Architectural commitments, data handling practices, and answers to the questions your vendor management team will ask. In writing, before you ask.
Your AI runs on private hardware in a secured US facility. Not a public cloud tenant. Not a hyperscaler sub-account. We own the infrastructure your data touches.
Your documents, conversations, and member records are never used to train any model. Not ours. Not anyone else's. This is contractual, not a policy page that can change with a notification email.
We do not use customer data for analytics, benchmarking, product improvement, or any purpose beyond operating the AI you contracted for. Audit logs are retained within your account, not aggregated or repurposed.
No black-box outputs. Every response carries a verifiable reference back to the document or policy paragraph that produced it. Your team can check the work. Your examiner can trace the reasoning.
Every query, response, and administrative action is cryptographically chained. Modification of any historical record breaks the chain and is immediately detectable. Built for examiners who ask whether the record can be trusted.
OIDC available for integration with major identity providers like Microsoft Entra ID. Your team authenticates with existing credentials. Multi-factor authentication policies configured in your identity provider carry through automatically. No separate user directory. No shared accounts. No additional password or second factor for your staff to manage.
All customer data is stored on US-based infrastructure owned and operated by Arcanum Works. Data at rest is encrypted per customer. Data in transit is encrypted. No customer data is stored outside the United States. No customer data is accessible from another customer's context.
Audit logs are retained within your account. They are not aggregated, anonymized, or repurposed. They exist for your compliance needs, not ours.
We are honest about our certification status because the audience for this page will know if we overstate it.
We have prepared responses to standard vendor management questionnaire categories: corporate governance, security controls, data handling, business continuity, sub-processors, and incident response.
Available in whatever format your vendor management process requires. Request it and we'll send it within two business days.
Request the package →We maintain a documented incident response process with defined severity levels, communication timelines, and post-incident reporting.
Credit unions under examination need to demonstrate that their vendors have these processes. We make ours available for review before you sign a contract, not after.
Most vendor management teams have one. Send it. We respond in writing within two business days.