Araptus builds security-first infrastructure for small businesses — the same discipline enterprises expect, without the enterprise price tag. Full disk encryption protects data at rest on the disk; we add layers above that: isolation, hardened auth, and defenses on every request. This page is the plain-English version of what your IT or security team would ask us in a questionnaire.

Want the detailed version? Reach out — we respond to security reviews and can share documentation under NDA.

How we protect your data

Per-client isolation

Every client runs on their own isolated stack — dedicated database, deployment, and services. No shared infrastructure between clients, so one account is never a path into another.

Encryption everywhere

Data is encrypted in transit (TLS/HTTPS on every request) and at rest in the database. No credentials or API keys are ever exposed to the browser — all sensitive calls run server-side.

Hardened authentication

Passwordless magic-link sign-in, multi-factor authentication, WebAuthn passkeys, and cryptographic device binding (a non-exportable key per trusted device) — so a leaked password alone gets no one in.

Least-privilege access

Row-level security scopes every record to its owner, role-based permissions gate what each user can see and do, and administrative access is locked to a fixed allow-list.

Application-layer defenses

Every request passes through a security layer: rate limiting, IP blocking, honeypot traps, bot verification (Cloudflare Turnstile), scanner detection, a strict Content-Security-Policy, and hardened security headers.

Signed deployments

Every deployment carries an HMAC-signed manifest recording who deployed it — a tamper-evident record of ownership and change, not an anonymous push.

Monitoring & logging

Error tracking and structured logging run across the stack, with dedicated security-event logging and alerting so unusual activity is seen, not missed.

Payment security

Payments are processed by Stripe (PCI-DSS Level 1). We never see or store full card numbers — only billing status and invoice metadata.

Your data is yours

  • You own it, always. Your content, your customers, and everything in your databases belong to you — during our engagement and after it.
  • Exportable on request. We export your data in standard, portable formats any time you ask — no lock-in, no hostage-taking.
  • No selling, ever. We never sell your data. Sub-processors that help run the platform are listed in our Privacy Policy and are bound to use your data only to provide the service.
  • Hosting & residency. Infrastructure is provided by Vercel and Supabase. Specific hosting regions and data-residency details are available on request.

Policies & governance

Our security program is documented, not improvised. We maintain written policies covering information security, access control, data classification, and incident response, and we review our own defenses the same way we harden our clients'.

We are actively formalizing our compliance program. We do not currently hold a SOC 2 report — if a certification or a completed security questionnaire is a requirement for your organization, tell us and we'll walk you through our controls and share documentation under NDA.

Report a vulnerability

Found a security issue in one of our systems? We want to hear about it. Email security@araptus.com with the details and steps to reproduce. We investigate every good-faith report and will work with you on responsible disclosure. Please don't run automated scans or access data that isn't yours.

Security questions before you sign?

Bring your security team. We'd rather answer the hard questions up front than surprise anyone later.

Talk to us about security