Security

Your customers, staff, and business records deserve careful handling. Here is an overview of our safeguards and the current limits of the beta.

Last updated September 14, 2026.

Business data and access

ArkSlate uses access controls to keep business workspaces separate and restrict what each team member can do. Owners manage staff permissions and connected devices. Sensitive activity is recorded to help you review changes in your workspace.

Encryption and payments

Business data is encrypted in transit and at rest. Card payments are processed by Stripe; ArkSlate does not store card numbers.

Service continuity

We monitor service health and publish updates on our status page. There is no contractual uptime SLA during beta, and we do not currently publish recovery time or recovery point commitments. Keep a copy of important records using the export formats available in your workspace.

Evaluating ArkSlate for your business?

Contact security@arkslate.com to discuss your security requirements or request a technical review. Our Privacy Policy describes how personal information is handled and identifies our service providers.

Where we are not yet

Please take these limits into account when evaluating ArkSlate:

  • We are not SOC 2 or ISO 27001 certified. No audit has been performed and no report exists. Our controls have not been independently audited.
  • We do not currently sign Business Associate Agreements. ArkSlate includes configuration and audit tooling for medical settings, but that tooling is not a compliance program and we are not a HIPAA business associate today. Do not put protected health information into ArkSlate on the assumption that it is covered — it is not.
  • There is no paid bug bounty yet. Reports are still welcome, and treated seriously.

Reporting a vulnerability

If you believe you have found a security problem in ArkSlate, please email security@arkslate.com with enough detail to reproduce it. We will acknowledge within two business days and keep you updated until it is resolved.

We will not pursue legal action against anyone who reports a vulnerability in good faith, gives us a reasonable opportunity to fix it before disclosing it publicly, and does not access, modify, or delete data belonging to anyone else while investigating. Please do not run automated scanning against production, and please do not test against another business's tenant — if you need an account to test with, ask us and we will make you one.

Questions

Security questions during an evaluation are welcome and we would rather answer them than have you guess. Email security@arkslate.com. For how we handle personal information specifically, see our Privacy Policy; for the contractual side, our Terms of Service.