Arcs LearningLearning IntelligenceLet's talk

Trust Center

Security, privacy, and the systems we trust

This page is maintained by Arc Strata Systems, Inc. to answer common security, privacy, and compliance questions about Arcs. It describes practices in effect today and the subprocessors we rely on to deliver our services.

Overview

Arcs helps organizations connect, migrate, and unlock value from learning data. Because that data is often sensitive, we treat security and privacy as foundational, not features. Our approach is layered: strong access controls for our team, encryption in transit and at rest through our infrastructure providers, least-privilege data handling, and clear contractual protections with our customers and subprocessors.

Nothing on this page constitutes an independent certification or audit result. Where we describe capabilities of the platforms we build on, those descriptions are drawn from those providers' public documentation.

Data collection and use

We only collect the data we need to deliver our services and operate our business. That includes: account and contact information you provide, learning data you or your integrations authorize us to process on your behalf, and standard operational telemetry (request logs, performance metrics, error reports) needed to run the platform reliably.

Customer learning data is processed under the terms of your agreement with Arcs and is not used to train shared or third-party foundation models. Where AI features operate on your data, they do so in the context of your tenant and your instructions.

Access and authentication

  • Access to production systems is limited to authorized Arcs personnel with a business need.
  • All internal accounts require multi-factor authentication.
  • Administrative actions on customer environments are logged.
  • Employee access is reviewed and revoked promptly upon role change or departure.

Infrastructure and encryption

Arcs runs on major cloud providers (see subprocessors below). Data is encrypted in transit using TLS and encrypted at rest using the encryption features provided by our underlying storage and database services. Network access to production data stores is restricted to Arcs services running within private networks.

Incident response

Arcs maintains an internal incident response process covering detection, containment, customer notification, and post-incident review. If we become aware of a security incident that affects your data, we will notify affected customers without undue delay and share the information you need to meet your own obligations.

To report a suspected vulnerability or security issue, email security@arcslearning.com.

Subprocessors

We rely on a small number of vetted service providers ("subprocessors") to deliver Arcs. Each is bound by contractual data protection commitments. This list is maintained as our systems evolve; customers with active agreements are notified of material changes as described in their contract.

Provider
Purpose
Data processed
Region
Amazon Web Services (AWS)
Cloud hosting and infrastructure
All customer data at rest and in transit
United States, European Union
Cloudflare
CDN, DNS, and edge security
Request metadata, IP addresses
Global edge network
Google Workspace
Business email and internal collaboration
Customer contact information
United States
HubSpot
CRM and customer communications
Contact name, email, company, message content
United States, European Union
Stripe
Payment processing (where applicable)
Billing contact and payment metadata
United States

Privacy requests

If you are an end user of a customer's Arcs-powered experience, please contact that organization first — they act as the controller of your data. If you are an Arcs customer or need to reach us directly, email privacy@arcslearning.com.

Last updated: August 2026. Have a question this page doesn't answer? Get in touch.