Security properties
When you integrate according to this architecture:- Arcane does not initiate confidential transactions or hold your transaction-signing authority;
- Arcane’s API, indexer, encrypted data store, and application services do not store plaintext disclosure keys;
- Arcane can index and persist encrypted records without decrypting them;
- protected key use and plaintext processing occur only inside the Trusted Compute Module for an authorized operation;
- Arcane returns only the approved disclosure scope and does not persist that plaintext during normal operation; and
- Arcane protects historical disclosure keys under the same controls as active keys while they remain required.
Trust boundaries
The logical Arcane infrastructure shown in the architecture diagrams is not a
single trust boundary. The Trusted Compute Module and key-management provider
form separate protected boundaries inside the overall system.
Shared responsibility
Arcane provides controlled-disclosure infrastructure. It does not make legal,
regulatory, or business decisions for you. You define the policy and approval
model. Arcane enforces the resulting platform permissions and disclosure scope.
Review trusted compute
Understand where protected key use and plaintext processing occur.
Configure user access
Manage organization membership and application-scoped permissions.