Your conversations never train a model. Tenant-isolated, encrypted, yours.

Security & trust

Your conversations. Your data. Your control.

ArcGlass reads the most sensitive material your company produces — what your clients actually say, to your people, in private. This page is the complete account of what we do with it, what we will never do with it, and the controls you hold.

Encrypted in transit and at rest SOC 2 Type II observation period underway — report expected August 2026 Independent penetration test completed — results available under NDA Built by engineers from Microsoft and Amazon

Every security conversation we have comes down to three questions. Here are the short answers. The rest of this page is the long ones.

01

Does your AI train on our conversations?

No. Never. Not to improve our product, not to improve anyone's model, not in aggregate, not anonymized. Your conversation data is used to serve you, and for nothing else.

02

Who can reach our data?

Only the people you authorize. Access is role-based, sign-in runs through your own identity provider, and every customer's data is isolated — enforced in the architecture, not by convention.

03

Do we still own it?

Yes, explicitly, in our Terms of Service. Export it or delete it at any time. If you leave, it leaves with you.

The lifecycle of one conversation

What happens to a conversation

A conversation enters ArcGlass and passes through five stages. Here is all of them.

01

Captured

ArcGlass only sees what you connect. You choose the calendars and mailboxes; permissions are scoped to exactly what the analysis requires, and you can revoke access at any time from your own identity provider — not by asking us.

02

Processed

We analyze the transcript. We do not retain audio or video recordings — there is no archive of your client calls sitting on our servers. The analysis extracts what matters to your business (commitments, risks, decisions, engagement) and attaches it to the account it belongs to. Transcripts themselves are text, not recordings: they are retained so your account history and briefs stay available, and they are deleted when you delete the meeting, the account, or your workspace.

03

Stored

Everything is encrypted in transit and at rest, in infrastructure we operate as a managed service. Your data is isolated from every other customer's — enforced in the application and data layer, not by convention. For organizations whose policy requires physical separation, dedicated storage is available under contract. EU data residency can be configured on request.

04

Used

Analysis feeds your account records, your team's pages, and your briefs. It never feeds a shared model, another customer's product experience, or our training data. If you'd rather the intelligence run on your own AI provider account, ArcGlass can use your foundation-model endpoints on request — so your conversation data never transits our AI account at all.

05

Deleted

Delete a single meeting, an entire account, or your whole workspace — whenever you choose. Deletion means deletion. Configurable retention windows, so most deletion happens automatically on your schedule, are available on request.

Controls

The controls you hold

Standard for every customer — not gated behind an enterprise tier.

Your data stays yours

No model training
Your conversation data is never used to train shared AI models. Ever. No exceptions, no anonymized carve-out — and we don't sell or share it.
No stored recordings
We analyze the transcript and discard the recording. No audio or video archive of your client calls exists on our servers.
You own your data
Full control and ownership, stated explicitly in our Terms of Service — not implied, not buried in a clause.
Deletion on your terms
Delete a meeting, an account, or your whole workspace; deletion is permanent. Configurable retention windows available on request.

Enterprise controls, standard

Single sign-on
Sign in through your existing identity provider — Google Workspace or Microsoft Entra ID. SAML available on request.
Role-based access control
Enterprise-grade RBAC. Decide who sees which accounts, which teams, and which briefs.
Scoped data visibility
Visibility follows the role and the reporting structure — a team lead sees their accounts, an admin sees the org. Enforced on every request.
Admin configurability
Org-wide visibility and control from a single dashboard. You decide how ArcGlass is used, not the other way round.

Infrastructure & assurance

Encrypted end to end
TLS for everything in flight; encryption at rest enabled by default on all databases and storage.
Tenant isolation
Every customer's data is isolated at the application and data layer. Dedicated storage available under contract where your policy requires physical separation.
Private networking / VPC
ArcGlass is a managed SaaS product — we don't ship a self-hosted build — but private networking and VPC connectivity are available on request for network-level control.
EU data residency
Configurable on request for organizations with regional requirements.
Bring your own model endpoint
Route AI processing through your organization's own foundation-model account — available on request.
SOC 2 Type II In progress
We're in our observation period, with the report expected August 2026. We'll share our auditor, scope, and timeline with you directly, and the report the day it's issued.
Independent penetration testing
Completed. We're happy to share the results with your security team under NDA.

Great conversations require trust.
So we built for "trust, but verify."

An intelligence product that operates invisibly doesn't deserve the access it's asking for. ArcGlass is built so participants know what's happening and admins decide how it works.

Participant transparency

Configure participant notifications to match your regional and legal requirements. Different jurisdictions, different rules, one setting.

Admin control over scope

Choose which teams, accounts, and conversation types ArcGlass touches. Turn it off for a client, a team, or a topic.

Verifiable output

Every claim ArcGlass makes links to the conversation it came from. You never have to take the analysis on faith; you can check it in one click.

Domain management

Consolidate free accounts and prevent shadow IT at scale.

Terms & policies

The paperwork, in the open

The documents behind the promises above.

Terms of Service
Including your explicit ownership of your data
Privacy Policy
What we collect and why
Data Processing Addendum (DPA)
Available on request
·
Subprocessor list
Who we use, what they do — available on request, with notice before it changes
·
Security documentation for procurement
Available on request
·
Responsible disclosure
security@arcglass.io
FAQ

Straight answers

Do you train AI models on our conversations?
No. Your data is never used to train shared AI models — not ours, not a provider's, not in anonymized or aggregated form. Analysis runs on your data to serve you, and stops there.
Do you store recordings of our calls?
No. ArcGlass analyzes the transcript and does not retain audio or video. The text transcript is retained so your account history and briefs stay available, and it is deleted when you delete the meeting, the account, or your workspace.
Where does our data live?
In infrastructure we operate as a managed service, encrypted at rest, with your data isolated from every other customer's. EU data residency can be configured on request, and dedicated storage is available under contract for organizations whose policy requires physical separation.
Can we self-host ArcGlass?
No — ArcGlass is a managed SaaS product, and we think that's the right call: it's how we ship security fixes to every customer the same day. For organizations that need network-level control, we support private networking and VPC connectivity on request.
Can we use our own AI provider instead of yours?
Yes, on request. ArcGlass can run its analysis through your organization's own foundation-model endpoints, so your conversation data never transits our AI account at all.
Are you SOC 2 certified?
Not yet — we're in our SOC 2 Type II observation period, with the report expected August 2026. We'll share our auditor, scope, and timeline with you directly, and the report the day it's issued. We've also completed an independent penetration test and can share those results with your security team under NDA.
Is our data encrypted?
Yes — in transit and at rest. TLS for everything in flight, and encryption at rest enabled by default across our databases and storage.
Who at our company can see what?
Whoever you decide. ArcGlass supports SSO (Google Workspace and Microsoft Entra ID) and role-based access control, so a team lead can be scoped to their own accounts while an admin sees the org. SCIM provisioning and SAML are available on request.
How do participants know ArcGlass is present?
You configure participant notifications to match your regional and legal requirements. Consent rules differ by jurisdiction, so we made it a setting rather than a one-size-fits-all default.
Can we delete our data?
Yes — a single meeting, an entire account, or your whole workspace, whenever you choose. Configurable retention windows, so most deletion happens automatically on your schedule, are available on request.
What happens to our data if we stop using ArcGlass?
You export it, we delete it. Your data was never ours; the Terms of Service say so explicitly.
Do you use subprocessors?
Yes, and we publish the list on request. We notify you before it changes.
Can we get a DPA?
Yes. Request it and we'll turn it around quickly — we're not going to make a mid-market company fight for a standard document.
Roadmap

What we're shipping next

A dated roadmap beats silence. Each of these is available on request while it lands.

Still not satisfied? Good.

You should interrogate anyone asking for this much access to your business. ArcGlass is built and maintained by engineers who've run infrastructure at Microsoft and Amazon — and we'd rather spend an hour on your security review than have you take our word for any of this.