Trust & Governance · Enterprise Security Architecture
Enterprise-grade zero-token cloud custody, database-level multi-tenant isolation, and preflight rollback safety.
ArthaOps discovery and remediation run exclusively on ephemeral, least-privilege cloud IAM credentials (AWS STS AssumeRole with External ID, Azure Managed Identities, GCP Workload Identity, and Kubernetes RBAC). The platform never requests, stores, or persists permanent access keys, passwords, or cloud root credentials in its databases.
Tenant boundaries are enforced directly at the database engine layer using PostgreSQL Row-Level Security (RLS). RLS operates as a fail-closed boundary, preventing any workspace from querying or modifying resources belonging to another tenant, regardless of application-level routing.
All customer configuration, cloud identifiers, and metadata are encrypted at rest using AES-256-GCM symmetric envelope encryption (KMS v2). All data in transit is encrypted via TLS 1.3. Environment secrets are strictly segregated between environments using platform-native encrypted vaults.
Before any optimization action is executed, a preflight safety validation evaluates the target resource. Full state snapshots are recorded prior to mutation to guarantee deterministic 1-click rollback capabilities across all connected cloud resources.
Every infrastructure scan, anomaly discovery, and optimization action is sealed into an immutable, append-only audit trail with SHA-256 cryptographic verification for SOC 2 reviews and enterprise governance.
Looking for our formal commitments regarding Indian data residency under the Digital Personal Data Protection Act (DPDPA 2023), zero cross-border telemetry export, and presentation-edge financial exactness?
Explore The Sovereign Proxy GuaranteeIf you identify a security vulnerability or susceptibility within the ArthaOps platform, please disclose it to our security team. We take all reports seriously and will validate and coordinate remediations in a timely manner.
To report a security vulnerability, send a detailed diagnostic report to our Security Response Team at security@arthaops.com.