Security and Trust
Last updated: 24 August 2026
Security approach
Arad applies defense in depth across identity, application, data and operational controls, proportionate to service risk and contractual scope.
Identity and access
Administrative access is role-based and least-privilege oriented. Email verification, optional multi-factor authentication, secure password handling, lockout controls, session protection and audit trails support account security.
Application and data protection
We use input validation, output encoding, anti-forgery controls, restricted file types, protected secrets, encrypted sensitive payloads where appropriate, secure transport and separation of public and private media.
Operations
Logging, monitoring, backups, dependency maintenance and controlled deployment support resilience. Access and retention are reviewed according to operational and legal need.
Incident response
Suspected events are triaged, contained, investigated and remediated. Notification to affected customers or authorities is handled when required by contract or applicable law.
Customer responsibility
Customers should protect credentials, enable multi-factor authentication, assign minimum permissions, keep integrations updated and promptly report suspicious activity.
Assurance
Specific certifications, penetration-test results, architecture details, SLAs and contractual security commitments are provided only when formally available and subject to appropriate confidentiality.
