Security

What is built, and what is not yet.

A product that asks you to check every claim should let you check its own. This page lists both columns.

SatoriArc is in alpha and is not yet running in production. "Built" means the control is in the product and tested; a row will say "In production" only once it is running there.

ControlStatusDetail
Tenant isolationBuilt, not yet in productionEach customer's records are separated by row-level security policies in the database. The application connects as a role that cannot bypass them.
Second factorBuilt, not yet in productionPasskeys first, or an authenticator app, with one-time recovery codes. Required for every role that can connect a mailbox, and for anyone who has enrolled one. A locked factor unlocks on a doubling delay.
Changing a factorBuilt, not yet in productionAdding or removing a sign-in factor asks you to prove yourself again, and ends your other sessions.
Mailbox accessBuilt, not yet in productionOAuth, never your password. SatoriArc writes drafts and reads only delivery failures and auto-replies on threads it created. Stored mailbox tokens are encrypted.
Tamper-evident logsBuilt, not yet in productionSign-ins, administrative changes, refused access, data access and exports, and our own staff's access are each written to an append-only, hash-chained log. Account owners can read their sign-in and administrative history in the product.
Our staff's accessBuilt, not yet in productionEvery action our staff take on a customer's account is recorded with a named person and a stated reason.
BackupsBuilt, not yet in productionNightly, encrypted, and restored automatically to prove they work. Kept for about 90 days.
MonitoringBuilt, not yet in productionA failed job, a broken mailbox connection or a missed backup sends an alert, and an outside check notices if the system stops reporting.
SOC 2Not yetNot yet audited.
Independent penetration testNot yetNot yet performed.
Single sign-on (SAML/OIDC)Not yetNot yet available.
Log anchoringNot yetOur logs reveal an edited entry, or one removed from the middle, but not yet the removal of the newest entries. Anchoring them outside the system is planned.
Direct database administrationNot yetNot yet recorded in the staff access log.

Last reviewed 3 October 2026. This page changes as the product does.

Report a vulnerability

If you think you've found a security problem, email security@satoriarc.com with what you found and how to reproduce it. We'll acknowledge it, keep you informed and credit you if you'd like. Please don't access other people's data or degrade the service while testing.

Our security.txt has the same contact.