Legal
Security
Last updated 2026-09-28
This page summarizes the security practices we apply to the ArQonnect platform and customer data. It is an overview for due diligence (including payment and cloud reviews) and does not replace contractual commitments in our Terms, Privacy Policy, or Data Processing Agreement. ArQonnect does not claim third-party certifications (such as SOC 2 or ISO 27001) unless we publish a specific attestation document.
1. Scope
These practices apply to https://arqonnect.io, https://app.arqonnect.io, https://api.arqonnect.io, and the infrastructure that stores and processes Customer Data on behalf of our subscribers.
2. Infrastructure & hosting
- Production workloads run on managed cloud infrastructure (primarily Amazon Web Services) with database hosting in Asia-Pacific by default unless otherwise agreed in an Enterprise order form.
- Media and attachments are stored in private object storage; access uses time-limited signed URLs.
- Encrypted database backups are retained for up to 30 days, then overwritten.
3. Encryption & data protection
- TLS 1.2 or higher for data in transit between clients, our APIs, and sub-processors.
- AES-256-GCM at rest for integration credentials, channel-provider tokens, and model API keys.
- Per-tenant data isolation enforced in application logic and database queries so one organization's data is not exposed to another.
4. Access control
- Role-based access for customer users within each organization.
- Separation between ArQonnect platform staff access and customer dashboard access; staff access is limited to what is needed for support and operations.
- Multi-factor authentication enforced for ArQonnect staff; customers can require MFA for their organization where supported in the dashboard.
5. Monitoring, logging & incidents
- Platform logs for security and reliability are retained for up to 90 days, then deleted (see Privacy Policy).
- We investigate suspected unauthorized access and notify affected customers without undue delay when a personal-data breach is confirmed, in line with our DPA.
- Error monitoring may be enabled via a sub-processor (for example Sentry) to diagnose production faults; see Privacy Policy §8.
6. Vulnerability management
- Regular vulnerability scanning of internet-facing services.
- Responsible disclosure: report suspected vulnerabilities to Compliance@arqonnect.io. Do not perform disruptive testing without written authorization.
7. Payments
We do not store full card numbers on ArQonnect servers. Subscription payments are processed by a PCI-DSS-compliant Merchant of Record; only limited billing metadata (such as last four digits, country, and subscription status) is retained in our systems. See Terms §3 and the Refund Policy.
8. Your responsibilities
- Protect dashboard credentials and rotate access when team members leave.
- Only upload knowledge-base and messaging content you have the right to use.
- Configure channel integrations using Meta-approved apps and comply with platform policies.
9. Contact
Security questions and responsible disclosure: Compliance@arqonnect.io.
