Security

How Aranis protects your data and your vendors' data

Transparency about our security architecture, implemented controls, and secure development practices.

Infrastructure

Hosting and data isolation

Aranis runs on Supabase infrastructure (managed PostgreSQL) with per-organization isolation via Row Level Security. Customer data is never shared between tenants.

Authentication

Robust access control

Authentication via email + password with mandatory email confirmation and MFA available to users on the platform. Sessions with automatic expiration.

Data in transit and at rest

Encryption at every layer

HTTPS/TLS 1.3 on all connections. Data at rest encrypted by Supabase infrastructure. Keys managed by the cloud provider.

AI and data

How we use AI with your data

AI analysis is performed via APIs of approved providers. Assessment data is sent for analysis and is not used to train external models. See our AI Usage Policy for details.

Incident response

What we do if something goes wrong

Active monitoring of errors and availability. Notification to affected customers within 72h, inside the three-business-day deadline set by Brazil's ANPD. Direct channel: security@aranis.ai.

Security contact

To report vulnerabilities or questions about our security posture:

security@aranis.ai