Privacy governance · Local storage protocols
Effective Date: March 31, 2026 · Last Updated: July 27, 2026 · ArthaOps. Inc.
This Comprehensive Cookie & Telemetry Policy ("Policy") governs the automated deployment, operational utilization, and programmatic management of cookies, web beacons, local storage objects, telemetry trackers, and similar programmatic data persistence technologies (collectively, "Tracking Technologies") across the ArthaOps Cost SaaS platform, associated application programming interfaces (APIs), software development kits (SDKs), and public-facing web properties (collectively, the "Platform"). The Platform is owned and operated by ArthaOps. Inc. ("ArthaOps", "we", "us", or "our").
Our Platform interfaces programmatically with complex multidimensional public cloud architectures, specifically Amazon Web Services (AWS). We deploy exactly378 cloud cost waste detectors across EC2, RDS, EBS, S3, ElastiCache, EKS, NAT Gateways, and CloudWatch to provide localized, high-fidelity cloud cost waste detection schemas, algorithmic anomaly detection protocols, and autonomous deterministic remediation pipelines (collectively referred to as "Autopilot"). Because our operational footprint necessitates the maintenance of secure, continuous, and stateless/stateful session boundaries, robust cross-site request forgery (CSRF) defenses, and meticulous telemetry collection for continuous algorithmic refinement, the deployment of select Tracking Technologies is strictly mandatory and architecturally non-negotiable.
This Policy is inextricably incorporated by reference into the ArthaOps Terms of Service and Privacy Policy. It is expressly architected to fulfill our statutory transparency obligations under the Digital Personal Data Protection Act, 2023 (DPDPA 2023), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, alongside extraterritorial alignments such as the European Union’s General Data Protection Regulation (GDPR) and the ePrivacy Directive (Directive 2002/58/EC as amended). This applies insofar as these frameworks govern sovereign data principals or globally distributed end-users interacting with our AP-SOUTH-1 (Mumbai) hosted infrastructure. We affirm that our telemetry and state management implementations have been subjected to rigorous privacy engineering heuristics, adhering strictly to the principles of data minimization, purpose limitation, and storage limitation.
By accessing, browsing, interacting with, authenticating into, or otherwise initiating any programmatic or graphical exchange with the Platform, you acknowledge that you have read, comprehensively understood, and materially assented to the technical disclosures articulated in this Policy. For the avoidance of doubt, while explicit affirmative consent is solicited via our granular Consent Management Platform (CMP) for non-essential Tracking Technologies, the provisioning of strictly necessary authentication, security, and load-balancing cookies operates on the basis of contractual necessity and legitimate interest, rendering them exempt from preemptive consent requirements under global jurisprudential norms.
To ensure unambiguous technical parity between ArthaOps and the end-user (or auditing entity), the following cryptographic, networking, and browser-storage primitives are defined precisely as they operate within the context of our Platform’s React/Next.js architecture. We reject overly simplified analogies in favor of deterministic engineering definitions.
Cookies: Small text data strings of alphanumeric characters, strictly limited to 4096 bytes per domain, transmitted by our origin servers via HTTP/HTTPS response headers (e.g., Set-Cookie) and persisted autonomously by the user's web browser client (User-Agent). Cookies are integrity-protected via HTTP security directives (HttpOnly, Secure,SameSite) but do not use asymmetric key-signing mechanisms. They enable statefulness over the inherently stateless HTTP protocol. We deploy both "session cookies" (which execute an automatic self-destruction sequence upon the termination of the browser process) and "persistent cookies" (which retain their state across subsequent browser initializations until a hardcodedExpires timestamp or Max-Age directive is reached, subject to manual evidentiary purging by the user or automated browser eviction policies).
Web Beacons & Pixels: Transparent, single-pixel (1x1) graphic image representations, zero-dimensional iframe injections, or asynchronous JavaScript payloads that establish a unilateral HTTP GET request to our telemetry servers or authorized third-party endpoints. These are primarily utilized within our notification architecture and specific ingress points to establish deterministic read-receipts, viewport visibility matrices, and asynchronous load confirmations without interfering with the primary Document Object Model (DOM) rendering pipeline or blocking the main JavaScript execution thread.
localStorage (Web Storage API): A synchronous key-value pair storage mechanism executing within the browser's sandbox that provides a persistent data persistence layer independent of HTTP request headers. Unlike cookies, localStorage payloads are not autonomously transmitted to the server with every network request, drastically reducing bandwidth overhead and minimizing exposure to network-level interception. ArthaOps utilizes localStorage strictly for caching non-sensitive UI state preferences, dry-run dependency graph coordinates prior to AWS STS AssumeRole execution, and offline mutation queues.
sessionStorage (Web Storage API):Functionally analogous to localStorage in its key-value structural format, but mathematically scoped to the lifecycle of a specific top-level browsing context (tab or window). Data inscribed to sessionStorage is irrecoverably purged upon closure of the corresponding tab, providing an ephemeral, highly secure enclave for transient contextual data, multi-step configuration wizard states, and temporary IAM parameter validations prior to cryptographic commitment.
IndexedDB: A low-level asynchronous API for client-side storage of significant amounts of structured data, including files and blobs. This API employs robust transactional database mechanics to manage highly complex, normalized datasets directly within the client environment. ArthaOps leverages IndexedDB specifically for our Autopilot remediation history caching and large-scale AWS cost inventory paginations, ensuring near-instantaneous offline availability and minimizing round-trip latencies to our AP-SOUTH-1 origin infrastructure.
Service Workers: Event-driven, event-loop-based scripts executed in a background thread entirely independent of the primary DOM thread. Service Workers act as programmable network proxies, intercepting HTTP requests to orchestrate complex caching logic, facilitate robust offline experiences, and manage background data synchronization protocols. Our implementation strictly utilizes Service Workers to optimize the deterministic loading of our core Next.js JavaScript bundles, caching static React assets, and intercepting API requests to provide graceful degradation protocols during intermittent internet connectivity scenarios.
The algorithmic deployment and operational lifecycle of Tracking Technologies across the ArthaOps infrastructure are rigorously underpinned by a robust, multifaceted legal architecture designed to ensure absolute compliance with Indian sovereign statutes and extraterritorial data protection frameworks. This section articulates the precise jurisprudential foundations validating our technical operations.
Strictly Necessary & Essential Functionality:Under the purview of the Digital Personal Data Protection Act, 2023 (DPDPA) Section 4 (Lawful Purpose and Consent) and Section 7 (Certain Legitimate Uses), alongside the explicit exemptions codified in Article 5(3) of the European ePrivacy Directive, the deployment of strictly necessary cookies relies upon the legal bases of "contractual necessity" and "legitimate operational imperative." These Tracking Technologies—encompassing robust authentication mechanisms via Logto Cloud Inc., payment security tokenization via Razorpay, and critical state-management tokens—are structurally indispensable to the provision of the requested SaaS services. In their absence, the fundamental cryptographic integrity, session boundary isolation, multi-tenant workspace separation, and transactional finality of the Platform would critically degrade. Consequently, these elements are deployed mandatorily without preemptive consent, though complete transparency is continuously maintained via this Policy.
Performance, Telemetry & Diagnostics: The utilization of aggregated, statistically modeled, and pseudonymized error tracking (via Sentry) and product telemetry (via PostHog) relies on a dual-pronged legal basis contingent upon jurisdictional variables. Primarily, under DPDPA frameworks, this processing is substantiated by ArthaOps's legitimate organizational interest in continuously refining platform security, diagnosing critical algorithmic anomalies within our 378 waste detectors, and ensuring the fulfillment of our strict 99.9% Service Level Agreement (SLA) uptime targets. We actively deploy aggressive data minimization heuristics—such as zero-PII sanitization pipelines prior to Sentry transmission, dropping IP addresses at the edge, and distinct ID anonymization within PostHog—to drastically reduce the privacy impact on the Data Principal, thereby maintaining a proportionate and legally defensible balance between organizational necessity and individual privacy rights.
Consent-Driven Deployments (Analytics & Features):For non-essential tracking modalities that exceed the threshold of strict operational necessity—including advanced behavioral analytics, cross-session user journey mapping, and non-critical UI persistence—we rely strictly upon the explicit, informed, and unambiguous affirmative consent of the Data Principal. This mechanism aligns seamlessly with the requirements of the DPDPA 2023 and the GDPR, facilitated through our granular Consent Management Platform (CMP). Data Principals possess the unencumbered, inalienable right to withdraw this consent instantaneously at any juncture, triggering an automated revocation sequence that instructs the client-side architecture to immediately cease deployment and proactively attempt the deletion of corresponding non-essential Tracking Technologies.
Information Technology Act, 2000 & SPDI Rules, 2011 Compliance: The overarching technical administration of all Tracking Technologies strictly adheres to the Reasonable Security Practices and Procedures mandated under Section 43A of the IT Act, 2000, and the corresponding SPDI Rules of 2011. All data collected via these mechanisms is subjected to AES-256 encryption at rest within our AP-SOUTH-1 (Mumbai) databases and TLS 1.3 transit encryption globally. We enforce stringent logical isolation, ensuring that ephemeral data gathered via cookies is explicitly segregated from the immutable, SHA-256 linear hash-chained audit ledgers that maintain our core compliance and remediation records.
To satisfy our rigorous transparency mandates and facilitate deep technical audits by enterprise procurement teams, the following enumerates an exhaustive, highly granular inventory of all active cookie primitives explicitly authorized for deployment across the ArthaOps ecosystem. This taxonomy categorizes cookies by their fundamental architectural purpose, detailing exact namespaces, temporal lifespans, upstream providers, and the corresponding legal justification for their presence within your User-Agent.
These primitives are non-negotiable architectural mandates required for cryptographic identity verification, session boundary enforcement, and access control across our multi-tenant workspace isolation boundaries. They are powered exclusively by our enterprise Single Sign-On (SSO) partner, Logto Cloud Inc., and custom internal ArthaOps logic.
| Cookie Namespace | Architectural Purpose | Provider & Origin | Lifespan Duration | Legal Basis |
|---|---|---|---|---|
| __session | Maintains the primary cryptographic session state. Evaluated server-side via Next.js middleware to validate JSON Web Tokens (JWT) and authorize server actions. | Logto Cloud (First-Party via Proxy) | Session (Closes on browser exit) | Strictly Necessary |
| arthaops_auth_token | Facilitates seamless, highly secure multi-tenant identity transitions between isolated ArthaOps workspaces, allowing immediate invalidation of access keys. | Logto Cloud (Managed OIDC) | 7 Days | Strictly Necessary |
| stealth_access | Internal proprietary token for bypassing stringent rate-limiting parameters during authenticated, user-initiated autonomous remediation sequences (Autopilot execution). | ArthaOps Internal | 2 Hours | Strictly Necessary |
Facilitating the secure acquisition, upgrade, and renewal of ArthaOps Command, Operator, and Control plans necessitates deeply integrated payment processing gateways. We leverage Razorpay to handle sovereign INR (₹) transactions at a fixed FX rate of 84.0 INR/USD, ensuring strict adherence to PCI-DSS Level 1 compliance requirements. These cookies are mandated by Razorpay for fraud analysis.
| Cookie Namespace | Architectural Purpose | Provider & Origin | Lifespan Duration | Legal Basis |
|---|---|---|---|---|
| rzp_checkout_id | Maintains transactional continuity across complex redirection flows (e.g., banking portals, UPI intents, 3D Secure UI verifications) to prevent state corruption. | Razorpay (Third-Party) | Session | Strictly Necessary |
| rzp_device_id | Employed for robust algorithmic fraud prevention, identifying anomalous device signatures, botnets, or synthetic payment mutation attempts. | Razorpay (Third-Party) | 1 Year | Legitimate Interest (Security) |
To maintain our stringent 99.9% uptime SLA and proactively identify regressions in our cloud cost waste detectors, we deploy zero-PII, hyper-sanitized diagnostic cookies via Sentry. These cookies provide critical distributed tracing contexts necessary for debugging Next.js React Server Components and complex client-side hydrations. No source code, passwords, or AWS IAM keys are ever captured.
| Cookie Namespace | Architectural Purpose | Provider & Origin | Lifespan Duration | Legal Basis |
|---|---|---|---|---|
| sentry-trace | Propagates W3C Trace Context headers across distributed microservices, linking front-end exceptions directly to our backend AP-SOUTH-1 logs. | Sentry (Third-Party) | 1 Hour | Legitimate Interest |
| baggage | Supplements the trace context with arbitrary key-value pairs (like deployment environment flags) without polluting the core trace identifiers. | Sentry (Third-Party) | 1 Hour | Legitimate Interest |
| _sentryReplaySession | Facilitates highly sanitized, masked session replays to visually diagnose complex DOM layout thrashing or unhandled promise rejections during AWS integrations. | Sentry (Third-Party) | 30 Days | Consent Required |
Understanding user interaction flows, tracking the adoption velocity of new waste detectors, and pinpointing friction within our UI is handled by PostHog. We use these analytics exclusively for product optimization and roadmap prioritization, operating strictly on anonymized or highly pseudonymized algorithmic identifiers.
| Cookie Namespace | Architectural Purpose | Provider & Origin | Lifespan Duration | Legal Basis |
|---|---|---|---|---|
| ph_*_posthog | Core configuration identifier holding state regarding feature flags, active A/B testing variants, and user configuration overrides within the dashboard. | PostHog (First-Party Proxy) | 365 Days | Consent Required |
| distinct_id | A pseudonymized cryptographic hash tying events across multiple devices, allowing us to generate accurate weekly active user (WAU) retention metrics. | PostHog (First-Party Proxy) | 365 Days | Consent Required |
| ph_opt_in_out_phc_* | Explicitly stores the user's consent preference regarding telemetry tracking, ensuring that if they opt-out, PostHog instantiation is perpetually blocked. | PostHog (First-Party Proxy) | 365 Days | Strictly Necessary (Compliance) |
ArthaOps strictly minimizes the use of invasive cross-site marketing trackers. However, to measure the efficacy of B2B campaigns aimed at engineering leaders, we may deploy selected attribution tags. These are entirely optional and gated firmly behind our initial CMP prompt. If you decline, these payloads will categorically refuse to initialize, preserving complete anonymity against third-party ad networks. We do not sell data to data brokers.
In modern single-page applications (SPAs) and React-based frameworks, the reliance on traditional cookies has partially shifted toward the more efficient, higher-capacity Web Storage APIs. ArthaOps employs both localStorage andsessionStorage to cache complex UI states, reducing server load, preserving user intent across navigations, and ensuring a highly responsive, low-latency user experience. This section delineates the specific keys and data structures persisted within these browser-native storage enclaves.
Within the localStorage domain, ArthaOps persists several critical but fundamentally non-sensitive configuration parameters. The key arthaops_ui_themestores a simple string value ("light", "dark", or "system") to immediately apply the correct CSS variables during the initial DOM parsing phase, preventing the jarring "Flash of Unstyled Content" (FOUC). The arthaops_detector_preferenceskey retains a serialized JSON object mapping user-defined visibility toggles for our 378 waste detectors (e.g., hiding the EKS idle node detector if the workspace does not utilize Kubernetes), ensuring that dashboard layouts persist across extended absences. Furthermore, we leverage localStorage for arthaops_draft_remediation, which temporarily caches the deterministic state of pending Autopilot dry-runs. If an engineering manager loses connectivity or accidentally closes a tab while reviewing a complex IAM role mutation or an S3 bucket policy adjustment, this local cache allows instantaneous, seamless recovery of that state upon their return, significantly enhancing operational continuity.
Conversely, our utilization of sessionStorageis highly restricted, deeply ephemeral, and focused strictly on intra-session security protocols and transient data flows. The primary key utilized is arthaops_oauth_state, which stores a cryptographically secure pseudorandom number generator (CSPRNG) payload used specifically to mitigate Cross-Site Request Forgery (CSRF) vectors during the intricate Logto Cloud OIDC OAuth callback dance. This payload is mathematically verified upon return from the identity provider and immediately purged. We also utilize sessionStorage forarthaops_wizard_context, caching intermediate selections during the multi-step AWS STS AssumeRole integration process. This ensures that sensitive External ID parameters and read-only IAM bound configurations are retained only while the configuration window is active. They undergo complete cryptographic destruction the moment the browser tab is terminated, thereby minimizing the attack surface for local malware data exfiltration.
To systematically defend against advanced persistent threats (APTs), man-in-the-middle (MitM) network interceptions, and sophisticated cross-site scripting (XSS) or request forgery (CSRF) vectors, ArthaOps engineers rigorously enforce the highest echelons of HTTP security directives on all outgoing cookie transmissions. These directives are not mere suggestions; they are immutably baked into our Next.js edge middleware and AWS API Gateway configurations.
Every critical authentication and session-management cookie is forcibly decorated with the Secureattribute. This directive constitutes an absolute cryptographic mandate, instructing the browser's networking stack to categorically refuse the transmission of the cookie over any unencrypted HTTP connection. The cookie will only traverse the network if a valid, verified TLS 1.3 cryptographic tunnel is established between the client and our AP-SOUTH-1 endpoints. This entirely nullifies the risk of session hijacking via passive network sniffing on unsecured public networks (e.g., airport Wi-Fi).
Furthermore, to eliminate the threat of XSS payloads accessing our session identifiers, we mandate the HttpOnlyattribute on all sensitive cookies. By appending this flag, we deliberately sever the JavaScript V8 engine's ability to interface with the cookie via the document.cookie API. Even if a highly sophisticated, zero-day malicious actor successfully injects an XSS payload into our DOM, the payload remains mathematically blind to the authentication tokens, preventing disastrous credential harvesting and subsequent account takeover (ATO).
We aggressively utilize the SameSite attribute to construct impenetrable CSRF defenses. Our most critical mutation endpoints enforce SameSite=Strict, ensuring that the cookie is solely attached to requests originating from the exact same site (e.g., within the arthaops.com domain). For authentication flows requiring cross-origin navigation (like returning from an SSO provider), we carefully downgrade to SameSite=Lax, which permits cookie transmission during safe top-level navigations but forcibly blocks it for cross-site POST requests. Finally, for supreme architectural resilience, we employ the__Host- prefix (e.g., __Host-session). This prefix acts as an unforgeable contract with the browser: it ensures the cookie is universally restricted to the issuing host, mandates the Secure flag, and completely prohibits the specification of a Domain attribute, preventing malicious subdomains from laterally overwriting root session credentials.
The architectural provenance of a cookie—whether it originates directly from the primary domain the user is actively engaging with, or from an external, embedded third-party domain—carries profound implications for privacy, security, and cross-site tracking capabilities. ArthaOps maintains a highly restrictive, deterministic stance regarding the introduction and management of these distinct cookie classes within our platform ecosystem, favoring first-party sovereignty wherever technologically feasible.
First-Party Cookies: These are discrete data primitives synthesized and instantiated exclusively by the primary domain visible within your browser's address bar (e.g., app.arthaops.com or arthaops.com). First-party cookies form the foundational bedrock of the ArthaOps operational paradigm. They are exclusively engineered to facilitate core platform mechanics, encompassing robust cryptographic identity verification, localized user preference caching, intricate dashboard state persistence, and highly secure, multi-tenant workspace routing. Because these cookies are strictly confined to our sovereign domain boundary, they are fundamentally incapable of monitoring user behavior, telemetry, or navigation patterns once you navigate away from the ArthaOps infrastructure. Their scope is mathematically constrained to our proprietary application surface area, ensuring maximum data sovereignty and strict adherence to the data minimization principles outlined in the DPDPA 2023.
Third-Party Cookies: Conversely, third-party cookies are generated by external domains that possess embedded resources, scripts, or operational integrations within the primary ArthaOps user interface. ArthaOps applies an aggressive policy of minimization regarding third-party cookies, permitting their deployment only when mathematically necessary to leverage best-in-class enterprise capabilities that are inefficient or insecure to build in-house. These specific deployments are strictly limited to critical infrastructure partners. Our authentication provider, Logto Cloud, may deploy essential cookies during complex identity federation sequences (e.g., Single Sign-On integrations with external Identity Providers like Google Workspace, Okta, or Microsoft Entra ID). Similarly, our payment gateway, Razorpay, deploys essential third-party cookies exclusively during checkout and B2B GSTIN invoice generation phases to satisfy stringent PCI-DSS Level 1 compliance mandates, specifically for dynamic fraud analysis, risk scoring, and 3D Secure (3DS) multifactor authentication state retention. We categorically do not permit unregulated third-party ad networks, opaque programmatic bidding ecosystems, or covert data brokers to deploy tracking cookies within our authenticated application payload.
The modern browser ecosystem is undergoing a radical, highly necessary paradigm shift toward aggressive, default-on privacy protections aimed at systematically dismantling covert cross-site tracking networks. ArthaOps strongly endorses this evolution. Our entire authentication, telemetry, and operational architecture is engineered from first principles to be fully resilient, transparent, and seamlessly functional in environments enforcing strict Intelligent Tracking Prevention (ITP) and Enhanced Tracking Protection (ETP) algorithms without resorting to adversarial workarounds.
Apple's Intelligent Tracking Prevention (ITP), deployed across Safari on macOS and iOS, and Mozilla's Enhanced Tracking Protection (ETP) within Firefox, employ sophisticated machine learning heuristics to identify, isolate, and systematically purge domains identified as cross-site trackers. They aggressively restrict the lifespan of client-side cookies (often capping document.cookie insertions to a maximum of 7 days or even 24 hours) and completely block third-party cookies by default. Furthermore, the Chromium engine (powering Google Chrome, Microsoft Edge, and Brave) is actively advancing initiatives to phase out third-party cookies entirely in favor of the localized Privacy Sandbox framework.
Because ArthaOps’s core architecture relies almost entirely on secure, HttpOnly, first-party cookies for its fundamental operational state, we are natively insulated from the disruptive, application-breaking effects of ITP and ETP. Our identity mechanisms are not dependent on fragile, cross-site third-party state. To maintain our analytics integrity without violating these browser protections, we proactively utilize advanced routing techniques, such as first-party data proxies and CNAME cloaking mitigation strategies. This ensures our critical error monitoring (Sentry) and product analytics (PostHog) payloads are transmitted directly through our own verified arthaops.com origin servers before being asynchronously forwarded to our subprocessors. This specific architectural decision ensures that even the most stringent browser anti-tracking engines recognize our critical telemetry as legitimate, first-party data flows. We categorically do not engage in browser fingerprinting, canvas fingerprinting, WebGL hashing, or covert state regeneration techniques (like "evercookies") to bypass these vital user protections.
ArthaOps recognizes that data sovereignty is fundamentally rooted in granular, transparent, and easily actionable user control. We reject the deceptive utilization of "dark patterns," coercive user interface designs, or ambiguous "implied consent" models. Instead, we implement a highly deterministic Consent Management Platform (CMP) that places absolute architectural control over non-essential Tracking Technologies directly into the hands of the Data Principal, in strict accordance with the DPDPA 2023.
Upon your initial ingress into the ArthaOps web ecosystem, our CMP intercepts the Next.js rendering pipeline, proactively suspending the instantiation of all non-essential scripts, telemetry payloads, and tracking cookies. A clear, legally precise dialog interface is presented, requiring an affirmative, explicit action (opt-in) to activate specific categories of processing, such as performance analytics or product optimization telemetry. This interface guarantees that the default cryptographic state is always "opt-out" for all non-essential Tracking Technologies, complying with the highest interpretive thresholds of global privacy legislation.
Crucially, consent is not a permanent, unalterable state. We provide persistent, unfettered access to our granular preference center via a persistent "Cookie Settings" link located in the global footer of our application. This interface allows you to dynamically mutate your consent parameters at any time. Should you choose to revoke consent for a specific category (e.g., Analytics), our platform instantly triggers an asynchronous revocation sequence. This sequence not only halts all future data transmission associated with that category but also leverages client-side JavaScript APIs to actively hunt and execute the deterministic deletion of any previously set cookies associated with those specific tracking endpoints. We maintain immutable, hash-chained audit logs of all consent mutations strictly for compliance demonstration purposes, ensuring total transparency during regulatory inquiries or audits.
While our proprietary Consent Management Platform (CMP) provides localized, granular control within the ArthaOps environment, ultimate absolute authority over your digital footprint resides within your chosen web browser client. Modern browsers expose complex configurations allowing you to globally intercept, inspect, aggressively block, or systematically purge all Tracking Technologies. For comprehensive technical control, we direct you to the official developer documentation for the following supported user agents:
chrome://settings/cookies. Here, you can define granular exceptions, block third-party cookies globally, or configure Chrome to execute a complete data purge upon exiting the browser process. See the official Chrome Support Documentation.about:preferences#privacy to toggle between Standard, Strict, and Custom rule sets. Strict mode will aggressively break known trackers. Reference the Mozilla MDN Web Docs for detailed configurations.edge://settings/privacy to select between Basic, Balanced, and Strict prevention schemas, and to manage localized cookie data. Review the Microsoft Edge Support Portal.brave://settings/shields.ArthaOps recognizes and respects the fundamental right of users to exercise draconian control over their browser's state management capabilities, up to and including the absolute prohibition of all cookies and local storage mechanisms. However, as an advanced, highly interactive Software-as-a-Service (SaaS) platform interfacing with complex AWS APIs, certain baseline functionalities are architecturally inextricably linked to the availability of these persistence layers. We provide the following deterministic technical assessment detailing the exact system degradations that will manifest should you enforce a global block on cookies while attempting to utilize our services.
Total Authentication Failure & Lockout: The most catastrophic impact of disabling all cookies is the complete paralysis of our Single Sign-On (SSO) architecture. The cryptographic JSON Web Tokens (JWTs) that define your secure session boundary are transmitted exclusively via HttpOnly,Secure cookies to prevent XSS exfiltration. If the browser refuses to store or transmit these tokens, the ArthaOps platform becomes mathematically incapable of verifying your identity. You will be permanently locked in an unauthenticated state, caught in an infinite redirection loop at the login boundary, entirely unable to access your workspace, view dashboard metrics, or execute cloud configuration mutations.
Security Protocol Disruption (CSRF Failures):Blocking cookies directly disables our robust Cross-Site Request Forgery (CSRF) defenses. Many critical platform actions, particularly within the billing, plan upgrade, and payment mutation flows facilitated by Razorpay, require the evaluation of synchronized CSRF tokens stored in transient session cookies to validate the authenticity and intent of the request. Without these tokens, our API gateways will, by default, aggressively reject all state-mutating requests (POST, PUT, DELETE), returning HTTP 403 Forbidden or 401 Unauthorized errors to protect the integrity of the system against synthetic automated attacks.
Degraded User Experience & Total State Loss:Blocking non-essential cookies and Web Storage APIs (localStorage/sessionStorage) will result in a highly degraded, high-friction user experience. The application will suffer immediate amnesia regarding your UI preferences. Dark mode toggles will fail to persist, forcing a jarring reset upon every page reload. Any complex, multi-step configuration wizards—such as the crucial AWS STS AssumeRole parameter setup—will lose their intermediate state if you navigate away or refresh, forcing you to begin the intricate process entirely from scratch. Furthermore, while disabling strictly non-essential telemetry (Sentry/PostHog) will not impair core Autopilot functionality, it completely blinds our engineering teams to any localized runtime exceptions you may encounter, severely degrading our ability to provide proactive, rapid-response technical support or debug edge cases specific to your AWS environment architecture.
The "Do Not Track" (DNT) header is a standardized HTTP field designed to allow users to broadcast a unilateral preference regarding cross-site tracking and data collection to remote web servers. Despite initial industry momentum and advocacy, the DNT specification has largely failed to achieve widespread adoption or standardized regulatory enforcement mechanisms across the broader technology ecosystem. Consequently, a vast majority of ad-tech platforms, web properties, and third-party networks systematically ignore the DNT signal.
ArthaOps adopts a fundamentally transparent and technically compliant posture regarding the DNT header. When our edge networking nodes (Next.js middleware) detect the presence of an active DNT: 1 signal embedded within an incoming HTTP request, our systems are programmed to ingest, log, and structurally honor this request in a deterministic manner. Specifically, the detection of a DNT signal immediately triggers an automated, preemptive override within our Consent Management Platform (CMP). This override categorically classifies the session as having explicitly opted-out of all non-essential Tracking Technologies. Consequently, the initialization sequences for all performance, telemetry, and optional analytical scripts (such as PostHog or marketing attribution tags) are aggressively aborted prior to execution. We ensure that our respect for the DNT signal is absolute, transforming a historically ignored HTTP header into a functional, highly effective privacy control mechanism within the confines of our sovereign platform architecture.
The digital compliance landscape, interpretations of the DPDPA 2023, and our internal platform architecture are subject to continuous, rapid evolution. To ensure absolute parity with emerging jurisprudential frameworks and to accurately reflect integrations of novel infrastructure technologies (such as the addition of new AWS cost waste detectors or billing mechanisms), ArthaOps reserves the unencumbered right to algorithmically or manually mutate the parameters of this Cookie Policy at our sole discretion. We firmly reject the practice of silent, undocumented policy modifications.
All material modifications to this Policy will be subject to a rigorous notification protocol. Should a revision introduce fundamentally new categories of data processing, integrate controversial third-party trackers, or significantly alter the legal basis upon which we deploy existing cookies, we will execute a mandatory, highly visible notification sequence across the ArthaOps dashboard. This may necessitate a renewed affirmative consent sequence upon your next authenticated session. For minor typographical corrections, formatting enhancements, or non-material clarifications, updates will be reflected silently via the "Last Updated" timestamp and version identifier prominently displayed in the header of this document. We mandate that you periodically review this unified changelog to maintain an accurate understanding of our current telemetry practices and security protocols.
| Version | Release Date | Material Modifications & Technical Context |
|---|---|---|
| 2.1.0 | July 27, 2026 | Comprehensive overhaul aligning with the finalized implementation rules of the DPDPA 2023. Restructured consent frameworks and introduced explicit, highly technical documentation regarding Web Storage APIs (localStorage/sessionStorage) usage and DNT signal handling. |
| 2.0.0 | January 15, 2026 | Integration of the Logto Cloud OIDC ecosystem. Obsoleted legacy internal JWT deployment schemas. Updated comprehensive cookie inventory table to reflect new OIDC session identifiers (logto_*) and updated Razorpay parameters. |
| 1.5.0 | August 10, 2025 | Deployment of PostHog analytics proxy. Shifted from standard third-party client-side rendering to a privacy-preserving first-party proxy architecture via AP-SOUTH-1 to bypass ITP/ETP restrictions while enhancing strict data minimization. |
If you require deep technical clarification regarding specific cookie payloads, wish to initiate a formal Subject Access Request (DSAR) under the DPDPA 2023 related to your telemetry data, or if you suspect an anomalous, unauthorized tracking vector executing within the ArthaOps domain, our Data Protection Officer (DPO) and dedicated legal engineering team are available for immediate consultation. We commit to a strict statutory 30-day resolution window for all formal privacy inquiries.
Corporate Entity: ArthaOps. Inc.
Registered Address: 61, Laxmi Nagar Zone, Dheku Road, Amalner, Dist. Jalgaon, Maharashtra 425401, India
Primary Legal Contact: legal@arthaops.com
Data Privacy & DPO Contact: privacy@arthaops.com
Security Operations Center (SOC): security@arthaops.com
Grievance Officer: grievance@arthaops.com
Business Operations: Monday–Friday, 9:00 AM – 6:00 PM IST