Trust & security
Archon is a system of record for how your business actually operates. That only works if you can trust us with the data. Here is the shortest version of what we commit to, how we enforce it, and where to verify each claim.
GDPR & CCPA operational
We process personal data under lawful bases documented in our Privacy Policy, respond to data-subject requests (access, deletion, correction), and sign Standard Contractual Clauses for EU/UK transfers.
Privacy Policy →Data Processing Addendum
We sign DPAs with customers who need one. Our template covers processor obligations, SCC Module 2, technical and organizational measures, and sub-processor flow-down.
View DPA →Sub-processors disclosed
Every third-party service we use to deliver Archon is listed publicly with purpose, data categories, and region. We commit to 30 days’ notice before adding new ones.
Sub-processors list →Your data, your controls
Any signed-in user can export a complete JSON archive of their account and its associated records, or schedule account deletion with a 7-day grace window. No support ticket required.
Privacy controls →Tenant isolation
Multi-tenant data is separated at three layers: Postgres row-level security on every org-scoped table, application-level membership checks on every mutation, and per-organization scoping in the vector store.
Secrets & rotation
All credentials are stored in environment variables, never in code or the frontend. We rotate AI-provider keys quarterly, service-role keys annually (or immediately on suspicion), and log every rotation.
Audit trail
Sensitive mutations — member invites, role changes, SOP exports, account deletions — are logged with actor, IP, and user-agent. Organization admins can review their trail.
Incident response
We maintain a breach-response runbook with a 72-hour GDPR notification clock and a customer-communication template. Report suspected issues to security@regnor.systems.
Roadmap
We ship what we can verify today and name what is coming so enterprise buyers can plan around it:
- ●Today: GDPR/CCPA operational, DPA available, sub-processors disclosed, audit log, export/erasure self-service.
- ◐Next 6 months: SSO/SAML for enterprise plans, signed BAA-style addenda for regulated-data pilots, vulnerability scanning in CI.
- ○12–18 months: SOC 2 Type I then Type II, independent penetration test, formal vendor-risk program.
Data we do not accept
Archon is not designed for regulated data. Our Terms explicitly prohibit uploading or processing:
- Protected health information subject to HIPAA
- Cardholder data subject to PCI-DSS
- Financial records subject to SOX or similar audit regimes
- Personal data of EU children under 16
- Export-controlled technical data
See Terms of Service §5 for the full list.
Questions?
Security or compliance questions, including vendor assessment questionnaires: security@regnor.systems. We respond within two business days.