Security
Last updated: July, 2026
1. Overview
ARCY AI is currently offered as a BETA product. This page describes the practical security measures in place today.
2. Infrastructure
The ARCY AI platform runs on Amazon Web Services (AWS). Widget interactions (Chat, Teach, and Agent mode) are processed using AWS Bedrock; dashboard-side product intelligence is processed using AWS Strands Agents. Application data, session data, and behavioral signals are stored and processed within AWS infrastructure, which holds SOC 1/2/3, ISO 27001/27017/27018, and PCI DSS Level 1 certifications. See our Privacy Policy for the full breakdown of how each is used.
3. Encryption
Data is encrypted in transit using TLS. Data at rest in our primary database and object storage is encrypted using our cloud provider's standard encryption-at-rest capabilities.
4. Authentication and Access Control
Dashboard access is managed through Clerk, which is SOC 2 Type II certified. Access to production infrastructure and customer data is restricted to authorized personnel and scoped to what is necessary to operate the platform.
5. Subprocessors
We rely on a small number of subprocessors, each independently certified:
- Clerk (authentication) — SOC 2 Type II certified, GDPR compliant
- Amazon Web Services (infrastructure, AWS Bedrock, AWS Strands Agents) — SOC 1/2/3, ISO 27001/27017/27018, PCI DSS Level 1 certified, GDPR-ready
- Stripe (billing) — certified PCI Service Provider Level 1
6. Reporting a Vulnerability
If you believe you have found a security vulnerability in the ARCY AI platform, please report it through our contact page so we can investigate promptly. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to address it.