1. SOC 2 Type II Trust Services Criteria
2. HIPAA Security Rule (§164.312)
3. PCI-DSS v4.0 Payment Card Industry Standard
4. NIST SP 800-207 (Zero Trust Architecture)
NIST SP 800-207 defines seven core tenets of Zero Trust Architecture. LIOP satisfies these tenets through end-to-end cryptographic and runtime verification:- Tenet 1 (All data sources are resources): Every database, file archive, or stream is treated as an isolated LIOP Data Node.
- Tenet 2 (All communication is secured regardless of network location): Private libp2p networks use Pre-Shared Keys (
libp2p/pnet), while gRPC channels enforce mTLS. - Tenet 3 (Access to resources is granted on a per-session basis): OAuth 2.1 Bearer tokens are validated per invocation with proactive 30-second refresh buffers.
- Tenet 4 (Access is determined by dynamic policy): Routing and clearance tiers enforce caller permissions prior to code execution.
- Tenet 5 (Enterprise monitors and measures integrity of assets): Mathematical ZK-Receipts confirm that returned outputs were computed honestly without host memory tampering.
- Tenet 6 (Resource authentication is dynamic and strictly enforced): Stale tokens are reactively invalidated upon receiving HTTP 401 challenge headers.
- Tenet 7 (Continuous telemetry collection): Instantaneous Prometheus metrics report node health, AST rejections, and latency distributions.