How Aranis protects your data and your vendors' data
Transparency about our security architecture, implemented controls, and secure development practices.
Hosting and data isolation
Aranis runs on Supabase infrastructure (managed PostgreSQL) with per-organization isolation via Row Level Security. Customer data is never shared between tenants.
Robust access control
Authentication via email + password with mandatory email confirmation and MFA available to users on the platform. Sessions with automatic expiration.
Encryption at every layer
HTTPS/TLS 1.3 on all connections. Data at rest encrypted by Supabase infrastructure. Keys managed by the cloud provider.
How we use AI with your data
AI analysis is performed via APIs of approved providers. Assessment data is sent for analysis and is not used to train external models. See our AI Usage Policy for details.
What we do if something goes wrong
Active monitoring of errors and availability. Notification to affected customers within 72h, inside the three-business-day deadline set by Brazil's ANPD. Direct channel: security@aranis.ai.
To report vulnerabilities or questions about our security posture:
security@aranis.ai