Arciin.

Trust.

Security

Local-first by design. Your files, keys, and AI traffic stay on infrastructure you operate unless you choose otherwise.

Your perimeter

Last updated · July 9, 2026

1. Security model

Arciin is local-first. The goal is that your libraries, credentials, and AI traffic stay on infrastructure you operate. Our marketing site and license service are separate from the data plane of your instance.

2. What stays on your server

On a typical self-hosted deploy:

  • Files, thumbnails, and metadata in your libraries.
  • User accounts and sessions you configure.
  • API keys and AI provider keys you paste into the instance.
  • Password vault secrets (when enabled on a paid plan).
  • Logs, jobs, events, and app databases for that instance.

3. What may leave your server

Only what you configure: outbound calls to AI providers you choose, optional remote access (your reverse proxy or tunnel), optional backup destinations, and periodic license checks for paid plans. We do not need your file contents to sell you a license.

4. Authentication and access

Arciin supports local authentication and, on higher plans, multi-user roles. You should place the instance behind TLS when exposed beyond a trusted LAN, restrict admin accounts, and rotate API keys. Business plans may include SSO and advanced access policies as documented at purchase time.

5. Encryption

Use HTTPS for any remote access path. At-rest encryption depends on your disk and volume setup. Paid vault features encrypt secrets within the application; you still control the host’s full-disk encryption.

6. Updates

Free tier uses manual updates; paid plans can automate updates. Apply security patches on the OS, reverse proxy, and container runtime you use to run Arciin.

7. Reporting vulnerabilities

If you believe you found a security issue in Arciin or this website, email sales@arciin.app with details and steps to reproduce. Please give us a reasonable window to respond before public disclosure.

8. No perfect security

Self-hosting shifts operational security to you. We provide software and guidance; we cannot guarantee that every deployment will be free of misconfiguration or compromise.

Report an issue

Email sales@arciin.app with steps to reproduce. We treat security reports seriously.