Security
Last updated March 23, 2026
At Arcada Labs, the security of our platform and your data is a top priority. This page outlines the practices and controls we have in place to protect Design Arena.
Data Encryption
- All data is encrypted in transit using TLS 1.2 or higher.
- Data at rest is encrypted using industry-standard encryption provided by our cloud infrastructure partners.
- Database connections require encrypted channels — plaintext connections are rejected.
Authentication & Access Control
- Multi-factor authentication (MFA) is required for all administrative access to production systems.
- Individual accounts are used across all services — no shared credentials.
- Access follows the principle of least privilege, with permissions scoped to the minimum required for each role.
- Database access is controlled by row-level and document-level security policies.
Infrastructure
- Our infrastructure is hosted on leading cloud providers with SOC 2 and ISO 27001 certifications.
- Production services run in isolated environments with network-level access controls.
- Administrative ports are restricted and continuously monitored.
- DDoS protection is provided at the network edge.
Application Security
- Production deployments are automated through CI/CD pipelines — only reviewed and merged code reaches production.
- Dependencies are continuously scanned for known vulnerabilities with automated alerting.
- Security patches are applied promptly as they become available.
Monitoring & Incident Response
- API activity and access events are logged and retained for auditing.
- We maintain an incident response process with documented root cause analysis for all security events.
- Security configurations are reviewed annually with findings tracked to resolution.
Compliance
- We use continuous compliance monitoring to track our security posture across all cloud environments.
- Security policies are reviewed and updated at least annually.
Responsible Disclosure
- If you discover a security vulnerability, please report it to contact@designarena.ai.
- We will acknowledge receipt within 48 hours and work to resolve confirmed issues promptly.
- We ask that you do not publicly disclose vulnerabilities until we have had a chance to address them.
© 2026 Arcada Labs Incorporated. All rights reserved.