Deploy Arcive
Security
Deployments run inside systems you already own. This page sets out how that access is granted, limited, logged and given back.
Last updated 11 September 2026
Scope
This covers how we handle access and data during audits and deployments. The public website is separate and collects nothing; see the privacy policy.
Access to your systems
- You grant it, you hold it, you revoke it. Access is created in your own identity provider under a named account for us. We never ask for a shared login or for someone else’s credentials.
- Least privilege. We request the narrowest scope that does the job, read-only wherever read-only is enough, and scoped to the one part of the operation in question rather than the whole estate.
- Multi-factor authentication is enabled on every account we hold, and credentials are stored in a password manager, never in code, tickets or documents.
- Revocation on completion. Access is handed back at the end of an engagement. You can withdraw it at any point without notice, and we will ask you to confirm it has been removed.
How data is handled
- Work happens in place. Systems are read where they live. We do not take bulk copies of your data out of your environment.
- Minimum necessary. Where a sample is genuinely needed to build or test something, we take the smallest one that works and prefer redacted or synthetic data.
- Encryption. Devices used for client work have full-disk encryption and automatic screen lock. Data in transit uses TLS.
- A person approves anything that leaves. Systems we deploy draft, route and escalate. Nothing reaches your customer without one of your people approving it.
Subprocessors
One third party is involved in running this website: Cloudflare, Inc., for hosting and content delivery. It processes IP addresses and request logs. Typefaces are served from this domain, so no font service receives visitor data.
Subprocessors involved in an engagement, including any model or infrastructure provider used to deliver a deployment, are named in the data processing terms of that engagement before they are used. We give written notice before adding a new one, and you may object.
Retention
Material gathered during an engagement, such as notes, samples, exports and credentials, is deleted within 30 days of the engagement ending, or sooner if you ask. Deliverables and the audit report are yours and are retained only as your contract specifies. Ordinary business records such as invoices are kept as UK law requires.
If something goes wrong
If we become aware of a security incident affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware. The notification will say what we know, what is affected, what we are doing, and what we recommend you do. We will keep you updated until it is closed, and follow up in writing with the cause and the fix.
Reporting a vulnerability
Email deploy@arcive.ai with the subject line “Security”. We acknowledge within two business days and aim to give a substantive update within ten. We will not pursue legal action over good-faith research that respects privacy, avoids degrading the service and does not access data beyond what is needed to demonstrate the issue. Please give us reasonable time to fix an issue before disclosing it publicly.
What we do not claim
Deploy Arcive is a small practice and holds no formal certification such as ISO 27001 or SOC 2 today. We would rather say so than imply otherwise. We are happy to complete security questionnaires, sign an NDA, work within your own security requirements, and agree specific controls in the engagement contract.