Security
Overview

How Arnio Protects Your Data

Arnio processes Merchant Data as a data processor on behalf of merchants. This document describes the technical and organizational measures in place to protect Merchant Data and Shopper Engagement Signals at every layer of the platform.


1. Overview

Arnio is a behavioral intelligence platform that helps Shopify merchants understand shopper intent. Arnio acts as a data processor on behalf of merchants. Merchant Data, Shopper Engagement Signals, and Behavioral Data collected on a merchant's storefront belong to that merchant.

This document describes the technical and organizational security measures Arnio uses to protect that data.

2. Security Principles

Arnio's security program is organized around five core principles:

  • Least privilege: every team member and system component has only the access required to perform its function.
  • Defense in depth: multiple layers of controls, not a single perimeter.
  • Encryption everywhere: Merchant Data is encrypted in transit and at rest.
  • Auditability: access to production systems and sensitive data is logged and retained.
  • Transparency: Arnio documents its security practices and makes them available for review.

3. Infrastructure & Hosting

Arnio's backend API runs on Railway. The marketing site and merchant dashboard run on Vercel. Arnio does not operate physical hardware or data center infrastructure.

Controls implemented at the infrastructure layer include:

  • Production, staging, and development environments are isolated from each other.
  • Automated dependency auditing identifies and flags vulnerable packages.
  • Deployments use zero-downtime rollouts with automated rollback capabilities.
  • Customer-facing services are separated from internal tooling.

4. Encryption

Merchant Data and Shopper Engagement Signals are encrypted at every stage:

  • In transit: all data transmitted between Arnio services, the tracking script, and the merchant dashboard uses TLS 1.2 or higher.
  • At rest: all stored Merchant Data is encrypted using AES-256.
  • Encryption keys are managed through cloud provider key management systems.

5. Access Controls

Access to Merchant Data is governed by role-based access controls (RBAC):

  • Access is granted on a least-privilege basis. No team member has broader access than their role requires.
  • Access to production systems is restricted to a small number of authorized individuals.
  • Access privileges are reviewed on a regular schedule.
  • All access to production data generates audit log entries.

6. Authentication

All Arnio team members with access to production systems are required to use multi-factor authentication (MFA).

Customer-facing authentication is handled by Clerk, using Google SSO and Shopify OAuth. Arnio does not store user passwords. Session tokens are managed by Clerk.

7. Monitoring & Alerting

Arnio monitors infrastructure and application events continuously:

  • Infrastructure health, error rates, and latency are monitored in real time.
  • Security-relevant events (authentication failures, permission escalations, and unusual access patterns) trigger automated alerts.
  • Application and access logs are retained for a minimum of 90 days.
  • On-call procedures are in place for responding to alerts outside business hours.

8. Data Protection & Backups

Arnio maintains the following data protection controls:

  • Automated backups run on a regular schedule across all production data stores.
  • Backup integrity is verified periodically through restoration testing.
  • Merchant Data is logically isolated by merchant identifier. One merchant's data cannot be accessed from another merchant's account.
  • Data deletion requests are honored within 30 days of receipt.

9. Privacy Commitments

Merchant Data and Shopper Engagement Signals are processed solely to provide the Arnio service to the merchant. Merchant Data is never:

  • Sold to any third party.
  • Shared with other merchants or customers.
  • Used to train public AI or machine learning models.
  • Used to create identifiable cross-customer benchmarks or Customer-specific Insights for other merchants.

Aggregated, anonymized platform analytics (system performance metrics, error rates, and feature usage patterns) may be used to improve Arnio's reliability, security, and performance. This data cannot be used to identify individual merchants or shoppers.

10. Incident Response

Arnio maintains an incident response plan that defines:

  • Escalation paths and on-call responsibilities for security events.
  • Breach containment and forensic investigation procedures.
  • Merchant notification procedures in the event of a confirmed data breach.
  • Post-incident review and remediation requirements.

In the event of a confirmed breach affecting Merchant Data, Arnio will notify affected merchants within 48 hours of discovery. Notification will include the nature of the breach, categories of data involved, and remediation steps taken or planned.

11. Compliance Roadmap

Arnio is actively working toward SOC 2 Type II certification, with a target completion during Q3 2026. Until certification is complete, Arnio makes its security practices available for review on request.

Arnio actively monitors compliance with:

  • General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Applicable data policies from Shopify and Klaviyo

SOC 2 Type II: In progress. Target completion Q3 2026. Compliance documentation and security review materials are available to prospective enterprise customers on request.

12. Contact

For security questions, responsible disclosure reports, or compliance review requests:

security@arnio.co

Last updated: July 2026 · Arnio Inc. · Austin, Texas