FAQCopy as MarkdownFrequently asked questions about ARCY's security posture.Where is ARCY hosted, and is traffic encrypted in transit?Is our data encrypted at rest?Do you have Zero Data Retention (ZDR) with your AI provider?How are our API keys protected?Can ARCY employees see our customers' data?What internal access controls exist for the ARCY team?How do you isolate one customer's data from another?Do you offer dedicated infrastructure for enterprise customers?What stops a Flow from taking an action we didn't authorize?Do you have a responsible disclosure program?Have you had an external penetration test?What is your incident response process?What happens to our data if we stop using ARCY?How do you handle arcy.js versioning and breaking changes?If ARCY itself goes down, does our app break too?Can we cap how much the agent does, to control cost or runaway usage?