Security
Last updated September 14, 2026
At Arcada Labs, the security of our platform and your data is a top priority. Design Arena implements appropriate technical and organisational measures to protect Data, including:
Authentication & Access Control
- Access management policies addressing user provisioning based on the least privilege principle, enabling only authorised personnel to have access to systems and data.
- Role-based access controls allowing access to Data only on a need-to-know basis.
- Use of multi-factor authentication (MFA) for access to systems containing Data.
- Prompt revocation of access upon employee termination or role change.
- Individual accounts are used across all services — no shared credentials.
- Database access is controlled by row-level and document-level security policies.
- Access follows the principle of least privilege, with permissions scoped to the minimum required for each role.
Security Awareness and Training
- Security awareness training for all employees at onboarding and annually thereafter.
- Targeted training for employees with access to sensitive data or elevated privileges.
Security Assessments
- Annual vulnerability assessments and penetration testing of systems that process Data.
- Remediation of identified vulnerabilities based on severity.
- Production deployments are automated through CI/CD pipelines — only reviewed and merged code reaches production.
- Dependencies are continuously scanned for known vulnerabilities with automated alerting.
- Security patches are applied promptly as they become available.
Monitoring & Incident Response
- Security incident response plans emphasizing detection, containment, eradication and recovery.
- Annual review and testing of incident response procedures.
- Application and infrastructure security audit logs to support operational troubleshooting, auditing, and security investigations.
- We maintain an incident response process with documented root cause analysis for all security events.
- Security configurations are reviewed annually with findings tracked to resolution.
Data Encryption
- Encryption of Data at rest using industry-standard encryption (e.g., AES-256) provided by our cloud infrastructure partners.
- Encryption of Data in transit using TLS 1.2 or higher.
- Database connections require encrypted channels — plaintext connections are rejected.
Business Continuity
- Regular backups of Data with encryption.
- Backups stored in a location geographically-separated from the primary data storage location.
Infrastructure
- Infrastructure hosted on leading cloud providers with SOC 2 and ISO 27001 certifications.
- Production services run in isolated environments with network-level access controls. Administrative ports are restricted and continuously monitored.
- DDoS protection is provided at the network edge.
- Disaster recovery procedures to restore availability and access to Data in the event of a physical or technical incident.
- Maintained backup and recovery procedures for covered workspace data. Coverage, retention periods, and recovery procedures depend on the affected system and its backup configuration.
Personnel Security
- Background checks for employees with access to Data, to the extent permissible under applicable law.
- Confidentiality agreements executed by employees and contractors with access to Data.
Compliance
- We use continuous compliance monitoring to track our security posture across all cloud environments.
- Security policies are reviewed and updated at least annually.
Responsible Disclosure
- If you discover a security vulnerability, please report it to contact@designarena.ai.
- We will acknowledge receipt within 48 hours and work to resolve confirmed issues promptly.
- We ask that you do not publicly disclose vulnerabilities until we have had a chance to address them.
© 2026 Arcada Labs Incorporated. All rights reserved.