Live demos available here
Security

Security practices from the first commit.

How we protect the systems we build, sized to each business and its risk. This matters more as automation and AI gain access to business data.

Practices

What we implement by default

  • Sign-in

    Modern authentication with multi-factor options for staff accounts.

  • Role-based access

    People see and do only what their role allows, enforced in the database as well as the app.

  • Least privilege

    Integrations and automations get the narrowest access that works.

  • Encryption

    In transit (TLS) and at rest through the hosting and database platforms.

  • Logging and audit

    Records of sensitive actions so changes can be traced.

  • Backups and recovery

    Automated backups sized to how fast the system must come back.

  • Change control

    Version control, code review, preview environments and controlled releases.

  • Secure APIs

    Authenticated endpoints, input validation, rate limits and managed secrets.

AI and automation

Same rules as people.

AI features use the same role model as staff, work from approved sources, are logged, and go through human approval wherever an action could affect customers, money or the brand.

Castle Arc does not currently hold formal certifications such as SOC 2 or ISO 27001. When a project has specific regulatory requirements, we identify them in discovery and plan the architecture and vendors accordingly.

Security and governance services

Review what you run today.

We can review an existing system's access, integrations and recovery setup, or design a new one securely from the start.