Security

Last updated: July, 2026

1. Overview

ARCY AI is currently offered as a BETA product. This page describes the practical security measures in place today.

2. Infrastructure

The ARCY AI platform runs on Amazon Web Services (AWS). Widget interactions (Chat, Teach, and Agent mode) are processed using AWS Bedrock; dashboard-side product intelligence is processed using AWS Strands Agents. Application data, session data, and behavioral signals are stored and processed within AWS infrastructure, which holds SOC 1/2/3, ISO 27001/27017/27018, and PCI DSS Level 1 certifications. See our Privacy Policy for the full breakdown of how each is used.

3. Encryption

Data is encrypted in transit using TLS. Data at rest in our primary database and object storage is encrypted using our cloud provider's standard encryption-at-rest capabilities.

4. Authentication and Access Control

Dashboard access is managed through Clerk, which is SOC 2 Type II certified. Access to production infrastructure and customer data is restricted to authorized personnel and scoped to what is necessary to operate the platform.

5. Subprocessors

We rely on a small number of subprocessors, each independently certified:

  • Clerk (authentication) — SOC 2 Type II certified, GDPR compliant
  • Amazon Web Services (infrastructure, AWS Bedrock, AWS Strands Agents) — SOC 1/2/3, ISO 27001/27017/27018, PCI DSS Level 1 certified, GDPR-ready
  • Stripe (billing) — certified PCI Service Provider Level 1

6. Reporting a Vulnerability

If you believe you have found a security vulnerability in the ARCY AI platform, please report it through our contact page so we can investigate promptly. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to address it.