Arkavio
How it worksFeatures
Log inJoin

Security & Trust

Version 1.0 · Last updated: 4 June 2026

Arkavio handles sensitive practice data — client contacts, staff costs, timesheets and finances. We take that seriously. This page summarises how we protect it.

Hosting & data residency

  • The Service runs on Vercel (application hosting and content delivery).
  • Customer Data, authentication and files are stored in Supabase (PostgreSQL), hosted within the UK/EU.

Tenant isolation & access control

  • Row-level security (RLS) is enforced on every table; all data is scoped by organisation, so one practice can never see another’s data.
  • Role-based access within a practice: director, manager, project architect and staff, with project-scoped access for project architects.
  • Practice bank account details (the receiving account shown on the invoices a practice issues) are editable only by users with the director role and are encrypted at rest like all Customer Data. Because these details print on the invoice itself, they are necessarily visible to the directors and managers who issue invoices; they are never shared with any other third party.
  • Internal access follows least-privilege principles.

Encryption

  • In transit: all traffic is served over TLS/HTTPS.
  • At rest: Customer Data is encrypted at rest by our database and storage provider.

Authentication & abuse prevention

  • Managed authentication with secure session handling (PKCE flow).
  • Cloudflare Turnstile protects public forms — sign-up, sign-in, password recovery, email verification and the Founding Partner application — from bots and abuse.
  • Sign-up is restricted to work email domains (personal-email domains are blocked).
  • Rate limiting is applied to authentication endpoints.

Monitoring & error tracking

  • Error and performance monitoring (Sentry), configured to minimise the personal data captured; we do not send credentials.
  • Session replay is input-masked by default and only enabled with user consent; recordings are anonymised.

Privacy by design

  • Product analytics (PostHog, EU region) are cookieless until consent and strip identifying properties.
  • IP addresses in cookie-consent audit records are hashed, never stored raw.

Backups

Regular, managed database backups are maintained via our database provider.

Payments

Payments are processed by Stripe on Stripe-hosted pages. Arkavio does not store full card details.

Data protection & sub-processors

  • Arkavio is registered with the ICO as a data controller.
  • For customer data we act as a processor under a Data Processing Agreement with a named sub-processor list (Annex 3).
  • See our Privacy Policy for data rights and retention.

Certification roadmap

We are a young company and are honest about where we are:

  • Today: ICO-registered; the controls described above implemented in the platform.
  • Near-term target: Cyber Essentials (UK government-backed scheme, widely recognised by UK buyers).
  • Longer-term: evaluate Cyber Essentials Plus and ISO/IEC 27001 as the customer base grows.

Reporting a vulnerability

If you believe you have found a security issue, please email security@arkavio.com with details. We welcome responsible disclosure and will acknowledge your report.

Arkavio

All-in-one practice management for UK architecture practices. Built by a registered architect, in the UK, staying that way.

Product

  • How it works
  • Features

Company

  • Contact

Account

  • Log in
  • Start free trial

Legal

  • Privacy
  • Cookies
  • Terms
  • Security
  • All legal
© 2026 Arkavio Ltd. All rights reserved.Registered in England & Wales.