Legal

Data Processing Addendum (DPA)

For customers who will need GDPR-compatible processing terms with Arc Labs once the managed Brain cloud launches (currently in development), this page provides the canonical DPA template, the planned sub-processor list, and a summary of technical and organizational measures. Self-hosted Brain runs entirely in your own infrastructure, where Arc Labs is not a processor of your data.

Version 1.0 · Effective 2026-05-02

How to execute

  1. Request the current DPA template (v1.0) by emailing trust@arc-labs.ai. We'll send it over the same business day.
  2. Complete Annex A (your contact details and data categories) and Annex B (any additional technical measures specific to your deployment).
  3. Send the executed copy to trust@arc-labs.ai. We countersign within three business days.

For larger procurement processes, we accept your DPA template as a starting point — email trust@arc-labs.ai to begin redlines.

Sub-processors

Planned sub-processors for the forthcoming managed Brain cloud. None are engaged yet — the managed cloud is in development and has no users. This list takes effect once the managed cloud launches; customers will receive 30 days' notice before we add new sub-processors that handle customer data.

ProviderPurposeRegion
AWSCompute, storage, networking (US, EU regions)US-East, EU-West
GCPCompute, storage (AP-South region)AP-South
CloudflareCDN, DDoS mitigationGlobal
SentryError monitoring (PII-stripped)US
PostmarkTransactional emailUS
StripePayment processingUS

Subscribe to changelog RSS — sub-processor updates are tagged infra.

Technical and organizational measures (Annex B summary)

  • TLS 1.3 in transit; AES-256-GCM at rest.
  • Per-(namespace, agent) isolation enforced in the storage engine; per-tenant data keys via envelope encryption.
  • Role-based access; least-privilege defaults; quarterly access reviews.
  • Vulnerability scanning weekly (cargo-audit, npm audit, pip-audit).
  • Backups encrypted with separate keys; key rotation quarterly.
  • Incident response runbook; customer notification without undue delay and no later than 72 hours of a confirmed incident.
  • Hard-delete on customer request; tombstones in audit log; no memory content retained.

Full TOMs are in Annex B of the executed DPA. The /security page has the public-facing version.

Procurement contact

For DPA execution, security questionnaires, SOC 2 status, or insurance certificates:

trust@arc-labs.ai →

Updates from the lab.

Engineering notes, research drops, occasional product updates. Roughly monthly.