Security practices from the first commit.
How we protect the systems we build, sized to each business and its risk. This matters more as automation and AI gain access to business data.
What we implement by default
Sign-in
Modern authentication with multi-factor options for staff accounts.
Role-based access
People see and do only what their role allows, enforced in the database as well as the app.
Least privilege
Integrations and automations get the narrowest access that works.
Encryption
In transit (TLS) and at rest through the hosting and database platforms.
Logging and audit
Records of sensitive actions so changes can be traced.
Backups and recovery
Automated backups sized to how fast the system must come back.
Change control
Version control, code review, preview environments and controlled releases.
Secure APIs
Authenticated endpoints, input validation, rate limits and managed secrets.
Same rules as people.
AI features use the same role model as staff, work from approved sources, are logged, and go through human approval wherever an action could affect customers, money or the brand.
Castle Arc does not currently hold formal certifications such as SOC 2 or ISO 27001. When a project has specific regulatory requirements, we identify them in discovery and plan the architecture and vendors accordingly.
Review what you run today.
We can review an existing system's access, integrations and recovery setup, or design a new one securely from the start.
