Last updated: June 2025
Security is a core principle at Arc. We take reasonable and appropriate technical and organizational measures to protect information against unauthorized access, alteration, disclosure, or destruction.
All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Data at rest is encrypted using industry-standard AES-256 encryption where applicable.
Access to customer and operational data is restricted to Arc personnel on a need-to-know basis. We enforce strong authentication, including multi-factor authentication (MFA), for internal systems and cloud infrastructure.
Our services run on reputable cloud infrastructure providers that maintain their own rigorous security programs, including SOC 2 and ISO 27001 certifications. We regularly review and harden our configurations against known attack vectors.
We keep software dependencies up to date and monitor for known vulnerabilities. We conduct periodic security reviews of our codebase and infrastructure. Critical issues are prioritized and remediated promptly.
In the event of a security incident, we have procedures to contain, investigate, and remediate the issue. Affected users will be notified in accordance with applicable laws and regulations.
If you discover a potential security vulnerability in our systems, please report it to us at hello@arclens.space before disclosing it publicly. We will investigate all legitimate reports and respond as quickly as possible. We appreciate the security community's efforts to help keep Arc safe.
While we take security seriously, no system can be guaranteed 100% secure. We encourage you to use strong, unique passwords and to report any suspicious activity related to your interactions with Arc.
Security questions or disclosures: hello@arclens.space.