Security

The page your examiner reads first.

Architectural commitments, data handling practices, and answers to the questions your vendor management team will ask. In writing, before you ask.

Commitments

Five commitments. Not aspirations.

01

Infrastructure we own and control.

Your AI runs on private hardware in a secured US facility. Not a public cloud tenant. Not a hyperscaler sub-account. We own the infrastructure your data touches.

02

No training on your data.

Your documents, conversations, and member records are never used to train any model. Not ours. Not anyone else's. This is contractual, not a policy page that can change with a notification email.

03

Your data runs your service. Nothing else.

We do not use customer data for analytics, benchmarking, product improvement, or any purpose beyond operating the AI you contracted for. Audit logs are retained within your account, not aggregated or repurposed.

04

Source citations on every answer.

No black-box outputs. Every response carries a verifiable reference back to the document or policy paragraph that produced it. Your team can check the work. Your examiner can trace the reasoning.

05

Tamper-evident audit trail.

Every query, response, and administrative action is cryptographically chained. Modification of any historical record breaks the chain and is immediately detectable. Built for examiners who ask whether the record can be trusted.

Authentication

Your identity provider, your controls.

OIDC available for integration with major identity providers like Microsoft Entra ID. Your team authenticates with existing credentials. Multi-factor authentication policies configured in your identity provider carry through automatically. No separate user directory. No shared accounts. No additional password or second factor for your staff to manage.

Data handling

Where your data lives. Where it does not.

All customer data is stored on US-based infrastructure owned and operated by Arcanum Works. Data at rest is encrypted per customer. Data in transit is encrypted. No customer data is stored outside the United States. No customer data is accessible from another customer's context.

Audit logs are retained within your account. They are not aggregated, anonymized, or repurposed. They exist for your compliance needs, not ours.

Standards

Where we are. Where we're headed.

We are honest about our certification status because the audience for this page will know if we overstate it.

SOC 2 Type I
In progress. Timeline available on request. Type II to follow.
GLBA support
Architectural and operational practices designed to support your institution's GLBA obligations. Written response available.
Examination readiness
Documentation packages designed to support your institution's examiner review of AI vendor relationships. Reference available on request.
Vendor management

The answers, in writing, before you ask.

We have prepared responses to standard vendor management questionnaire categories: corporate governance, security controls, data handling, business continuity, sub-processors, and incident response.

Vendor management package

Available in whatever format your vendor management process requires. Request it and we'll send it within two business days.

Request the package
Incident response

What happens when something goes wrong.

We maintain a documented incident response process with defined severity levels, communication timelines, and post-incident reporting.

Credit unions under examination need to demonstrate that their vendors have these processes. We make ours available for review before you sign a contract, not after.

Questions

Have a question we didn't cover?

Most vendor management teams have one. Send it. We respond in writing within two business days.