arctex

Platform Security

Security

A straightforward account of how your business's data is isolated and protected — not a list of buzzwords. Last updated 2026-10-08.

Tenant isolation

Every business's data is isolated at the database level: the platform's production database has row-level security enabled on every table, which denies access by default to anything other than the application's own server-side connection. On top of that, every data query in the application itself is scoped to the business making the request — a record belonging to another business is never returned, not even as an error that reveals it exists.

Credential storage

Third-party API keys and OAuth tokens you connect (calendars, social accounts, payment providers) are encrypted at rest using AES-256-GCM before being stored, and decrypted only at the moment they're actually used to make a request on your behalf.

Authentication

Login attempts are rate-limited across both the account and the network address making them, which slows down credential-guessing without ever permanently locking a real user out. Two-factor authentication is available and enforced for the platform's own highest-privilege accounts.

Audit logging

Sensitive actions — permission changes, data exports, billing changes, and more — are recorded in an audit log tied to the account that performed them.

AI features

When you use an AI agent feature, it can only read and act on your own business's data — every tool it uses is scoped the same way every other part of the platform is, and it cannot query another business's records. See our AI Policy for how AI features handle data more broadly.

Reporting a security issue

If you believe you've found a security vulnerability, email security@arctex.ai. Please don't test against another business's account or data without permission.

This page describes current practice and is not a certification. We do not claim certifications (such as SOC 2) that have not actually been examined and issued.