Trust & Security
This page is maintained by the Arabist team to answer common security and privacy questions about arabist.io. It is not an independent audit or certification, and it reflects our current practices; controls evolve as the product grows.
Access & authentication
- Email + password sign-in with password reset via a signed, single-use link.
- Row-level security on every user-facing database table — a signed-in user can only read and write their own rows.
- Administrative surfaces (institution management, reputation, health, outreach) are gated by a separate
super_adminrole and are not reachable by regular accounts.
Data in transit & at rest
- All traffic to arabist.io is served over HTTPS with HSTS preloading enabled.
- We ship a strict Referrer-Policy, X-Content-Type-Options, X-Frame-Options and Permissions-Policy on every response, and a Content-Security-Policy (currently in report-only mode while we baseline violations).
- Application data and uploaded manuscript images are stored by our managed database and object-storage subprocessor with encryption at rest handled by that provider.
Subprocessors
We use a short list of infrastructure and AI subprocessors to run the service. See the current subprocessor list for vendor, purpose, and data-region details.
AI processing
Uploads are sent to third-party AI models via the Lovable AI Gateway to produce transcription, morphology, glossary, translation, bibliography, and catalog records. Uploads are not used to train third-party models. See Privacy for full detail.
Retention & deletion
- Jobs, pages, and generated reports remain in your account until you delete them from your account.
- You can export your account data or permanently delete your account from the Data & Privacy section of the account page. Deletion removes your profile, jobs, pages, folders, and subscription records; anonymised billing records required for tax reporting may be retained by our payment processor.
Reporting a vulnerability
Please email security@arabist.io with a description of the issue and steps to reproduce. We ask that you give us a reasonable window to investigate before public disclosure. We do not currently run a paid bug-bounty program.
Compliance
Arabist is not currently certified against SOC 2, ISO 27001, HIPAA, or PCI-DSS. For payment card handling we rely on our PCI-DSS-compliant payment processor — card numbers never touch our servers. For customers with regulated data, please contact us before uploading.