Security
What is built, and what is not yet.
A product that asks you to check every claim should let you check its own. This page lists both columns.
SatoriArc is in alpha and is not yet running in production. "Built" means the control is in the product and tested; a row will say "In production" only once it is running there.
| Control | Status | Detail |
|---|---|---|
| Tenant isolation | Built, not yet in production | Each customer's records are separated by row-level security policies in the database. The application connects as a role that cannot bypass them. |
| Second factor | Built, not yet in production | Passkeys first, or an authenticator app, with one-time recovery codes. Required for every role that can connect a mailbox, and for anyone who has enrolled one. A locked factor unlocks on a doubling delay. |
| Changing a factor | Built, not yet in production | Adding or removing a sign-in factor asks you to prove yourself again, and ends your other sessions. |
| Mailbox access | Built, not yet in production | OAuth, never your password. SatoriArc writes drafts and reads only delivery failures and auto-replies on threads it created. Stored mailbox tokens are encrypted. |
| Tamper-evident logs | Built, not yet in production | Sign-ins, administrative changes, refused access, data access and exports, and our own staff's access are each written to an append-only, hash-chained log. Account owners can read their sign-in and administrative history in the product. |
| Our staff's access | Built, not yet in production | Every action our staff take on a customer's account is recorded with a named person and a stated reason. |
| Backups | Built, not yet in production | Nightly, encrypted, and restored automatically to prove they work. Kept for about 90 days. |
| Monitoring | Built, not yet in production | A failed job, a broken mailbox connection or a missed backup sends an alert, and an outside check notices if the system stops reporting. |
| SOC 2 | Not yet | Not yet audited. |
| Independent penetration test | Not yet | Not yet performed. |
| Single sign-on (SAML/OIDC) | Not yet | Not yet available. |
| Log anchoring | Not yet | Our logs reveal an edited entry, or one removed from the middle, but not yet the removal of the newest entries. Anchoring them outside the system is planned. |
| Direct database administration | Not yet | Not yet recorded in the staff access log. |
Last reviewed 3 October 2026. This page changes as the product does.
Report a vulnerability
If you think you've found a security problem, email security@satoriarc.com with what you found and how to reproduce it. We'll acknowledge it, keep you informed and credit you if you'd like. Please don't access other people's data or degrade the service while testing.
Our security.txt has the same contact.