How we protect our platform and our customers' data.
Security is foundational to everything ARQQ builds.
SOC 2 Type II certified. ISO 27001 compliant. GDPR, CCPA, and PDPA adherent. Audit reports available under NDA.
AES-256 encryption at rest, TLS 1.3 in transit. Zero-trust workload identity via SPIFFE/SPIRE.
Hardware MFA for all employees. Least-privilege access enforced via automated policy.
Continuous automated scanning. Annual third-party penetration testing. Critical vulnerabilities patched within 24 hours.
Report vulnerabilities: security@arqq.net