Security & Control

    Your agents operate inside boundaries you define.

    arcta carries company context into the workflow without taking ownership of the environment, data, decisions, or operating memory.

    Get in touch

    Five boundaries of control

    arcta operates the system. Your company remains the authority.

    01
    Deployment boundary

    Your environment

    Deploy into customer-controlled, tenant-approved infrastructure—not another external system of record.

    02
    Data boundary

    Your data

    Files, prompts, outputs, and operating evidence remain engagement-scoped, encrypted, and are not used to train shared models.

    03
    Action boundary

    Your authority

    Existing identity, permissions, ownership, approval policy, and separation of duties determine who can view, draft, approve, and act.

    04
    Evidence boundary

    Your lineage

    Sources, Canon changes, evaluations, approvals, reviewer handoffs, and system actions remain attributable and reviewable.

    05
    Ownership boundary

    Your Canon

    Operating knowledge, standards, evaluations, corrections, and outcome history remain a portable company asset.

    Agent governance

    Control is part of the workflow, not a review added afterward.

    Permissions

    Role and system permissions establish what an agent can see and which tools it can use.

    Approval gates

    Consequential actions stop at agreed human-review and approval boundaries.

    Provenance

    Sources, workflow state, evaluations, and review history remain available for inspection.

    Evaluation

    Reviewed failures and corrections become durable tests and operating guidance instead of disappearing in a thread.

    Security that fitsyour work.

    Private data, controlled access, human review, and evidence from day one.

    Does arcta use customer data to train shared models?

    No. Client files, prompts, outputs, and operating evidence remain engagement-scoped and are not used to train shared models.

    How is data protected?

    Data is protected with AES-256-GCM at rest, TLS 1.3 in transit, and KMS-backed envelope encryption.

    Who can authorize an agent action?

    The customer's existing permissions, ownership rules, approval policy, and separation of duties determine who can view, draft, approve, and act.

    Can models or interfaces be replaced?

    Yes. The company-specific operating memory and control model do not depend on a single model or interface.

    What is arcta's SOC 2 status?

    SOC 2 Type I readiness work is in progress. arcta does not present readiness work as a completed attestation.

    How do I report a vulnerability?

    Use the contact page to report a vulnerability and include enough detail for the team to reproduce and assess it.