Arca

Security

Arca encrypts your data at rest and in transit, never uses it to train AI models, and is SOC 2 Type II certified.

Security

Data protection
and access controls

The controls that protect your documents and workspace data.

Data privacy

Your documents and workspace data remain private and are never used to train AI models.

Encryption

All data is encrypted at rest and in transit using industry-standard encryption protocols.

Infrastructure

Arca runs on hardened cloud infrastructure with continuous monitoring and network isolation.

Access control

Role-based permissions and SSO ensure only authorized users can access sensitive research and regulatory work.

Audit logs

Every action is recorded in audit logs, so you can see who did what and when.

Responsible AI

Models run in secure processing environments designed to keep your work confidential and subject to your scientists' review.

Compliance

Compliance
& certifications

Independent audits and contractual commitments.

SOC II

SOC 2 Type II

SOC 2 Type II certified, with independent audits validating our data security, availability, and confidentiality controls.

SAML

SAML and audit trails

SAML single sign-on, with activity logs of who accessed what.

GDPR

GDPR and EU hosting

GDPR compliant, with a data processing agreement and EU Standard Contractual Clauses, and dedicated EU-hosted deployments for data that must stay in the EU.

Single tenant

Single tenant

Dedicated environments, scoped permissions, and tenant-level controls keep customer work isolated.

FAQs

Frequently asked
questions

Answers to common questions about how Arca handles and protects your data.

No. Arca does not use customer data to train general-purpose machine learning models. Your data is processed solely to deliver the services you have contracted for, as set forth in our Security Policy and Data Processing Agreement.

Arca employs encryption in transit, least-privilege access controls, continuous logging and monitoring, and third-party security tooling. Access to customer data is restricted to authorized personnel on a need-to-know basis. Our full Security Policy is publicly available, and we respond to security due diligence questionnaires upon written request.

Arca maintains a formal incident response process. In the event of a confirmed security incident affecting customer data, we will notify affected customers without undue delay, and no later than 72 hours after becoming aware of the incident, consistent with our DPA obligations and applicable law.

Yes. Arca offers a standard DPA covering processor/subprocessor relationships. You can review it at arca.inc/legal/dpa or contact us at contact@arca.inc to execute a countersigned copy.

You do. Customers retain full ownership of their data at all times. Arca holds only a limited right to process your data as necessary to deliver the services as directed by you, consistent with our Terms of Service and Data Processing Agreement.

Yes. You may request deletion of your customer data at any time. Arca will fulfill deletion requests as soon as reasonably practicable, except where further retention is required by applicable law, as described in our DPA.

Arca relies on reputable cloud service providers and subprocessors bound by security and confidentiality obligations consistent with our Security Policy. A current subprocessor list is available upon request.

Yes. Enterprise customers requiring bespoke contract terms may negotiate a Master Services Agreement. Please reach out to contact@arca.inc to begin the process.

Yes. Contact us at contact@arca.inc to schedule a personalized demo with our team.

Talk to us about deploying Arca.