Arkin Vault
How it works Why Arkin Vault Compare For authors Connectors Pricing
🇮🇳 India 🇺🇸 United States
Help Security Admin
Book a call

Security

Current as of 2026-07-06. This document describes our security controls in plain language and our coordinated-disclosure program. It is not a contractual representation; binding security commitments live in a Data Processing Addendum or Security Annex.

Hosting and network

  • Hosted on Amazon Web Services with data residency by region — US and global data in the United States, and Arkin Vault India data in India (Mumbai). Workloads run on hardened, isolated compute within a private network.
  • HTTPS is enforced and HTTP is redirected to HTTPS.
  • Every response carries a strict set of browser-hardening and transport-security headers (HSTS, clickjacking, MIME-sniffing, and referrer protections).

Authentication and access

  • Passwords are stored using a modern, salted, adaptive password-hashing algorithm — never in plaintext or as reversible values.
  • Admin sessions are signed and held server-side; CSRF protection is enforced on all state-changing requests.
  • Recipient access is gated by configurable combinations of an authorized-email allow-list, an access password, and NDA signing.
  • Per-document NDA scoping: each recipient signs once per document, not globally.

Data at rest and in transit

  • All data in transit uses TLS 1.2 or higher.
  • Application data and uploaded files are encrypted at rest with managed keys.
  • Encrypted backups are taken daily and retained for fourteen (14) days.

Auditing

  • Every recipient access event (page view, download, print, NDA signing, login, logout) is logged with viewer name, email, IP, user-agent, timestamp, and page number where applicable.
  • NDA signatures are cryptographically bound to the NDA text via SHA-256 hash; the signed-PDF artifact captures all signer metadata.
  • Admin actions are logged separately as admin_preview to distinguish from real recipient activity.

Application hardening

  • Upload size limits and rate limiting are enforced on authentication and upload endpoints.
  • Per-page watermarking is applied with admin-configurable text.
  • Encrypted PDFs are rejected at upload time with a clear error message.
  • Path-traversal protection on all file-handling routes.

Vulnerability disclosure

We welcome reports from security researchers. Please email security@arkinvault.com with:

  • A clear description of the vulnerability and impact.
  • Step-by-step reproduction.
  • Your name and any handle for credit (we will publicly acknowledge consenting researchers).

We commit to acknowledge receipt within 72 hours, provide an initial assessment within 7 days, and remediate critical issues as quickly as practicable. We will not pursue legal action against good-faith research that complies with this policy: do not access more data than is necessary to demonstrate the issue, do not exfiltrate or alter customer data, do not disrupt the service, and give us reasonable time to remediate before disclosure.

Contact

General: security@arkinvault.com
Privacy: privacy@arkinvault.com

Privacy Terms Acceptable Use Security
© 2026 Aethyia Inc. · Arkin Vault is a product of Aethyia Inc. · v2.5.1