Ariana Nexus operates at the intersection of healthcare, artificial intelligence, government, and research, where a single unauthorized access event can compromise patient safety, national security, model integrity, or the physical safety of the Afghan diaspora scholars the firm serves. The firm has adopted zero trust as the foundational governance model for its systems, data, and operations. Zero trust is not a product or a feature. It is an operating discipline: assume breach, verify explicitly, enforce least privilege, and inspect continuously.
This document states that posture. It describes the controls the firm operates today, the frameworks its design is aligned to, and the maturity path it is following. It is a posture statement. Alignment to a framework is a statement of consistency with that framework; it is not a certification, and this document asserts none except where a control is stated to be implemented and operational.
This document governs the identity, access, and data-handling controls Ariana Nexus applies across every engagement and all four sectors it serves: Healthcare Systems, Government and Public Sector, AI and Data Systems, and Research, Education and Institutional Partnerships. It applies to the firm's personnel, its contracted experts, and the platform services the firm operates.
Ariana Nexus is a Delaware limited liability company headquartered in Washington, D.C., with primary operations in Virginia and offices planned in London and Berlin. It maintains no operations inside Afghanistan and no office in Kabul, a deliberate legal-protection posture that bounds where data is handled. Controlled Unclassified Information, where processed, is handled within the United States.
This document describes a zero-trust operating discipline. Where it states that a control is implemented, that control is deployed and operational. Where it states alignment to a framework, the firm has designed its controls in accordance with that framework but has not undergone third-party certification against it unless expressly noted. Alignment is not certification.
The firm's architecture rests on four principles, consistent with NIST Special Publication 800-207 and the widely used formulation of zero trust. Every connection is untrusted until verified. Every device is unmanaged until enrolled. Every request is unauthorized until validated. Every session is monitored until terminated.
Every access request is authenticated and authorized on all available signals: identity, location, device health, workload, data classification, and anomaly detection. Access is never granted on network location alone. A user on the office network receives the same scrutiny as a user connecting from another country.
Access is granted on a just-enough and just-in-time basis. No user holds standing administrative access to production systems. Privileged roles are assigned through time-limited elevation with approval, and access reviews keep permissions matched to current function rather than historical accumulation.
The architecture is designed on the assumption that any component may already be compromised. That assumption drives segmentation, encryption, continuous monitoring, and automated response. The objective is not to prevent every breach, which no organization can guarantee, but to minimize blast radius, detect compromise quickly, and contain its reach.
Authentication and authorization are enforced per session and re-evaluated. Access events, authentication attempts, policy violations, and anomalous behaviors are logged and analyzed.
The firm implements zero trust across six control planes, aligned with the NIST SP 800-207 architecture and the CISA Zero Trust Maturity Model.
| Control plane | Governing rule |
|---|---|
| Identity | Every user, service account, and workload identity is verified through strong authentication before access is granted. No implicit trust is conferred by network location, device type, or a prior session. |
| Device | Every endpoint is enrolled, managed, and assessed for compliance before access is permitted. Unmanaged devices are restricted to a limited access tier. |
| Network | Segmentation and micro-segmentation isolate workloads, data stores, and service layers. Lateral movement is restricted by policy, and internal traffic is treated with the same scrutiny as external traffic. |
| Application | Application access is governed by role-based policy enforced at the application layer. Unmanaged application use is monitored and controlled. |
| Data | Data is classified, labeled, and protected by sensitivity. Access is governed by identity, device posture, and least privilege, not by network membership. |
| Visibility and analytics | Access events, authentication attempts, policy violations, and anomalous behaviors are logged, correlated, and analyzed. |
The controls below are deployed within the Microsoft 365 Business Premium environment, which provides an integrated security stack for zero-trust enforcement across identity, endpoint, email, and data protection rather than a set of separate point tools.
Identity is the primary control plane. Access is governed through Microsoft Entra ID, the central identity plane for all organizational access. The following are enforced.
Devices are managed through Microsoft Intune, and endpoint compliance is a precondition of access rather than an assumption made after it.
The primary communication surface is protected by Microsoft Defender for Office 365.
Data is classified, labeled, and protected through Microsoft Purview across the Microsoft 365 environment.
Where an engagement involves Protected Health Information, a Business Associate Agreement is executed before any such data touches any platform. This precondition is absolute and applies regardless of sector or urgency.
The firm's zero-trust architecture is designed in alignment with the frameworks below. The status column uses the defined terms that follow the table.
| Framework | Status | Basis |
|---|---|---|
| NIST SP 800-207, Zero Trust Architecture | Aligned | Core reference architecture for the firm's zero-trust design. |
| CISA Zero Trust Maturity Model | Aligned | Used for self-assessment across its pillars. |
| NIST Cybersecurity Framework 2.0 | Aligned | Govern, Identify, Protect, Detect, Respond, Recover. |
| Microsoft Zero Trust deployment guidance | Implemented | Active deployment within Microsoft 365 Business Premium. |
| HIPAA Security Rule, 45 CFR 164.302 to 164.318 | Aligned | Technical safeguards implemented through the Microsoft 365 stack. |
| NIST SP 800-171 Rev. 2 and Rev. 3 | Roadmap | Required for Controlled Unclassified Information; System Security Plan in development. |
| SOC 2 Type II | Roadmap, 2026 to 2027 | Auditor engagement planned. |
| ISO/IEC 27001:2022 | Roadmap, 2027 | Formal certification planned. |
| CMMC Level 2 | Roadmap, 2027 | Certification target for defense engagements. |
| FedRAMP | Roadmap, 2028 | Long-term target for federal cloud authorization. |
| Term | Meaning |
|---|---|
| Implemented | The control or framework is fully deployed and operational in the current environment. |
| Aligned | The firm has designed its controls in accordance with the framework and follows its principles, but has not undergone third-party certification or audit against it. |
| Roadmap | The firm is planning or preparing for formal certification, with a target date. Target dates are provided in good faith and are subject to change. |
When the firm provides interpretation, translation, or cultural-competency services involving Protected Health Information, access to that information is limited to credentialed personnel operating under executed Business Associate Agreements, authenticated through multi-factor authentication, on compliant devices, and governed by data-loss-prevention policy. No Protected Health Information is accessible to any user, device, or application that has not passed every control plane.
For engagements involving Controlled Unclassified Information, the firm applies the requirements of NIST SP 800-171 within its zero-trust framework. Such information is isolated in dedicated environments with restricted access, sensitivity labels enforcing encryption and marking, and data-loss-prevention rules preventing exfiltration. All processing of Controlled Unclassified Information occurs within the United States.
The AI Data Factory processes linguistic, cultural, and annotation data for model training and validation. Access to training datasets, annotation pipelines, and quality-assurance outputs is governed by the same controls. Human reviewers are authenticated individually, their device posture is verified, and their access is scoped to only the data elements a specific task requires.
Academic research collaborations involving sensitive data are governed by data-use agreements and enforced through the same controls. External collaborators receive limited, time-bound access through guest policies in Microsoft Entra ID, with multi-factor authentication required and device compliance assessed.
The firm treats zero trust as a multi-year path. The phases below describe its planned maturation. Roadmap items are forward-looking and are governed by the roadmap qualifier in section 12; they are plans, not commitments.
| Phase | Planned work |
|---|---|
| Foundation, current to 2026 | Microsoft 365 Business Premium security stack deployed; multi-factor authentication enforced for all users; conditional access enforced; device enrollment and compliance operational through Intune; data-loss prevention and sensitivity labels deployed through Purview; email threat protection active; internal zero-trust self-assessment completed against the CISA maturity model. |
| Hardening, 2026 to 2027 | Evaluate upgrade to Microsoft 365 E5 for advanced threat protection; deploy centralized security event correlation and automated response; implement privileged identity management for just-in-time administrative access; formalize the System Security Plan and Plan of Action and Milestones for NIST SP 800-171; begin SOC 2 Type I readiness; engage a third-party penetration-testing firm for annual assessment. |
| Certification, 2027 to 2028 | Complete SOC 2 Type II audit; achieve ISO/IEC 27001:2022 certification; achieve CMMC Level 2 for defense engagements; deploy automated compliance monitoring; implement a zero-standing-access model with full privileged-identity-management enforcement. |
| Advanced maturity, 2028 to 2030 | Pursue FedRAMP authorization for cloud-based offerings; implement NIST SP 800-53 controls for high-impact government systems; deploy behavioral threat detection; achieve Cyber Essentials Plus for European government engagements; evaluate post-quantum cryptographic migration against NIST standards. |
| Autonomous operations, 2030 and beyond | Adaptive zero-trust policy engine with risk scoring; continuous compliance verification across frameworks; augmented security operations for continuous monitoring; integration with client security architectures for end-to-end trust-chain validation. |
For procurement officers: the firm can demonstrate, through configuration evidence and audit logs, that access to your data is governed by identity verification, device compliance, and least-privilege policy rather than perimeter assumptions.
For chief information security officers and security teams: the architecture is built on a recognized enterprise platform with native integration across identity, endpoint, email, and data protection rather than a patchwork of point tools.
For compliance officers: alignment with NIST SP 800-207, the CISA Zero Trust Maturity Model, the HIPAA Security Rule, and NIST SP 800-171 provides documented evidence of control implementation that maps to audit requirements.
For government contracting officers: the roadmap to CMMC Level 2, SOC 2 Type II, and FedRAMP describes a planned and resourced path to the certifications required for government engagements.
The firm implements commercially reasonable security measures aligned with recognized frameworks. No security architecture, including zero trust, can guarantee absolute protection against all threats. The firm expressly disclaims any warranty or guarantee that its systems, networks, or data will be immune from unauthorized access, cyberattack, data breach, or other security incident.
Where this document states that the firm is aligned with a framework, it means the firm has designed its controls in accordance with that framework's principles and requirements but has not undergone third-party certification or audit against it unless expressly stated otherwise. Where certifications appear on the roadmap, target dates are provided in good faith and are subject to change based on business priorities, auditor availability, and regulatory developments.
The maturity roadmap reflects the firm's plans and intentions as of the effective date. Roadmap items are forward-looking statements and are not commitments, guarantees, or obligations. The firm reserves the right to modify, defer, or reprioritize roadmap items at its sole discretion. No client, partner, or third party may rely on roadmap items as binding commitments. Specific security obligations for a client engagement are defined exclusively in the applicable Engagement Agreement.
The firm's zero-trust implementation relies on the Microsoft 365 Business Premium platform and its component services, including Entra ID, Defender, Intune, and Purview. The firm does not control the development, availability, security, or functionality of that platform and expressly disclaims liability for any security incident, service interruption, vulnerability, or data breach attributable to it or to any other third-party service.
To the maximum extent permitted by applicable law, the firm's total aggregate liability for all claims arising out of or related to the security architecture described in this document shall not exceed the amounts set forth in the applicable Engagement Agreement, or, where no Engagement Agreement exists, one hundred dollars (100 USD). The firm shall not be liable for any indirect, incidental, special, consequential, punitive, or exemplary damages arising from or related to any security incident, regardless of the theory of liability. Nothing in this section limits or excludes the firm's liability for fraud or fraudulent misrepresentation; for death or personal injury caused by negligence; or for any other liability that cannot be excluded or limited under applicable law, including under the UK Unfair Contract Terms Act 1977, the UK Consumer Rights Act 2015, or the General Data Protection Regulation.
Any dispute arising out of or relating to the contents of this document is subject to the dispute-resolution provisions of the Terms of Use, section 18.
| Version | Effective | Note |
|---|---|---|
| 1.1 | Mar 22, 2026 | Register-wide revision for legal accuracy; posture and certification language aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model. |
Related documents in this register: Identity and Access Governance, Data Protection and Classification, Encryption and Key Management, Threat Monitoring and Response, and Incident Response and Resilience.
Evaluators requiring supporting documentation, configuration evidence, or a security architecture briefing may submit a formal inquiry. Observations regarding this register are reviewed by the firm.