Security command center
Evidence before escalation. Point Armalo at your code, name the attacker paths that matter, and get a pinned investigation you can review. Every conclusion stays attached to a saved copy of the code and a clear authority boundary.
Listed in the Cloud Security Alliance’s Agentic AI startup showcase, mapped to their identity, governance, observability, and guardrails frame. See how permissions, approvals, and the audit trail work together on the governed work page.
Scans pin the target, preserve detector evidence, and keep suspected candidates separate from validated findings.
The substrate table, residency matrix, and subprocessor list below are the canonical answer an enterprise buyer is looking for on /security. The scanned-investigation workspace below sits behind them — both surfaces are reachable from the tabs above.
Quarterly review cadence — owner: Armalo security team security@armalo.ai
Armalo separates the public edge, account services, customer work, and durable storage. Customer work runs on dedicated servers first, with per-customer isolated environments as the second option, behind a hardened edge. The certifications listed below are our hosting providers' attestations, not Armalo's. Armalo itself is not SOC 2 certified.
| Substrate | Component | Data type | Region | Compliance posture | Legal-review status |
|---|---|---|---|---|---|
| Dedicated control servers | Identity, workspace separation, permissions, billing, audit, secrets handling, policy, and conversation-log services | Account metadata, organization and workspace metadata, authoritative room events, policy records, metering records | US primary | ISO 27001:2022, GDPR Art. 28 DPA | Pending |
| Dedicated compute servers | Primary compute for customer work and platform workers | Ephemeral execution state, checked-out code, build cache, mission artifacts awaiting promotion | US primary | ISO 27001:2022, GDPR Art. 28 DPA | Pending |
| Hosted isolated environments | Secondary execution in per-customer isolated environments | Ephemeral filesystem, downloaded copy of your code, mission input, command output, generated artifacts | EU and US, selected by workspace policy and availability | SOC 2 Type II, HIPAA posture, GDPR DPA | Reviewed |
| Public edge network | TLS termination, proxying, traffic filtering, DNS | IP address, request metadata, TLS session metadata, cached public responses where configured | Global network | Covered by the provider's contractual and data-processing terms | Reviewed |
| Encrypted object storage | Durable object storage for approved artifacts, backups, cold audit exports, image files and saved copies | Encrypted objects and object metadata | United States (West) | ISO 27001:2022, GDPR Art. 28 DPA | Pending |
Durable control-plane data and disposable execution state live in different places and have different deletion paths. Backups follow the same residency as their primary store.
| Data class | Where stored | Default retention | Who can access | Deletion path |
|---|---|---|---|---|
| Workspace conversation log | Authoritative event log on the dedicated control servers; encrypted backups in encrypted object storage | Routine conversation retention: active for the life of the workspace plus 90 days after the conversation. Workspace deletion or an accepted erasure request removes active-system data within 30 days; database backups rotate at 7 days | Workspace members according to RBAC; scoped Armalo operators for support or incident response; agents receive only the context for their own mission | Delete workspace or submit an erasure request; policy requires removal on workspace deletion or accepted erasure; database backup copies expire within the 7-day rotation after live deletion; current fulfillment is confirmed through a scoped request; automatic removal at the routine window is not yet in place |
| User-uploaded files | Encrypted object storage; temporary mission copies inside your private work area | Active for the life of the workspace; 30 days after deletion request; temporary work-area copies expire when the work area is deleted | Workspace members according to RBAC; mission agents only when the file is granted to that mission; scoped operators during support or incident response | Delete the file or workspace; revoke mission capability; purge the live object - uploaded files are not currently backed up, so deletion of the live object is final |
| Generated code artifacts | Workspace code storage and encrypted object storage; temporary build output in the work area | Active while attached to the workspace or its code storage; 30 days after workspace deletion; work-area output lasts only until promotion or the work area is deleted | Workspace members; connected code host; mission agents with code access; scoped operators during support | Delete from code storage and the workspace artifact store; delete the work area; request workspace erasure - Armalo keeps no independent backup copy of generated artifacts beyond workspace code storage and the object store, so deletion removes Armalo's live and object copies; copies at a connected code host follow that host's retention |
| Integration credentials | Encrypted control-plane secrets vault; agents receive only short-lived capability handles | Long-lived credential remains until revoked, rotated, integration disconnected, or workspace deleted; short-lived mission credential expires at its configured deadline | Authorized Owner or Admin for connection management; the credential service issues access; the agent does not receive the raw long-lived value | Disconnect integration, revoke at provider, rotate secret, or delete workspace; outstanding short-lived grants are revoked or allowed to expire |
| Workspace audit logs | Append-only workspace audit store on the dedicated servers; Enterprise exports may be copied to the customer's destination | 30 days by default; Enterprise override available | Owner and Admin by default; authorized security Viewer where configured; scoped Armalo security and incident-response operators | Automatic daily removal after the 30-day window; workspace deletion workflow; Enterprise export retention is controlled by the customer |
| Request logs | Append-only tool access store on the dedicated servers | No automatic expiry yet; these records are append-only | Scoped Armalo security and incident-response operators; authorized admins via the admin audit-log endpoint | Not yet deletable on request; if a request covers them, we will tell you |
| Billing data | Armalo control servers for usage ledger and account linkage; Stripe for payment processing and regulated payment records | Usage ledger retained while the account is active and as needed for accounting, tax, dispute, and legal obligations; payment-card data remains with Stripe | Owner and billing Admin; Armalo billing operators; Stripe for payment processing | Close account and request deletion; Armalo removes data not subject to legal retention; Stripe follows its contractual and legal deletion obligations |
| Telemetry | Operational telemetry pipeline and encrypted stores; provider-side infrastructure telemetry where applicable | The policy target for identifiable operational telemetry is up to 30 days unless needed for an active incident; automatic expiry is not yet in place; aggregated anonymized metrics may be retained indefinitely | Scoped Armalo engineering, reliability, and security operators; workspace administrators for views inside their workspace | Scheduled expiry is not yet automatic; policy requires removal of workspace-linked records on account deletion, and current fulfillment is confirmed through a scoped request; aggregated anonymized metrics cannot be linked back to a workspace |
Residency controls
A provider receives only the data needed for its purpose. This list is current as of 2026-07-30; it may evolve as Armalo adds regions, integrations, model routes, and delivery providers. Notice is provided through the DPA or customer agreement where required.
| Subprocessor | Purpose | Data shared | Region | DPA status | Legal-review status |
|---|---|---|---|---|---|
| Cloudflare | Edge proxy, TLS termination, traffic filtering, DNS | IP address, request metadata, TLS metadata, public response data, DNS query metadata | Global edge | DPA available; transfer terms governed by Cloudflare agreement | Reviewed |
| Hetzner | Dedicated compute, control servers, private networking, durable object storage, backups | Encrypted customer data, account and workspace metadata, room events, artifacts, audit records, operational telemetry | United States (Hetzner us-west) | GDPR Art. 28 DPA; ISO 27001:2022 | Pending |
| E2B | isolated work areas | Mission prompt subset, selected files, code download, command input and output, temporary artifacts, short-lived capabilities | EU or US, selected by policy | GDPR DPA; SOC 2 Type II; HIPAA posture | Reviewed |
| Stripe | Subscription billing, invoices, payment processing | Customer name, billing contact, plan, invoice data, payment method data handled by Stripe, transaction status | Stripe service regions, including US processing | Stripe DPA available; payment data governed by Stripe terms | Reviewed |
| OpenAI | Metered model inference when selected | Prompt and context required for the model request; generated response; request metadata | Provider-selected region or customer-contracted region | Provider DPA applies to platform inference; BYO-key customers also rely on their provider agreement | Reviewed |
| Anthropic | Metered model inference when selected | Prompt and context required for the model request; generated response; request metadata | Provider-selected region or customer-contracted region | Provider DPA applies to platform inference; BYO-key customers also rely on their provider agreement | Reviewed |
| Metered model inference when Gemini is selected | Prompt and context required for the model request; generated response; request metadata | Provider-selected region or customer-contracted region | Provider DPA applies to platform inference; BYO-key customers also rely on their provider agreement | Reviewed | |
| xAI | Metered model inference when selected | Prompt and context required for the model request; generated response; request metadata | Provider-selected region or customer-contracted region | Provider contractual data terms apply; availability and DPA terms are reviewed per Enterprise schedule | Reviewed |
| Google Workspace | Identity and organization sign-in | Email address, display name, account identifier, sign-in details, organization-domain metadata | Google global service | Google Workspace or Google data terms apply; customer agreement may govern BYO identity | Reviewed |
| GitHub | Code connection, download, and sync of changes and review requests | Code project details, selected source code, change history, installation identity, limited-access code token | GitHub service regions | GitHub DPA available; customer may connect its own organization agreement | Reviewed |
| SendGrid | Transactional email when configured | Recipient email, template variables, delivery metadata, bounce and complaint events | Provider service regions, commonly US/global | DPA available when SendGrid is the configured sender | Reviewed |
| Mailgun | Transactional email when configured | Recipient email, template variables, delivery metadata, bounce and complaint events | Provider-selected US or EU region where configured | DPA available when Mailgun is the configured sender | Reviewed |
Connect a public GitHub code project or an approved private connection.
Security scans do not write code, apply changes to your code, or open change requests.
Each run records an immutable revision and scanner evidence references.
Give the investigation a target and a useful question. The first pass is designed to be safe, legible, and reviewable.
TARGET
Code project + version
Pin what was actually examined.
MODEL
Threat priorities
Focus on consequence, not noise.
RECEIPT
Evidence trail
Trace every finding to proof.
Only this workspace’s authenticated runs appear here.
Workspace history is private.
Scan history belongs to each workspace. You’re signed out, so there’s nothing to show here — sign in to see your workspace’s runs.
Start a new investigation →Redacted. What a finished investigation looks like — every finding traces to evidence.
Sample web application
target ▓▓▓▓▓▓ · ref 9f3ac21 · completed 2026-09-10
Dependency with a known CVE
High2 evidence receipts · lockfile excerpt, advisory reference
Storage bucket allows public reads
Medium1 evidence receipt · saved policy copy
Security headers missing on 4 pages
Low1 evidence receipt · header scan
Sample data — customer identifiers, code project names, and evidence contents are redacted. Real investigations show the same structure with your workspace’s data.
Found something we should know about? Email security@armalo.ai with what you found, where you found it, and how to reproduce it. We read every report and confirm we have received it.