How your data is protected
You are putting client confidences into Arc. This page states what happens to them.
Where your data is held
- All customer data is stored in the United Kingdom, on Amazon Web Services.
- Encrypted in transit and at rest.
- The database is not reachable from the public internet. Only the application can connect to it.
- Passwords are hashed and are never readable by the application. Credentials for connected tools are sealed with authenticated encryption before storage.
Who can reach it
- Your team. Access is scoped to your company and re-checked on every read and write, at the server. It is not enforced by hiding things in the interface.
- The clients you send links to. They see the decisions you sent them, and nothing else.
- Us, only to provide support. Every administrative access to customer data is written to an append-only audit log.
Client links
A client link is a bearer link: whoever holds it can view and respond to the decisions it covers, without an account. Only a hash of each link is stored, so a link cannot be recovered from our systems, and links expire. Treat one as you would a key — send it to the person it is for, and re-send rather than forward.
What the AI does, and does not do
- Text you import is processed to extract the decisions it contains. That is its only purpose.
- Your content is not used to train AI models.
- Imported conversations are treated as untrusted input and isolated before processing, so instructions hidden in a transcript cannot make Arc act on them.
- Nothing is processed unless you import it. Reviewing, confirming, exporting and printing involve no AI processing.
- Every extracted decision is a draft for you to review. Nothing reaches a client without your approval.
The record itself
- It is append-only. A decision that changes is superseded and both versions remain, with their dates and sources. Nothing is silently rewritten.
- Evidence attaches to a decision. Arc is not a file store; material enters only as evidence of something decided.
- You can take it with you. Export the full record at any time. It is not held in a format only we can read.
How we build
- Changes are reviewed and pass an automated test suite before release.
- Tenant isolation and the record’s integrity rules are covered by tests that run on every change.
- Deployment credentials are short-lived and issued per deployment. Secrets are held in a managed secret store, never in source control.
- The application and its infrastructure undergo a full security review covering access control, tenant isolation, dependencies and configuration, repeated after significant change.
Reporting a vulnerability
Email hello@archq.co.uk with enough detail to reproduce the issue. We acknowledge within two business days and will keep you updated until it is resolved. Please give us a reasonable opportunity to fix an issue before disclosing it publicly. We will not pursue legal action against anyone acting in good faith under this section.
Compliance
Arc holds no third-party security certification. If your organisation requires evidence for its own compliance process, ask us and we will complete a security questionnaire.
How we handle personal data, and the basis on which we process it, is set out in the privacy policy and the Data Processing Agreement.