Security Policy

A recovery platform must protect itself first.

Arximus protects the systems that handle recovery jobs, backup metadata, encrypted storage, restore operations, reports, signing keys, credentials, customer access, and operator workflows. The recovery control plane is a high-value system, and it must be treated like one.

Platform security

Arximus Cloud is a recovery control plane.

The platform manages protected assets, backup jobs, restore jobs, manifests, storage, reports, credentials, keys, alerts, and audit records. That requires strong tenant isolation, least privilege, monitoring, and operational discipline.

Operator access is restricted, audited, justified, and limited to the work required.

Secure delivery

Recovery trust depends on how the platform is built and released.

Arximus release practices include code review, static analysis, dependency scanning, secret scanning, artifact control, database migration discipline, and critical release procedures.

Changes to systems that affect backup, restore, reports, storage, or access control must be controlled and auditable.

Security controls

Core controls for the platform itself.

Customers trusting Arximus with recovery need confidence in Arximus operations.

Access

Least privilege

Role-based access, MFA, support access controls, just-in-time access, and approval for sensitive operator actions.

Tenancy

Tenant isolation

Tenant boundaries across application logic, databases, object storage, queues, dashboards, and reports.

Secrets

Secrets management

Credential storage, key handling, redaction, rotation, revocation, and access logging.

Storage

Backup storage protection

Object isolation, encryption, access logging, retention controls, immutable windows, and deletion governance.

Release

Secure release pipeline

Code review, dependency scanning, static analysis, secret scanning, artifact control, and rollback procedure.

Monitoring

Operational monitoring

API health, queue health, backup processing, restore processing, storage health, errors, alerts, and platform incidents.

Trust is operational.

Security policy must match the recovery responsibility.

Arximus is designed to protect the systems, data, and workflows that make recovery possible.

Next step

Review privacy and status.

Understand how customer data is handled and how recovery service health is communicated.