Data Privacy
Your documents and workspace data remain private and are never used to train AI models.


Arca protects your scientific and regulatory work with enterprise-grade infrastructure, strict data controls, and AI safeguards designed for sensitive life sciences workflows.
Arca upholds the highest rigor to comply to safety and security.
Your documents and workspace data remain private and are never used to train AI models.
All data is encrypted at rest and in transit using industry-standard encryption protocols.
Arca runs on hardened cloud infrastructure with continuous monitoring and network isolation.
Role-based permissions and SSO ensure only authorized users can access sensitive research and regulatory work.
Every action is recorded through detailed audit logs to support transparency and accountability.
AI operates within secure processing environments designed to preserve confidentiality and scientific oversight.
Enforceable commitments backed by independent audits and industry-recognized frameworks.
SOC 2 Type II certified, with independent audits validating our data security, availability, and confidentiality controls.
Enterprise authentication and activity logs deliver secure access control and full system visibility.
GDPR compliant with data residency, processing agreements, and controls to protect EU personal data
Dedicated environments, scoped permissions, and tenant-level controls keep customer work isolated.
Answers to common questions about how Arca handles and protects your data.
No. Arca does not use customer data to train general-purpose machine learning models. Your data is processed solely to deliver the services you have contracted for, as set forth in our Security Policy and Data Processing Agreement.
Arca employs encryption in transit, least-privilege access controls, continuous logging and monitoring, and third-party security tooling. Access to customer data is restricted to authorized personnel on a need-to-know basis. Our full Security Policy is publicly available, and we respond to security due diligence questionnaires upon written request.
Arca maintains a formal incident response process. In the event of a confirmed security incident affecting customer data, we will notify affected customers without undue delay — and no later than 72 hours after becoming aware of the incident — consistent with our DPA obligations and applicable law.
Yes. Arca offers a standard DPA covering processor/subprocessor relationships. You can review it at arca.inc/legal/dpa or contact us at contact@arca.inc to execute a countersigned copy.
You do. Customers retain full ownership of their data at all times. Arca holds only a limited right to process your data as necessary to deliver the services as directed by you, consistent with our Terms of Service and Data Processing Agreement.
Yes. You may request deletion of your customer data at any time. Arca will fulfill deletion requests as soon as reasonably practicable, except where further retention is required by applicable law, as described in our DPA.
Arca relies on reputable cloud service providers and subprocessors bound by security and confidentiality obligations consistent with our Security Policy. A current subprocessor list is available upon request.
Yes. Enterprise customers requiring bespoke contract terms may negotiate a Master Services Agreement. Please reach out to contact@arca.inc to begin the process.
Yes. Contact us at contact@arca.inc to schedule a personalized demo with our team.