Cybersecurity Policy

Last updated: April 20, 2026

Arkonomy ("we", "our", or "us") is committed to protecting the confidentiality, integrity, and availability of user data and platform systems. This policy describes the controls we maintain to secure your information and our infrastructure.

1. Purpose and Scope

This policy applies to all Arkonomy systems, services, and infrastructure — including the web and mobile applications, backend services, third-party integrations, and any personnel or contractors with access to production systems.

The objective is to establish a consistent baseline of security controls that protects user financial data, prevents unauthorised access, and ensures continued platform availability.

2. Data Classification

All data handled by Arkonomy is classified into three tiers that govern how it is stored, accessed, and transmitted:

3. Access Control

Access to Arkonomy systems follows the principle of least privilege:

4. Encryption

All user data is protected by encryption at every layer:

5. Vulnerability Management

We maintain an active programme to identify and remediate security vulnerabilities:

To report a vulnerability, please contact us at hello@arkonomy.com. We ask that you allow us reasonable time to investigate before any public disclosure.

6. Incident Response and Disaster Recovery

In the event of a security incident, we follow a structured five-step response process:

Disaster recovery targets are maintained in line with our infrastructure providers' SLAs:

7. Physical Security

Arkonomy does not operate physical data centres. All compute, storage, and networking infrastructure is hosted on cloud platforms that maintain their own certified physical security controls:

8. Vendor Risk Management

All third-party vendors who access or process user data are evaluated for security posture and monitored on an ongoing basis:

Supabase (AWS)

SOC 2 Type II compliant. Provides database, authentication, storage, and serverless compute. All data remains within Supabase's encrypted, access-controlled environment. supabase.com/security

Vercel

SOC 2 Type II compliant hosting and edge compute platform used to serve the Arkonomy web application. vercel.com/security

Plaid

PCI DSS Level 1 and SOC 2 Type II certified. Handles all bank credential exchange and financial data aggregation. Arkonomy never receives or stores bank usernames, passwords, or MFA codes. plaid.com/legal/privacy-notice

Stripe

PCI DSS Level 1 certified payment processor. Arkonomy does not store, process, or transmit payment card data — all payment handling is performed directly by Stripe. stripe.com/docs/security

Anthropic (Claude AI)

Enterprise API with per-request data isolation. Only anonymised, aggregated spending summaries are sent — no raw transactions or personally identifiable information. Data is not used for model training under our API agreement. anthropic.com/privacy

9. Policy Review

This policy is reviewed at least annually, or following any significant security incident, major infrastructure change, or relevant regulatory development. Updated versions will be published at this URL with a revised effective date.

10. Contact

For security questions, vulnerability reports, or data security concerns, contact us at hello@arkonomy.com.

Please disclose vulnerabilities responsibly — contact us privately and allow reasonable time for investigation before any public disclosure.