Architecture Security by Design — NIS 2 & SOC 2

A sovereign SOC orchestrator designed for NIS 2 and SOC 2 compliance.

Traceability is the keystone of regulatory compliance. Akuity SOC integrates a Security by Design architecture from its design, guaranteeing absolute compliance with your NIS 2 and SOC 2 audit obligations.

Partenaire Pure Player Microsoft depuis 1990 NIS 2 Conformité Cyber Munich, Bavière (Allemagne)
Operational asymmetry

Traditional SIEMs Fail on Regulatory Compliance

Sans Akuity SOC
Avec Akuity SOC
Fragile partitioning

Application separation: security is managed in the application code, which can be bypassed in the event of a software vulnerability.

Waterproofing Database: Row-Level Security PostgreSQL intractable, essential even by the application code.

Inaccurate logs

Actions assigned to generic identifiers(admin,system). Unable to identify the responsible analyst in the event of a dispute.

Full accountability: Each JSON log contains the exact AAL2 authentication token of the analyst.

Risky exports

Reporting files sensitive to Excel vulnerabilities: malicious macros injected into unfiltered CSV exports.

Anti-injection CSV: integrated protection against the execution of malicious code in exports.

3 pillars of compliance

How Akuity SOC is revolutionizing SOC 2 and NIS 2 compliance

PostgreSQL Cryptographic Isolation (RLS)

Security at the heart of the PostgreSQL engine viaRow Level Security. Each query indexed byidx_tickets_tenantand verified according to JWT identityauth.uid(). Technically impossible to access another customer's incidents.

Immutable Audit Logs — JSON Standard

Each remedial action (REVOKE_USER_SESSIONS,ISOLATE_DEVICE,SOFT_DELETE_EMAIL) plotted by the functionlogAudit. Standardized JSON fingerprint with AAL2 identity, UTC timestamp and result.

Secure Destruction and GDPR Sovereignty

In the event of unsubscription,complete CSV archive generated then total deletiontickets, tenants and spaces in base. Exclusive accommodation in Bavaria (Germany). No data outside the EU.

Concrete case

NIS 2 Audit control in 3 steps

01

The Auditor's Request — Evidence from a 6-Month Incident

NIS 2 Audit

During an NIS 2 audit, the controller requests proof of actions taken during a critical incident dating back 6 months involving a financial management account.

02

Extraction — CSV archive generated from Settings

Secure Export

The administrator generates theconsolidated CSV archivefrom the Akuity SOC Settings page. Export in seconds, protected against injection.

03

Proven Compliance — Every Action Traced and Accounted for

NIS 2 compliant

The document lists the date (Timestamp UTC), the identity of the SOC account, the MFA requirement met (AAL2) and the success ofISOLATE_DEVICE.Full complianceregulatory requirements.

FAQ

Frequently asked questions about SOC 2 & NIS 2 compliance