Security
Policy before provider access.
Arc.AI is designed to make identity, spend, privacy, routing, and operational evidence part of the request path—not a separate after-the-fact dashboard.
Trusted identity
Attribute traffic to an organization, workspace, principal, application, and key before policy is evaluated.
Pre-dispatch enforcement
Evaluate access, spend, region, retention, and endpoint eligibility before a provider call is made.
Explicit failover
Fail over only across administrator-approved endpoints. Policy constraints do not relax to recover a request.
Runtime evidence
Record the policy version, endpoint, attempt chain, reservation, settlement, and outcome without requiring payload logging.
Least privilege
Separate model, billing, security, and organization responsibilities. Payload access is not implied by an administrative role.
Controlled change
Version policy changes, approvals, emergency actions, and administrative events for audit and rollback.
Security depends on the selected deployment, plan, provider contracts, identity configuration, customer applications, and enabled connectors. Specific controls, service levels, incident terms, and evidence are defined in the applicable commercial agreement.