Security
Arke reads the most sensitive thing an agency has: its relationships. Here is exactly how that data is handled, in plain language. If anything on this page is unclear, write to support@usearke.com and a human answers.
All traffic runs over TLS 1.2+; everything stored, from mail metadata to transcripts and notes, is encrypted at rest with AES-256. Recordings live in isolated object storage with signed, expiring URLs.
Nothing you connect is ever used to train AI models, ours or anyone else's. The agent reads your workspace at question time, answers, and retains nothing outside your workspace.
Arke asks for read-only OAuth scopes on mail and calendar. It never sends email on your behalf, and you can revoke access from your Google or Microsoft account at any moment.
Meeting recordings are private to the member who made them until they choose to share. Phone numbers are verified per member and map to exactly one account.
Disconnect a channel and its synced data goes with it. Delete a workspace or your account and everything is hard-deleted from production within 30 days, backups included on their cycle. Export first; transcripts and summaries leave as Markdown, PDF, or Doc.
Every query is scoped to your workspace at the database layer. No shared caches across customers, no cross-workspace reads. A workspace is a wall, not a filter.
SOC 2 Type II is in progress with an independent auditor. Arke is built GDPR-ready: data processing agreements are available on request, exports are self-serve, and deletion requests are honored without a support ticket. We will publish reports here as they complete. No badge before the audit backs it.
The complete list of vendors that may touch customer data, and why. This list changes rarely and deliberately.
| Vendor | Purpose | Region |
|---|---|---|
| Neon | Database hosting | US |
| Cloudflare | Application hosting & CDN | Global |
| Anthropic | AI processing (no training on your data) | US |
| Stripe | Payments; card data never touches Arke | US |
| Deepgram | Meeting transcription | US |
| Recall.ai | Meeting recorder infrastructure | US |
| Twilio | Phone verification & SMS | US |
Report vulnerabilities to support@usearke.com. We acknowledge within 48 hours, keep you updated while we fix, and credit researchers who report responsibly. Please don't test against other customers' data; spin up a trial workspace instead.