Security & Data Protection
Last Updated: August 22, 2026
ArcWalk is engineered for critical infrastructure. We understand that the data you collect—from equipment nameplates to facility one-lines—is the foundation of site safety. Our security architecture is built to ensure this data remains accurate, available, and private.
Security Philosophy: We apply a "Defense in Depth" strategy, ensuring that data is protected on the device, during transit, and at rest in the cloud.
1. Data Encryption
We utilize industrial-grade encryption standards across the entire data lifecycle.
Encryption in Transit
All communication between the ArcWalk mobile application and our backend servers is forced over secure channels.
- TLS 1.3 We use the latest Transport Layer Security protocols to prevent eavesdropping and man-in-the-middle attacks.
- Certificate Pinning Ensures the app only talks to verified Synfra servers, preventing sophisticated interception attempts.
Encryption at Rest
Once your data reaches our secure cloud infrastructure, it is immediately encrypted before being committed to physical storage.
- AES-256 All project metadata, equipment specifications, and high-resolution technical photos are encrypted using the Advanced Encryption Standard with 256-bit keys.
- Managed Key Infrastructure Storage keys are managed through hardened hardware security modules (HSMs), ensuring that even in the event of physical hardware theft, the data remains unreadable.
2. On-Device Security
ArcWalk is designed to be "Offline-First," meaning your data is stored locally before it ever touches the cloud.
- Application Sandboxing: Both iOS and Android utilize kernel-level sandboxing. ArcWalk's local database and technical photos are isolated from all other applications on your device.
- Secure Local Storage: We use high-performance, encrypted local storage to ensure that technical data remains safe even if the device is lost or stolen, provided the device's own biometric or passcode security is enabled.
3. System Integrity & Authentication
To ensure that engineering reports are based on legitimate field findings, we verify the source of every submission.
Device Attestation
We leverage platform-native hardware security to verify the integrity of the App:
- Apple App Attest Verifies that submissions are coming from an un-tampered version of ArcWalk running on a genuine iPhone or iPad.
- Google Play Integrity Ensures the device is not "rooted" or running malicious software that could alter technical data during capture.
API Security
Our cloud infrastructure is guarded by a hardened API gateway. Access is restricted via cryptographically signed tokens and strict rate-limiting to prevent unauthorized access to project history.
4. Reliable Infrastructure
We partner with industry leaders to provide a globally distributed, resilient backend:
- Cloudflare D1: A distributed SQL database that ensures high availability and data consistency.
- Cloudflare R2: S3-compatible object storage for technical photos, featuring 99.999999999% (11 nines) of annual durability.