Security

Trust & Security

This page describes how artifinance.io and the ARIA sandbox at app.artifinance.io are actually built today — not an aspirational architecture diagram. Where something isn't true yet, we say so directly, on the same page as everything else, because a due-diligence reviewer finds the gap either way and a page that only lists strengths reads as less credible, not more.

Architecture, today's shape

Encryption & credentials

Access & audit

Subprocessors

The same short list named in our Privacy Notice, kept in sync with it:

Data protection rights

DPDP 2023 (India) and GDPR (EU/EEA/UK) rights — access, correction, export, deletion, and withdrawal of consent — are covered in full in our Privacy Notice, along with how to exercise them.

What we haven't certified yet, honestly

These are open items, not hidden ones. If your procurement process needs to track them, ask us for status — we'll tell you where each one stands.

Report a security issue

Found a vulnerability or something that looks like one? Email hello@artifinance.io with what you found and how to reproduce it, and we'll treat it as a priority.