{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "SAS",
  "title": "Systems Architecture Statement",
  "definitionRef": {
    "artifactId": "SAS",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "SAS.artifactDefinition.v2",
    "title": "Systems Architecture Statement"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Systems Architecture Statement",
        "Document ID": "SYS-ARCH-STATEMENT-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Engineering Lead",
        "Approver": "Security Lead",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Systems Architecture Statement",
        "Document ID: SYS-ARCH-STATEMENT-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Engineering Lead",
        "Approver: Security Lead",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example documents the Arcfield system architecture boundary, major components, data flows, trust boundaries, dependencies, control mapping and evidence needed for ISMS scope, risk and audit readiness. This statement remains binding for the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Security Lead"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Security Lead"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "statement_content",
      "title": "Systems architecture statement",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this statement is",
          "level": 1,
          "text": "This document is Arcfield's Systems Architecture Statement for the Information Security Management System (ISMS). It describes Arcfield Platform, the B2B SaaS platform for regulated fintech and health customers, as a set of named systems, trust boundaries, data locations and shared-responsibility splits that auditors can sample. It is not the ISMS Scope Statement, not the Statement of Applicability, and not a C5 Type 1 or Type 2 attest report. The Scope Statement (ISS) sets the ISMS boundary. This file explains how the in-scope service is built and operated. Cite this Document Control version from risk, supplier and evidence records. Do not copy these paragraphs into those records."
        },
        {
          "id": "scope",
          "heading": "Scope of this description",
          "level": 1,
          "text": "Use this table before you treat a component as in-scope for this architecture statement or leave it to another record.",
          "rows": [
            {
              "In this document": "Arcfield Platform production, the identity path, CI/CD, logging, backup restore, support tooling and the evidence store that can affect confidentiality, integrity or availability of in-scope customer data.",
              "Not in this document": "The ISMS organisational boundary itself. That freeze lives in ISS.",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "In this document": "Shared-responsibility splits with the cloud host, identity provider, backup provider and support platform.",
              "Not in this document": "Annex A control selection. That freeze lives in the Statement of Applicability.",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "In this document": "Data types, regions and subprocessors that carry Arcfield Platform customer configuration or support data with customer PII.",
              "Not in this document": "Live register rows, tickets or minutes. Those cite this Document Control version.",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "In this document": "Complementary user entity controls (CUEC): the process, the template customer organizations fill, and which customer-side controls stay with the customer.",
              "Not in this document": "Customer evidence packs, a C5 Type 1 or Type 2 report, a BSI audit programme, or a second Document Control table.",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this architecture statement. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "System boundary",
              "Meaning": "The set of components, accounts and data stores Arcfield can configure or for which it must produce evidence."
            },
            {
              "Term": "Trust boundary",
              "Meaning": "A crossing where identity, data or change authority leaves a Arcfield-controlled plane."
            },
            {
              "Term": "Edge",
              "Meaning": "Edge protection and the API gateway. Customer and administrator traffic both enter here, then split."
            },
            {
              "Term": "Control plane",
              "Meaning": "Identity provider tenant, CI/CD, privileged access, secrets store, policy engine, runtime orchestrator (Kubernetes) and support. These paths can change or read production without being the tenant workload."
            },
            {
              "Term": "Data plane",
              "Meaning": "Production platform plus tenant-isolated application, data-store and object-store instances."
            },
            {
              "Term": "Observability",
              "Meaning": "Logging and detection, security-event correlation, metrics and alerts, distributed tracing and the ISMS evidence repository."
            },
            {
              "Term": "CUEC",
              "Meaning": "Complementary user entity controls. Customer-side controls and evidence. This file records the process and the template; it does not hold customer evidence packs."
            },
            {
              "Term": "Shared responsibility",
              "Meaning": "A split that names what the supplier operates and what Arcfield must still evidence."
            },
            {
              "Term": "Subprocessor",
              "Meaning": "A supplier that processes Arcfield Platform customer data or authentication events under Arcfield instruction."
            },
            {
              "Term": "Evidence index",
              "Meaning": "The exportable records that prove a control on this architecture, with owner and system."
            }
          ]
        },
        {
          "id": "service_and_use_cases",
          "heading": "Service and use cases",
          "level": 1,
          "text": "Arcfield Platform is a multi-tenant SaaS used by fintech and health customers to configure regulated-customer workflows, store tenant configuration and exchange support tickets. End users authenticate through the corporate identity provider with SSO and MFA. Customer administrators manage tenant settings. Arcfield support staff access tickets and attachments through a separate support platform with time-bound roles. Engineers change production only through CI/CD. There is no standing production SSH. Use the table to keep workshop examples in the language of these use cases before they enter the live risk register.",
          "rows": [
            {
              "Use case": "Customer administrator changes tenant workflow configuration.",
              "Systems": "Edge protection, API gateway, Identity provider tenant, Tenant A application",
              "Data": "Tenant configuration",
              "Trust path": "SSO and MFA through Edge into the data plane",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Use case": "Support agent reads a ticket with a configuration export attached.",
              "Systems": "Support platform, Privileged access, Production platform",
              "Data": "Support tickets and attachments",
              "Trust path": "Time-bound support role; audited access",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Use case": "Engineer ships a signed build to production.",
              "Systems": "CI/CD, Runtime orchestrator, Policy engine, Secrets store, Production platform",
              "Data": "Build artifacts, deploy logs",
              "Trust path": "Signed deploy and network policy",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Use case": "On-call restores a tenant from backup after a failed change.",
              "Systems": "Backup and restore, Production platform, Tenant A data store",
              "Data": "Encrypted production backups",
              "Trust path": "Restore role with dual control onto Production platform",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "system_boundary_and_architecture",
          "heading": "System boundary and architecture",
          "level": 1,
          "text": "The in-scope boundary is the Arcfield Platform production account, the identity-provider tenant used for SSO and MFA, the CI/CD project that can change production, logging and detection, Backup and restore, the support platform, and the ISMS evidence repository. Marketing sites and a sandbox that cannot reach production secrets are out of this statement; they are ISS exclusions, not silent architecture gaps. Draw six trust-boundary zones: Internet (customer users and Arcfield administrators), Edge (edge protection and API gateway), Control plane (identity, CI/CD, privileged access, secrets store, policy engine, runtime orchestrator and support), Data plane (production platform plus tenant-isolated application, data-store and object-store instances), Observability (logging and detection, security-event correlation, metrics and alerts, distributed tracing and the evidence repository), and Backup (encrypted in-region restore). The named boxes below are the components in the figure. Tenant isolation is logical inside Arcfield Platform. Draw two tenant instances so the split is visible; do not invent Asset Inventory IDs or a second hosting tenant for those boxes. Do not invent a second backup region. Draw the boundary as accounts and roles, not as a vendor logo. A generic 'cloud' label is not a system.",
          "items": [
            "Customer users",
            "Arcfield administrators",
            "Edge protection",
            "API gateway",
            "Identity provider tenant",
            "CI/CD",
            "Privileged access",
            "Runtime orchestrator",
            "Secrets store",
            "Policy engine",
            "Support platform",
            "Production platform",
            "Tenant A application",
            "Tenant B application",
            "Tenant A data store",
            "Tenant B data store",
            "Tenant A object store",
            "Tenant B object store",
            "Logging and detection",
            "Security event correlation",
            "Metrics and alerts",
            "Distributed tracing",
            "ISMS evidence repository",
            "Backup and restore"
          ],
          "mermaid": "```mermaid\nflowchart TB\n  subgraph internet[\"Internet\"]\n    users[\"Customer users\"]\n    admins[\"Arcfield<br/>administrators\"]\n  end\n  subgraph edge[\"Edge\"]\n    waf[\"Edge protection\"]\n    apigw[\"API gateway\"]\n  end\n  subgraph control[\"Control plane\"]\n    idp[\"Identity<br/>provider tenant\"]\n    cicd[\"CI/CD\"]\n    pam[\"Privileged<br/>access\"]\n    orch[\"Runtime<br/>orchestrator\"]\n    secrets[\"Secrets store\"]\n    policy[\"Policy engine\"]\n    support[\"Support platform\"]\n  end\n  subgraph data[\"Data plane\"]\n    prod[\"Production<br/>platform\"]\n    appA[\"Tenant A<br/>application\"]\n    appB[\"Tenant B<br/>application\"]\n    dbA[\"Tenant A data<br/>store\"]\n    dbB[\"Tenant B data<br/>store\"]\n    storeA[\"Tenant A object<br/>store\"]\n    storeB[\"Tenant B object<br/>store\"]\n  end\n  subgraph observe[\"Observability\"]\n    logging[\"Logging and<br/>detection\"]\n    siem[\"Security event<br/>correlation\"]\n    metrics[\"Metrics and<br/>alerts\"]\n    tracing[\"Distributed<br/>tracing\"]\n    evidence[\"ISMS evidence<br/>repository\"]\n  end\n  subgraph backupzone[\"Backup\"]\n    backup[\"Backup and<br/>restore\"]\n  end\n  users -->|\"HTTPS/TLS 1.3\"| waf\n  admins -->|\"HTTPS and MFA\"| waf\n  waf -->|\"TLS 1.3\"| apigw\n  waf -->|\"privileged\"| pam\n  apigw -->|\"mTLS and JWT\"| orch\n  apigw -->|\"SSO and MFA\"| idp\n  orch -->|\"network policy\"| prod\n  prod -->|\"isolate\"| appA\n  prod -->|\"isolate\"| appB\n  appA -->|\"TLS\"| dbA\n  appB -->|\"TLS\"| dbB\n  appA -->|\"encrypted I/O\"| storeA\n  appB -->|\"encrypted I/O\"| storeB\n  support -->|\"support role\"| appA\n  pam -.->|\"audited access\"| orch\n  cicd -.->|\"signed deploy\"| orch\n  orch -.->|\"fetch secrets\"| secrets\n  orch -.->|\"policy check\"| policy\n  apigw -.->|\"access logs\"| logging\n  orch -.->|\"events\"| metrics\n  appA -.->|\"logs\"| logging\n  appB -.->|\"logs\"| logging\n  appA -.->|\"metrics\"| metrics\n  appB -.->|\"metrics\"| metrics\n  appA -.->|\"traces\"| tracing\n  appB -.->|\"traces\"| tracing\n  pam -.->|\"audit logs\"| siem\n  logging -->|\"security events\"| siem\n  metrics -.->|\"anomalies\"| siem\n  logging -->|\"evidence\"| evidence\n  dbA ==>|\"encrypted backup\"| backup\n  dbB ==>|\"encrypted backup\"| backup\n  storeA ==>|\"snapshot\"| backup\n  storeB ==>|\"snapshot\"| backup\n  classDef actor fill:#424242,stroke:#000,stroke-width:3px,color:#fff\n  classDef security fill:#E65100,stroke:#BF360C,stroke-width:3px,color:#fff\n  classDef workload fill:#2E7D32,stroke:#1B5E20,stroke-width:3px,color:#fff\n  classDef observe fill:#E65100,stroke:#BF360C,stroke-width:3px,color:#fff\n  classDef restore fill:#C62828,stroke:#B71C1C,stroke-width:3px,color:#fff\n  class users,admins actor\n  class waf,apigw,pam,secrets,policy,siem security\n  class cicd,orch,idp,support,prod,appA,appB,dbA,dbB,storeA,storeB workload\n  class logging,metrics,tracing,evidence observe\n  class backup restore\n  linkStyle 0,1,2,3,4,5,6,7,8,9,10,11,12,13 stroke:#2196F3,stroke-width:3px\n  linkStyle 14,15,16,17 stroke:#4CAF50,stroke-width:2px\n  linkStyle 18,19,20,21,22,23,24,25,26,27,28,29 stroke:#FF9800,stroke-width:2px\n  linkStyle 30,31,32,33 stroke:#F44336,stroke-width:4px\n```\nCaption: Architecture diagram (trust boundaries, tenant isolation and restore path)\n",
          "rows": [
            {
              "Asset ID": "AST-001",
              "Asset name": "Production platform",
              "Asset owner": "Service Owner",
              "Classification": "Confidential",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Asset ID": "AST-005",
              "Asset name": "Identity provider tenant",
              "Asset owner": "IT Operations Manager",
              "Classification": "Restricted",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Asset ID": "AST-011",
              "Asset name": "CI/CD",
              "Asset owner": "Engineering Lead",
              "Classification": "Confidential",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Asset ID": "AST-014",
              "Asset name": "Support platform",
              "Asset owner": "Product Systems Owner",
              "Classification": "Confidential",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Asset ID": "AST-012",
              "Asset name": "Logging and detection",
              "Asset owner": "Security Lead",
              "Classification": "Restricted",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Asset ID": "AST-013",
              "Asset name": "Backup and restore",
              "Asset owner": "Engineering Lead",
              "Classification": "Confidential",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            },
            {
              "Asset ID": "AST-003",
              "Asset name": "ISMS evidence repository",
              "Asset owner": "ISMS Manager",
              "Classification": "Internal",
              "Evidence reference": "SAS-EV-001",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "architecture_reading",
          "heading": "How to read the diagram",
          "level": 1,
          "text": "The figure is the system-boundary drawing for this Document Control version. Use these notes with the figure. Do not treat a vendor logo as a system. Dashed frames are trust boundaries.",
          "groups": [
            {
              "heading": "Trust boundaries",
              "level": 2,
              "items": [
                "Internet: Customer users and Arcfield administrators outside the Arcfield Platform accounts.",
                "Edge: Edge protection and the API gateway. Customer traffic and administrator traffic both enter here, then split.",
                "Control plane: Identity provider tenant, CI/CD, privileged access, secrets store, policy engine, runtime orchestrator and support.",
                "Data plane: Production platform plus Tenant A/B application, data-store and object-store instances.",
                "Observability: Logging and detection, security-event correlation, metrics and alerts, distributed tracing and the ISMS evidence repository.",
                "Backup: Backup and restore in-region, in the same EU region as production. There is no second backup region in this freeze."
              ]
            },
            {
              "heading": "Data flows and encryption",
              "level": 2,
              "items": [
                "Blue (solid): encrypted production paths. HTTPS/TLS 1.3 from Internet to Edge, TLS 1.3 into the API gateway, mTLS and JWT to the runtime orchestrator, TLS and encrypted I/O inside the data plane.",
                "Green (dashed): authenticated control-plane paths. Signed deploy, fetch secrets, policy check, and audited privileged access to the runtime orchestrator.",
                "Orange (dashed): observability streams. Access logs from the API gateway, application logs and traces, metrics, privileged-access audit logs into security-event correlation, and evidence into the ISMS evidence repository.",
                "Red (thick): encrypted in-region backup and snapshots from tenant data stores and object stores. Restore is onto Production platform; that return path is not drawn up the page."
              ]
            },
            {
              "heading": "Component colours",
              "level": 2,
              "items": [
                "Grey: external actors (Customer users, Arcfield administrators).",
                "Orange: security and control components (Edge protection, API gateway, privileged access, secrets store, policy engine, security-event correlation).",
                "Green: in-scope runtime (CI/CD, runtime orchestrator, identity provider tenant, support platform, production platform, tenant application, data-store and object-store instances).",
                "Orange (observability): logging and detection, metrics and alerts, distributed tracing, ISMS evidence repository.",
                "Red: Backup and restore."
              ]
            },
            {
              "heading": "Tenant isolation",
              "level": 2,
              "items": [
                "Each tenant has its own application, data-store and object-store instance inside the data plane.",
                "The runtime orchestrator deploys with network policy. Isolation is logical inside Arcfield Platform, not a second unnamed hosting tenant.",
                "RBAC and tenant keys prevent cross-tenant access. Cross-tenant access is not a path on this figure."
              ]
            },
            {
              "heading": "Data location",
              "level": 2,
              "items": [
                "Primary processing and backup stay in the same EU region as Production platform. All in-scope data remains in the EU.",
                "This freeze does not draw a second backup region or geo-replication node."
              ]
            },
            {
              "heading": "Access control",
              "level": 2,
              "items": [
                "Customer users reach Arcfield Platform only through Edge protection and the API gateway with TLS 1.3, then SSO and MFA at the identity provider tenant.",
                "Arcfield administrators enter at Edge and continue on the privileged-access path with MFA. There is no standing production SSH.",
                "Privileged sessions are audited into security-event correlation."
              ]
            }
          ]
        },
        {
          "id": "shared_responsibility",
          "heading": "Shared responsibility",
          "level": 1,
          "text": "Record each split before you accept residual risk on a supplier. Arcfield remains accountable for Arcfield Platform even where a provider operates the layer.",
          "rows": [
            {
              "Layer": "Physical data centre and host hypervisor",
              "Provider operates": "Cloud host",
              "Arcfield still evidences": "Region choice, account guardrails, encryption configuration",
              "Evidence reference": "SAS-EV-002",
              "Evidence status": "Complete"
            },
            {
              "Layer": "Identity and MFA",
              "Provider operates": "Identity-provider service availability",
              "Arcfield still evidences": "SSO policy, MFA enforcement, joiner/mover/leaver reviews",
              "Evidence reference": "SAS-EV-002",
              "Evidence status": "Complete"
            },
            {
              "Layer": "Support platform",
              "Provider operates": "SaaS availability and platform patching",
              "Arcfield still evidences": "Role design, attachment handling, DPA and access reviews",
              "Evidence reference": "SAS-EV-002",
              "Evidence status": "Complete"
            },
            {
              "Layer": "Backup storage",
              "Provider operates": "Object durability",
              "Arcfield still evidences": "Encryption keys, restore tests, access to the restore role",
              "Evidence reference": "SAS-EV-002",
              "Evidence status": "Complete"
            },
            {
              "Layer": "Application logic and tenant isolation",
              "Provider operates": "Not delegated",
              "Arcfield still evidences": "Arcfield Platform code, RBAC, change and logging",
              "Evidence reference": "SAS-EV-002",
              "Evidence status": "Complete"
            },
            {
              "Layer": "Complementary user entity controls (CUEC)",
              "Provider operates": "Not a Arcfield platform control",
              "Arcfield still evidences": "The CUEC process and template in the next chapter. Customer evidence packs are not in this file.",
              "Evidence reference": "SAS-EV-002",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "cuec",
          "heading": "Complementary user entity controls",
          "level": 1,
          "text": "Arcfield operates Arcfield Platform. Customer organizations and their administrators remain responsible for complementary user entity controls (CUEC). This chapter records the CUEC process and the template customer organizations fill. It does not hold customer evidence. Completed packs stay with the customer; a pointer lives in the evidence repository. The auditor samples both on request.",
          "items": [
            "Arcfield publishes a CUEC list with this Document Control version. The list names customer-side identity, local devices, who may grant workforce access, and records the customer retains.",
            "Each customer organization fills that list with its own evidence: policies, screenshots, access-review extracts or audit reports.",
            "Arcfield checks submitted CUEC packs for completeness and plausibility. Arcfield does not accept the customer's residual risk in this file.",
            "Completed packs are archived at the customer and, on request, a copy pointer is held for the auditor. Do not paste customer screenshots or policies into this statement."
          ],
          "rows": [
            {
              "CUEC": "Workforce identity at the customer",
              "Customer still evidences": "Joiners, movers and leavers for customer-owned directories that federate into Arcfield Platform.",
              "Arcfield still evidences": "SSO and MFA on the Arcfield Platform identity-provider tenant.",
              "Evidence reference": "SAS-EV-007",
              "Evidence status": "Complete"
            },
            {
              "CUEC": "MFA on customer-controlled endpoints",
              "Customer still evidences": "Device and authenticator policy for customer staff who open Arcfield Platform.",
              "Arcfield still evidences": "MFA required on the Arcfield Platform login path.",
              "Evidence reference": "SAS-EV-007",
              "Evidence status": "Complete"
            },
            {
              "CUEC": "Who may request production support access",
              "Customer still evidences": "Named customer contacts who may open privileged support requests.",
              "Arcfield still evidences": "Time-bound support roles; no standing production SSH.",
              "Evidence reference": "SAS-EV-007",
              "Evidence status": "Complete"
            },
            {
              "CUEC": "Customer-held exports and local records",
              "Customer still evidences": "Retention and deletion of configuration exports the customer downloads.",
              "Arcfield still evidences": "Retention in Arcfield Platform stores named in the data-locations table.",
              "Evidence reference": "SAS-EV-007",
              "Evidence status": "Complete"
            },
            {
              "CUEC": "Customer-side backup of downloaded files",
              "Customer still evidences": "Backup of files the customer stores outside Arcfield Platform.",
              "Arcfield still evidences": "Encrypted in-region backup of Arcfield Platform production.",
              "Evidence reference": "SAS-EV-007",
              "Evidence status": "Complete"
            },
            {
              "CUEC": "Acceptable use for customer administrators",
              "Customer still evidences": "Local acceptable-use and sanction rules for tenant administrators.",
              "Arcfield still evidences": "RBAC and audit logging inside Arcfield Platform.",
              "Evidence reference": "SAS-EV-007",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "data_locations",
          "heading": "Data types, locations and jurisdiction",
          "level": 1,
          "text": "Name the information class, the store and the jurisdiction. Do not hide customer data behind a product name. Review this table when a new pipeline or region is proposed.",
          "rows": [
            {
              "Data type": "Customer PII and limited payment metadata (no card data)",
              "Store": "Tenant A data store / Tenant B data store",
              "Region / jurisdiction": "EU cloud region; card data is not stored",
              "Retention trigger": "Tenant offboarding plus legal hold"
            },
            {
              "Data type": "Tenant configuration and workflow records",
              "Store": "Tenant A data store / Tenant B data store",
              "Region / jurisdiction": "EU cloud region, Arcfield processing as controller/processor per DPA",
              "Retention trigger": "Tenant offboarding plus legal hold",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Data type": "Support tickets and attachments",
              "Store": "Support platform",
              "Region / jurisdiction": "Provider EU region; Arcfield DPA in force",
              "Retention trigger": "Ticket close plus published retention",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Data type": "Authentication and privileged-access logs",
              "Store": "Logging and detection",
              "Region / jurisdiction": "EU cloud region",
              "Retention trigger": "Security log retention rule",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Data type": "Security events and traces",
              "Store": "Security event correlation / Distributed tracing",
              "Region / jurisdiction": "EU cloud region",
              "Retention trigger": "Security log retention rule",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Data type": "Encrypted production backups",
              "Store": "Backup and restore",
              "Region / jurisdiction": "Same EU region as Production platform",
              "Retention trigger": "Backup retention and restore-test cycle",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Data type": "ISMS documented information",
              "Store": "ISMS evidence repository",
              "Region / jurisdiction": "EU, Arcfield-controlled",
              "Retention trigger": "Document Control next review date",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "subprocessors",
          "heading": "Subprocessors and suppliers",
          "level": 1,
          "text": "List every supplier that can see Arcfield Platform customer data, authentication events or production change authority. An unnamed integration is an unnamed audit boundary.",
          "rows": [
            {
              "Supplier": "Cloud host",
              "Service": "Compute, network, managed database",
              "Data or authority": "Encrypted data at rest, account IAM",
              "Record": "SINV / DPA-CLOUD-2026",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Supplier": "Identity provider",
              "Service": "SSO and MFA",
              "Data or authority": "Workforce identity events",
              "Record": "SINV / DPA-IDP-2026",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Supplier": "Support platform",
              "Service": "Ticketing",
              "Data or authority": "Tickets and attachments",
              "Record": "SINV / DPA-SUPPORT-2026",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Supplier": "Backup provider",
              "Service": "Object backup",
              "Data or authority": "Encrypted backups, restore API",
              "Record": "SINV / DPA-BACKUP-2026",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            },
            {
              "Supplier": "External penetration-test supplier",
              "Service": "Annual test",
              "Data or authority": "Scoped production findings",
              "Record": "SINV / NDA-PENTEST-2026",
              "Evidence reference": "SAS-EV-003",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "organization_and_roles",
          "heading": "Organization and roles",
          "level": 1,
          "text": "Architecture decisions that change residual risk are not a team habit. The Engineering Lead owns Arcfield Platform runtime and CI/CD change. The Security Lead owns detection rules, privileged-access review and this statement. The ISMS Manager freezes Document Control versions and escalates unnamed trust paths. Top Management approves this statement. Appointments themselves are IRAR rows that cite this version. If a new data flow can leave the EU region or a new subprocessor can see tenant data, the Security Lead updates this file before the change lands."
        },
        {
          "id": "controls",
          "heading": "Controls on this architecture",
          "level": 1,
          "text": "Use this table to find the control and the evidence on the named path. Do not copy SoA selections into this file; cite the SoA version.",
          "rows": [
            {
              "Control area": "Access",
              "Architecture rule": "Customer users enter through Edge protection and the API gateway; SSO and MFA at the identity provider tenant; privileged access with MFA and no standing production SSH.",
              "Evidence": "UAI access review; identity-provider MFA export; privileged-access audit logs",
              "Evidence status": "Complete"
            },
            {
              "Control area": "Change",
              "Architecture rule": "Production changes only through signed CI/CD, policy check and network policy on the runtime orchestrator.",
              "Evidence": "Pipeline log; change ticket citing this Document Control version",
              "Evidence status": "Complete"
            },
            {
              "Control area": "Logging",
              "Architecture rule": "API gateway access logs, tenant application logs and traces, metrics and privileged-access audit logs land in logging and detection and security-event correlation.",
              "Evidence": "LMP sample; detection rule export",
              "Evidence status": "Complete"
            },
            {
              "Control area": "Patch",
              "Architecture rule": "Runtime images and dependencies on Production platform follow the published patch window.",
              "Evidence": "Image build log; vulnerability ticket",
              "Evidence status": "Complete"
            },
            {
              "Control area": "Incident",
              "Architecture rule": "On-call uses logging and detection, security-event correlation and the IR procedure.",
              "Evidence": "Incident record; timeline export",
              "Evidence status": "Complete"
            },
            {
              "Control area": "BCM",
              "Architecture rule": "Encrypted backups in-region on Backup and restore; restore tested onto Production platform.",
              "Evidence": "Restore-test record; backup job log",
              "Evidence status": "Complete"
            },
            {
              "Control area": "Privacy",
              "Architecture rule": "New pipelines that leave a tenant data store trigger DPIA and a row in this statement.",
              "Evidence": "DPIA; DPA; this table's next version",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "evidence_index",
          "heading": "Evidence index",
          "level": 1,
          "text": "Keep one exportable record per row. A chat message is not evidence. Cite this Document Control version from each record.",
          "rows": [
            {
              "Evidence ID": "SAS-EV-001",
              "Record": "Architecture diagram (trust boundaries, tenant isolation and restore path)",
              "Owner": "Engineering Lead",
              "System": "ISMS evidence repository",
              "Evidence reference": "SAS-EV-001"
            },
            {
              "Evidence ID": "SAS-EV-002",
              "Record": "Shared-responsibility matrix",
              "Owner": "Security Lead",
              "System": "This file plus SINV",
              "Evidence reference": "SAS-EV-002"
            },
            {
              "Evidence ID": "SAS-EV-003",
              "Record": "Subprocessor and DPA list",
              "Owner": "Supplier Manager",
              "System": "SINV",
              "Evidence reference": "SAS-EV-003"
            },
            {
              "Evidence ID": "SAS-EV-004",
              "Record": "Access review for production and support roles",
              "Owner": "Security Lead",
              "System": "Privileged access / UAI",
              "Evidence reference": "SAS-EV-004"
            },
            {
              "Evidence ID": "SAS-EV-005",
              "Record": "CI/CD protected-branch and signing policy",
              "Owner": "Engineering Lead",
              "System": "CI/CD",
              "Evidence reference": "SAS-EV-005"
            },
            {
              "Evidence ID": "SAS-EV-006",
              "Record": "Backup restore test",
              "Owner": "Engineering Lead",
              "System": "Backup and restore",
              "Evidence reference": "SAS-EV-006"
            },
            {
              "Evidence ID": "SAS-EV-007",
              "Record": "CUEC process, template and completeness check",
              "Owner": "Security Lead",
              "System": "This file plus ISMS evidence repository pointer",
              "Evidence reference": "SAS-EV-007"
            }
          ]
        }
      ],
      "contentType": "statement_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope systems named here are Asset Inventory rows. Do not keep a second inventory.",
              "href": "AI_Asset_Inventory.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DPIA Data Protection Impact Assessment (Dual Compliance, ISO 27001 & EU Data Act)",
              "href": "DPIA_Data_Protection_Impact_Assessment_Plan.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory (Secure Engineering, Access Control & Identity Management)",
              "href": "UAI_Users_and_Access_Inventory.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "CR Context Register (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "CR_Context_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "CSRM Cloud Shared Responsibility Matrix (Secure Operations, Cloud Security Posture Management (CSPM))",
              "href": "CSRM_Cloud_Shared_Responsibility_Matrix.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "includes": [
    {
      "from": "AI",
      "keys": [
        "AST-001",
        "AST-005",
        "AST-011",
        "AST-014",
        "AST-012",
        "AST-013",
        "AST-003"
      ],
      "nodes": {
        "idp": "AST-005",
        "cicd": "AST-011",
        "support": "AST-014",
        "prod": "AST-001",
        "logging": "AST-012",
        "backup": "AST-013",
        "evidence": "AST-003"
      }
    }
  ],
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Statement",
    "role": "Binding Arcfield Platform ISMS statement in the surveillance window"
  }
}
