SHALL NOT EXCEED THE AMOUNTS SET FORTH IN THE APPLICABLE ENGAGEMENT AGREEMENT, OR, WHERE NO ENGAGEMENT AGREEMENT EXISTS, ONE HUNDRED DOLLARS ($100). ARIANA NEXUS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES ARISING FROM OR RELATED TO ANY DATA LOSS, BREACH, OR CLASSIFICATION ERROR. NOTHING IN THIS SECTION SHALL LIMIT OR EXCLUDE ARIANA NEXUS'S LIABILITY FOR: (A) FRAUD OR FRAUDULENT MISREPRESENTATION; (B) DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE; OR (C) ANY OTHER LIABILITY THAT CANNOT BE EXCLUDED OR LIMITED BY APPLICABLE LAW, INCLUDING BUT NOT LIMITED TO LIABILITY UNDER THE UK UNFAIR CONTRACT TERMS ACT 1977, THE UK CONSUMER RIGHTS ACT 2015, OR GDPR.
Dispute Resolution. Any dispute arising out of or relating to this page shall be subject to the dispute resolution provisions in the Terms of Use, Section 18.