Security & compliance

Your warehouse stays yours. The answer shows its work.

Arcus is designed for read-only warehouse access, tenant-scoped application data, SQL validation, and traceable answers. This page describes the posture we can stand behind today. SOC 2 Type II is in progress; Arcus does not claim completed certification, public uptime SLAs, or downloadable audit reports yet.

Data flow

Narrow access, tenant-scoped by default.

Read-only connectors

v1 supports BigQuery, Snowflake, and Postgres. Customers provide scoped credentials; Arcus validates generated SQL before execution.

Three-layer answers

Every answer is expected to include narrative, visualization, and raw data or preview rows with source attribution so teams can verify the result.

Tenant isolation

Routes, records, logs, and queries are designed around tenant IDs. Cross-tenant access is treated as a release-blocking security issue.

What we store

Enough to render and audit.

  • Application dataUsers, tenants, memberships, conversations, messages, chart specs, data previews, query logs, usage events, and audit events.
  • Connection secretsWarehouse credentials are encrypted and never returned to the browser after creation.
  • Warehouse dataArcus reads from the customer warehouse and stores only what is needed for the answer, trace, preview, and agreed retention behavior.
  • Model promptsPrompt and model-provider handling is disclosed during security review and should be covered in the customer agreement.
Controls status

Plain status beats fake badges.

  • SOC 2 Type IIIn progress. No completed SOC 2 report, bridge letter, or badge is claimed publicly.
  • Uptime SLANo public SLA for v1. Any uptime or support commitment must be in the signed order form.
  • Direct SaaS connectorsRoadmap. v1 expects SaaS data to be loaded into the customer warehouse before Arcus queries it.
  • Security artifactsCurrent materials are available by request. Pen-test reports and certifications are shared only if and when they exist.

Have a questionnaire?

Send it to security@usearcus.ai. We answer from the current implementation and mark anything that is roadmap, contract-dependent, or not yet available.

Send questionnaire