Trust & Security

How we protect your business data. Plain-English answers, no marketing fluff.

What's in place today

Active
Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. All traffic served over HTTPS via Cloudflare.

Active
Row-level security

Access enforced at the database layer, not the app layer. Each query is scoped to your workspace and your role automatically.

Active
Role-based access control

Workspace owners, admins, and members each see only what they're allowed to. Roles live in a dedicated table to prevent privilege escalation.

Active
PCI-compliant payments

Card data never touches our servers. Payments are handled by Paddle, a PCI-DSS Level 1 merchant of record.

Active
Daily backups

Database is backed up automatically every 24 hours with point-in-time recovery available.

Active
EU & US hosting

GDPR-compliant infrastructure. Data residency available in EU or US regions.

Active
Audit logging

Sensitive actions - sign-ins, role changes, billing events, data exports - are recorded in an append-only audit log.

Active
Leaked-password protection

Passwords are checked against the Have I Been Pwned database at signup and on change. Compromised passwords are rejected.

Active
Two-factor authentication

Optional TOTP-based 2FA via any authenticator app (Google Authenticator, 1Password, Authy). Enrol from Settings → Security.

Active
Security alerts by email

We email you on new sign-ins from unfamiliar IPs, password changes, and 2FA enable/disable so account takeovers are visible immediately.

Active
Self-serve data export

Download a JSON copy of your profile and the records you created at any time from Settings → Security. GDPR / DSAR compliant.

Active
Self-serve account deletion

Delete your account from Settings → Security. Solo workspaces are removed; backups are purged within 90 days.

Available on request

For teams with internal security or procurement requirements.

SAML Single Sign-On

Sign in via Okta, Azure AD / Entra ID, Google Workspace, or any SAML 2.0 provider. Available on request for Pro and Advisory plans.

Data Processing Agreement

GDPR-compliant DPA available for all paid plans. Email us and we'll send it the same day.

Workspace audit log export

Owners can export the workspace audit log as CSV for internal compliance reviews.

Subprocessors

Third-party services we use to deliver oI. Each has its own security controls.

ServicePurposeRegion
SupabaseDatabase, authentication, storageEU / US
CloudflareCDN, DDoS protection, edge runtimeGlobal
PaddlePayments, tax, invoicing (Merchant of Record)Global
ResendTransactional emailUS / EU
LovableApplication hostingEU / US

Frequently asked

Are you SOC 2 certified?

Not yet. SOC 2 Type I is on our roadmap and will be pursued once enterprise demand justifies the audit cost. Our underlying infrastructure providers (Supabase, Cloudflare, Paddle) are SOC 2 Type II certified, and our security controls are designed to be SOC 2-ready.

Where is my data stored?

In encrypted databases on AWS infrastructure managed by Supabase. EU and US regions are available. Email us before signup if you need a specific region.

Can I export or delete all my data?

Yes. You can export your data anytime from Settings. Account deletion permanently removes your data within 30 days, with backups purged within 90 days.

How do I report a security issue?

Email security@arcset.ca. We respond within one business day.