Security & compliance
ArcGlass processes customer conversations, so security is a first-order concern, not an afterthought. This section documents how your data is protected, handled, retained, and shared — the information a security or procurement review typically needs.
At a glance
- Encryption. Data is encrypted in transit (TLS) and at rest.
- Tenant isolation. Each organization's data is logically isolated and
scoped by
org_idon every query. - Access control. Role-based permissions with a single capability map; identity always comes from the verified session. See Members & Roles.
- No training on your data. Your conversations are never used to train shared AI models.
- No stored recordings by default. With Listen, audio stays on the device; ArcGlass processes transcripts, not raw recordings.
In this section
- Data security — encryption, isolation, access, and infrastructure.
- Data privacy & retention — what we process, recording consent, retention, and deletion.
- Subprocessors — the vendors that process data on our behalf.
Certifications
ArcGlass is completing its SOC 2 Type II examination. Independent penetration testing has been performed, with results available under NDA. A Data Processing Addendum (DPA) and EU data residency are available on request. For the current, authoritative trust posture, see the Security page; to request documents, use contact.