- How does Arctory encrypt data?
- All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. These industry-standard controls ensure that client information remains protected during processing and storage.
- Is Arctory GDPR compliant?
- Yes. Arctory provides mechanisms for exercising GDPR rights, applies consistent protection across all regions, and processes data according to GDPR requirements.
- Where is Arctory hosted?
- The application and database are hosted entirely in Germany. AI models run on EU servers (configurable). Organizations may also deploy Arctory in their own infrastructure for full control.
- Does the AI have access to our production data?
- You decide. AI is only involved while building or editing an application, and explicit access controls let you choose which data — if any — it may use; by default it works from your software code and database schema. Once deployed, your app talks to the database directly with no AI in the loop.
- Does Arctory use production data to train AI models?
- No. Production data is never used to train or improve AI models at any point.
- Does Arctory support bring your own API keys?
- Yes. Clients can supply their own API keys for supported AI model providers. This means AI inference runs under your own account, giving you full visibility into usage and ensuring no data is routed through Arctory's model credentials.
- What happens to our data when we stop using Arctory?
- Clients can request deletion of their data at any time. Data is retained only as necessary to provide the service and is removed according to documented deletion procedures.