Certifications and audits
SOC 2 Type I and Type II certified. Data residency in US, EU, or customer-designated regions. Enterprise SSO, role-based access, full audit logs, and end-to-end encryption.
Across estimating, permitting, codes, catalogs, CAD, and facility documentation, customers trust Armeta with project files that are commercially sensitive, regulated, or both. Our security program is built for that class of data.
Every commitment on this page is verifiable. Request current documentation, subprocessor lists, and architecture summaries from the security team under NDA.



SOC 2 Type I and Type II certified. Data residency in US, EU, or customer-designated regions. Enterprise SSO, role-based access, full audit logs, and end-to-end encryption.
TLS 1.3 for all data in transit. AES-256 for all data at rest. Cryptographic material is managed by a dedicated key management service with rotation enforced on a fixed schedule.
Single sign-on via SAML 2.0 and OIDC. Role-based access control aligned to customer directory groups. Full audit logs for authentication, authorization, and data access events, exportable to customer SIEM.
US, EU, and customer-designated regions supported. Customer project data is stored in the region selected at onboarding and is not replicated across regions without explicit authorization.
Multi-tenant cloud, dedicated single-tenant cloud, and on-premise or customer-managed private cloud. Air-gapped deployments are supported for engagements that require them.
24x7 on-call rotation. Documented severity classification, communication SLAs, and post-incident review process. Customer-impacting incidents are reported in line with the terms of the engagement.
The same controls cover the parties that prepare work and the parties that review it: engineering firms, construction companies, asset owners, and governments and regulators.
Whether the workflow is issuing an estimate, checking a permit package, citing a code, validating a catalog position, or structuring facility drawings, customer data stays inside the deployment model and residency region agreed at onboarding.
Specific customer data handling terms — including access, retention, deletion, and regional constraints — are defined in each customer's master services agreement and data processing addendum. The defaults documented here are the minimum; individual engagements can tighten them but not relax them.
For audit-facing customers, Armeta supports read-only auditor access to product outputs, review protocols, and provenance metadata as part of the engagement scope.
For questionnaires, vulnerability reports, or a copy of the current security overview, write to security@armeta.ai. Responses within one business day.
Logical segregation at every layer — storage, compute, and processing — keyed to the customer tenant. Single-tenant and on-premise deployments provide physical segregation in addition to logical controls.
Depending on the products in use, that can include cost estimates and rate libraries, permitting and design packages, codes and standards queries, catalog and materials specifications, CAD drawings, and facility documentation such as P&IDs and related as-builts. The same security controls apply across the product line.
Retention, deletion, and return-of-data are governed by the terms of the engagement. The default posture is that customer data is deleted on request and on contract termination, subject to documented legal-hold requirements.
Security questionnaires, architecture summaries, and subprocessor lists are available to qualified customers and prospects under NDA. Contact security@armeta.ai to request access.
Write to security@armeta.ai with as much detail as you can share. We acknowledge vulnerability reports within one business day and coordinate disclosure in good faith.