Security
Claims you can check, and the ones we cannot make yet.
Most security pages list attestations. This one lists mechanisms — where each guarantee lives in the code — and then says plainly what is still in progress.
What the code enforces
Six guarantees, each with its mechanism.
The record is append-only.
The audit table is partitioned and append-only at the database level. Retention settings, access, answers and connector changes all land in it. There is no edit path, for anyone.
Enforced in the schema.
Clearance at answer time.
Entitlement is checked when an answer is composed, not just when a document is filed. Answers cite their sources, so over-disclosure is detectable rather than silent.
Enforced in the vault.
Managers get shape, not messages.
Manager roll-ups are off by default, per tenant. The engine drops any finding it cannot quote verbatim, and a jurisdiction kill switch stays in the code even under a permanent-on policy.
Enforced by tests that fail the build.
It drafts. People send.
The manager-intelligence package holds no send capability — a test fails the build if any source file imports a mail transport. Chasers and replies are drafts, addressed to a person.
Structural, not attested.
Raw mail is purged on a clock.
Message bodies are encrypted at rest and deleted on the retention schedule you set. What Arlo learned from them stays; the original does not linger.
Configured under Governance → Retention.
Who you are, from your directory.
SAML and OIDC sign-in, SCIM provisioning and de-provisioning, seats enforced at the door. When someone leaves your directory, they leave Arlo.
SSO + SCIM shipped.
What stays where
One door. You can read what goes through it.
On-prem or cloud, the list is short enough to print.
Stays with you, always
- Mail bodies and the index
- Files and the vault
- Drafts and roll-ups
- The audit record
Goes out, per request
- The text being worked on, to the model endpoint you configure — Arlo's gateway or your own
- Nothing is retained by the model provider or trained on
Fully local inference — a model running inside your building with nothing leaving — is in progress and is the bar we set for calling Teams v1 done. Until it ships we say so here rather than imply it elsewhere.
What we do not have yet
Said plainly.
SOC 2
Not yet. The controls above are real and checkable today; the audit of them is not booked. We will not print a badge before there is a report.
A trust center
Not yet. This page and the sub-processor list are the trust center for now, and both are versioned in the open.
Self-serve deletion
Closing a workspace is a request to privacy@arlo.fyi, done within thirty days, with the ledger entry to prove it.
Send us your questionnaire.
A real person answers it, with file paths where the answer is code.