Your financial data, protected by design
ArcPay runs on infrastructure trusted by thousands of finance teams, with isolation, encryption, and Singapore data residency built into every layer.
SOC 2 Type 2 infrastructure
Runs on Supabase and Vercel — both independently SOC 2 Type 2 certified.
Encrypted end to end
AES-256 at rest and TLS 1.2+ in transit on every connection.
Singapore data residency
Your data is stored in the Singapore (ap-southeast-1) region.
Row-level isolation
Postgres row-level security keeps every account’s data separate.
How we protect your data
Your data is isolated at the database layer
Every table is governed by row-level security policies. One account can never read another account’s invoices, bills, or bank records — isolation is enforced by Postgres itself, not just application code.
We never move your money
ArcPay is an accounting tool, not a financial institution. We never hold, move, or intermediate funds. Bank data enters ArcPay only through statement files you choose to upload — we do not connect to your bank.
Least-privilege access
User-facing requests run on anon-scoped, session-authenticated clients. Elevated service-role keys are reserved for narrow administrative tasks and are never exposed to the browser.
Your data never trains AI models
AI features run on Anthropic Claude under our enterprise agreement. Your invoices, bank data, and books are never used to train any AI model.
Passwords and secrets
Passwords are hashed, never stored in plain text. Authentication, session management, and secret storage are handled by Supabase Auth.
Backups and recovery
Your ledger is backed up automatically every day, so data can be restored after accidental loss.
Compliance posture
IRAS-ready records
GST and reporting follow Singapore tax rules, with 7-year retention.
SOC 2 readiness in progress
We’re building toward our own SOC 2 Type 2 attestation. Until it’s issued, we’re happy to share a security overview on request.
Have a security question or need a vendor security review? info@arcpaysg.com. See also our Privacy Policy and Terms.