Built With Enterprise Security Practices in Mind
An overview of the security principles guiding the Trust Platform's design. Detailed architecture, audit and certification documentation is shared directly with enterprise and technical evaluators.
Our Approach
Security Principles Guiding the Trust Platform
We do not claim certifications or completed audits that have not been obtained. Where formal certification (e.g. ISO 27001, SOC 2) is pursued, it will be documented here with evidence.
Security Architecture
Designed with clear boundaries between what runs on-device and what runs in Arjuna's services.
Encryption in Transit & at Rest
Designed so data is encrypted both while moving between systems and while stored.
Authentication & Authorization
Designed around least-privilege access for every API, service and integration.
Secrets & Key Management
Designed to keep credentials and keys out of application code and version control.
Tenant Isolation
Designed so enterprise customer data is logically separated between tenants.
Logging & Monitoring
Designed to give visibility into platform activity and anomalies as the enterprise product matures.
Vulnerability Management
Designed around a process for identifying, prioritizing and remediating vulnerabilities.
Secure SDLC
Designed to build security review into the development lifecycle rather than after the fact.
Incident Response
Designed around a defined process for identifying, containing and communicating security incidents.
Business Continuity
Designed with resilience and recovery in mind as the platform moves toward production readiness.
FAQ
Common Security Questions
Does Arjuna have ISO 27001 or SOC 2 certification?
Not at this time. We do not claim certifications or completed audits that have not been obtained. If formal certification is pursued, it will be documented here with evidence once achieved.
How is customer data isolated between different enterprise customers?
The platform is designed so enterprise customer data is logically separated between tenants — one of the core principles guiding the Trust Platform's architecture. The specific isolation model is confirmed directly with enterprise and technical evaluators.
What happens if a security vulnerability is found in the platform?
The platform is designed around a defined process for identifying, prioritizing and remediating vulnerabilities, and a separate defined process for incident response — identifying, containing and communicating security incidents. Detailed procedures are shared directly with technical evaluators.
Can we get detailed security architecture documentation for a vendor review?
Yes — detailed architecture, audit and certification documentation is shared directly with enterprise and technical evaluators as part of the evaluation process, rather than published in full on this page.
Explore the Trust Platform

