Skip to content

Security built for project data.

Security overview

Across estimating, permitting, codes, catalogs, CAD, and facility documentation, customers trust Armeta with project files that are commercially sensitive, regulated, or both. Our security program is built for that class of data.

Every commitment on this page is verifiable. Request current documentation, subprocessor lists, and architecture summaries from the security team under NDA.

SOC 2 sealSOC 2 badgeVanta SOC 2 compliance badge
01

Certifications and audits

SOC 2 Type I and Type II certified. Data residency in US, EU, or customer-designated regions. Enterprise SSO, role-based access, full audit logs, and end-to-end encryption.

02

Data protection

TLS 1.3 for all data in transit. AES-256 for all data at rest. Cryptographic material is managed by a dedicated key management service with rotation enforced on a fixed schedule.

03

Access controls

Single sign-on via SAML 2.0 and OIDC. Role-based access control aligned to customer directory groups. Full audit logs for authentication, authorization, and data access events, exportable to customer SIEM.

04

Data residency

US, EU, and customer-designated regions supported. Customer project data is stored in the region selected at onboarding and is not replicated across regions without explicit authorization.

05

Deployment options

Multi-tenant cloud, dedicated single-tenant cloud, and on-premise or customer-managed private cloud. Air-gapped deployments are supported for engagements that require them.

06

Incident response

24x7 on-call rotation. Documented severity classification, communication SLAs, and post-incident review process. Customer-impacting incidents are reported in line with the terms of the engagement.

Who this protects

The same controls cover the parties that prepare work and the parties that review it: engineering firms, construction companies, asset owners, and governments and regulators.

Whether the workflow is issuing an estimate, checking a permit package, citing a code, validating a catalog position, or structuring facility drawings, customer data stays inside the deployment model and residency region agreed at onboarding.

Customer data handling

Specific customer data handling terms — including access, retention, deletion, and regional constraints — are defined in each customer's master services agreement and data processing addendum. The defaults documented here are the minimum; individual engagements can tighten them but not relax them.

For audit-facing customers, Armeta supports read-only auditor access to product outputs, review protocols, and provenance metadata as part of the engagement scope.

Security contact

For questionnaires, vulnerability reports, or a copy of the current security overview, write to security@armeta.ai. Responses within one business day.

FAQ

How is customer data segregated?

Logical segregation at every layer — storage, compute, and processing — keyed to the customer tenant. Single-tenant and on-premise deployments provide physical segregation in addition to logical controls.

What kinds of project data does Armeta handle?

Depending on the products in use, that can include cost estimates and rate libraries, permitting and design packages, codes and standards queries, catalog and materials specifications, CAD drawings, and facility documentation such as P&IDs and related as-builts. The same security controls apply across the product line.

What happens to customer data after an engagement ends?

Retention, deletion, and return-of-data are governed by the terms of the engagement. The default posture is that customer data is deleted on request and on contract termination, subject to documented legal-hold requirements.

Can we review Armeta’s security documentation?

Security questionnaires, architecture summaries, and subprocessor lists are available to qualified customers and prospects under NDA. Contact security@armeta.ai to request access.

How do we report a vulnerability?

Write to security@armeta.ai with as much detail as you can share. We acknowledge vulnerability reports within one business day and coordinate disclosure in good faith.