Trust.
Security
Local-first by design. Your files, keys, and AI traffic stay on infrastructure you operate unless you choose otherwise.
Your perimeterLast updated · July 9, 2026
1. Security model
Arciin is local-first. The goal is that your libraries, credentials, and AI traffic stay on infrastructure you operate. Our marketing site and license service are separate from the data plane of your instance.
2. What stays on your server
On a typical self-hosted deploy:
- Files, thumbnails, and metadata in your libraries.
- User accounts and sessions you configure.
- API keys and AI provider keys you paste into the instance.
- Password vault secrets (when enabled on a paid plan).
- Logs, jobs, events, and app databases for that instance.
3. What may leave your server
Only what you configure: outbound calls to AI providers you choose, optional remote access (your reverse proxy or tunnel), optional backup destinations, and periodic license checks for paid plans. We do not need your file contents to sell you a license.
4. Authentication and access
Arciin supports local authentication and, on higher plans, multi-user roles. You should place the instance behind TLS when exposed beyond a trusted LAN, restrict admin accounts, and rotate API keys. Business plans may include SSO and advanced access policies as documented at purchase time.
5. Encryption
Use HTTPS for any remote access path. At-rest encryption depends on your disk and volume setup. Paid vault features encrypt secrets within the application; you still control the host’s full-disk encryption.
6. Updates
Free tier uses manual updates; paid plans can automate updates. Apply security patches on the OS, reverse proxy, and container runtime you use to run Arciin.
7. Reporting vulnerabilities
If you believe you found a security issue in Arciin or this website, email sales@arciin.app with details and steps to reproduce. Please give us a reasonable window to respond before public disclosure.
8. No perfect security
Self-hosting shifts operational security to you. We provide software and guidance; we cannot guarantee that every deployment will be free of misconfiguration or compromise.
Report an issue
Email sales@arciin.app with steps to reproduce. We treat security reports seriously.