Security at Arvad

How we protect your data, code, and infrastructure: encryption, access control, per-job sandboxes, monitoring, and incident response.

Our security commitment

You trust us with IP and production apps. Security sits in every layer of the platform, from sandbox to credential broker.

We update controls as threats change, publish status honestly, and welcome responsible reports from researchers.

Architecture

How each project codebase stays isolated

Each project run uses that project's codebase in its own sandbox. SPIFFE identity, a credential broker, and fail-closed network policy keep source, secrets, and tokens from crossing tenants or jobs. No ambient secrets in the sandbox. No casual staff access to working trees.

How project codebases are isolated

Security controls

Data encryption

Encryption in transit and at rest for platform data

  • TLS 1.3 for network traffic
  • AES-256 for data at rest
  • Encrypted backups with separate key management
  • Sensitive credentials stay outside the sandbox; broker mints scoped access

Authentication and authorization

Access control and identity checks across the workspace

  • Multi-factor authentication (MFA)
  • OAuth 2.0 and OpenID Connect
  • Role-based access control (RBAC)
  • API key rotation and management
  • Sessions with automatic timeout

Infrastructure security

Cloud infrastructure controls and workload isolation

  • Per-job sandboxes with no ambient credentials
  • SPIFFE identity and fail-closed credential broker
  • Network segmentation and deny-by-default egress
  • Automated security patching
  • Regular penetration testing

Monitoring and detection

Threat detection, alerting, and response

  • Continuous security monitoring and alerting
  • Intrusion detection
  • Anomaly detection on security signals
  • Audit logging of security-relevant events
  • Security incident response path

Code security

Scanning and secure defaults on generated code

  • Automated vulnerability scanning
  • OWASP Top 10-oriented defaults in generated code
  • Dependency vulnerability checking
  • Code signing and verification
  • Secure coding checks in the build path

Incident response

Defined response for security events

  • Dedicated security incident response contacts
  • Incident notification within 72 hours
  • Post-incident analysis and reporting
  • Ongoing security review and hardening
  • Coordinated vulnerability disclosure

Certifications and compliance

SOC 2 Type II

In Progress

Audit for security, availability, and confidentiality (not complete)

ISO 27001

Planned 2026

Information security management standard (not yet certified)

GDPR

Compliant

GDPR practices for EU users. See /compliance and /privacy.

CCPA

Compliant

California Consumer Privacy Act practices. See /compliance and /privacy.

Security practices

Third-party audits and penetration testing
Employee security training and background checks
Secure development practices in the product SDLC
Incident response plan with defined escalation
Business continuity and disaster recovery planning
Security awareness training for the team
Vendor security assessments
Data retention and secure deletion policies

Responsible disclosure

Report security issues to us so we can fix them before public disclosure.

How to report

  • 1.Email security@arvad.ai with details of the vulnerability
  • 2.Include steps to reproduce and expected impact
  • 3.Give us reasonable time to fix before public disclosure
  • 4.We acknowledge within 48 hours and send updates

Valid reports may receive acknowledgment on a security hall of fame.

Tips for your account

Account security

  • Enable MFA
  • Use strong, unique passwords
  • Review account activity
  • Do not share credentials

API security

  • Rotate API keys regularly
  • Keep secrets in environment variables or a vault
  • Scope API access to what each integration needs
  • Watch API usage for unusual activity

Security contact

For vulnerability reports or security questions: