Security

Last updated March 23, 2026

At Arcada Labs, the security of our platform and your data is a top priority. This page outlines the practices and controls we have in place to protect Design Arena.

Data Encryption

  • All data is encrypted in transit using TLS 1.2 or higher.
  • Data at rest is encrypted using industry-standard encryption provided by our cloud infrastructure partners.
  • Database connections require encrypted channels — plaintext connections are rejected.

Authentication & Access Control

  • Multi-factor authentication (MFA) is required for all administrative access to production systems.
  • Individual accounts are used across all services — no shared credentials.
  • Access follows the principle of least privilege, with permissions scoped to the minimum required for each role.
  • Database access is controlled by row-level and document-level security policies.

Infrastructure

  • Our infrastructure is hosted on leading cloud providers with SOC 2 and ISO 27001 certifications.
  • Production services run in isolated environments with network-level access controls.
  • Administrative ports are restricted and continuously monitored.
  • DDoS protection is provided at the network edge.

Application Security

  • Production deployments are automated through CI/CD pipelines — only reviewed and merged code reaches production.
  • Dependencies are continuously scanned for known vulnerabilities with automated alerting.
  • Security patches are applied promptly as they become available.

Monitoring & Incident Response

  • API activity and access events are logged and retained for auditing.
  • We maintain an incident response process with documented root cause analysis for all security events.
  • Security configurations are reviewed annually with findings tracked to resolution.

Compliance

  • We use continuous compliance monitoring to track our security posture across all cloud environments.
  • Security policies are reviewed and updated at least annually.

Responsible Disclosure

  • If you discover a security vulnerability, please report it to contact@designarena.ai.
  • We will acknowledge receipt within 48 hours and work to resolve confirmed issues promptly.
  • We ask that you do not publicly disclose vulnerabilities until we have had a chance to address them.

© 2026 Arcada Labs Incorporated. All rights reserved.

Security | Design Arena