Security & reliability
Last updated: 1 October 2026
Arqor is operated by Arqor Ltd, registered in England and Wales, company number 17380863
Arqor keeps every company’s records separate, holds them in the UK, and lets nobody sign in with a password. This page says how, what happens if the service is unavailable, and how to report a security problem.

Independent security assessment
In September 2026, TAC Security, a lab authorised by the App Defense Alliance, assessed Arqor at arqor.io under the Cloud Application Security Assessment (CASA) at assurance level AL1. Arqor passed all 48 of its checks and was found in compliance.
Google requires CASA of any app that asks for restricted access to Gmail, as Arqor’s email client does. The assessment is repeated every year.
Where your data is held
Your data is held in the UK. Arqor’s database, sign-in and files sit with Supabase in its London region (AWS eu-west-2), and the servers that run Arqor are in London too.
- Everything is encrypted at rest (AES-256) and in transit (TLS). Supabase and Vercel, which host Arqor, are both SOC 2 Type 2 and ISO 27001 certified.
- The database is backed up every day, and any of the last 7 days can be restored. The backups cover the database, not the files themselves, so keeping your own copies (below) matters too.
- Email, payments and the optional AI features use the providers named in the privacy policy.
Who can see your data
Only the people you let in. Every table in Arqor’s database has row-level security switched on, so one company’s records are walled off from another’s, and the application checks a person’s company as well.
- Your team. Owners see everything in the company. Everyone else sees the jobs they work on, in line with their role. Remove someone from the team and their access ends.
- Anyone with a job’s QR code (no account): that one job’s current drawings, its documents except contracts, and its recent photos. They can add photos. The code stops working once the job is no longer active, so treat a job’s QR poster like a site key.
- Inspectors and clients you send a share link: what the link includes. It expires after 7, 30 or 90 days, as you choose. You can add a 4-digit PIN, and revoke it at any time.
- Arqor support, only when helping you. Support staff confirm with a passkey before entering an account, enter it as a marked support member, and can look but cannot send, pay, void or refund.
Photos, drawings and documents
- Documents (contracts, RAMS, specifications) are private files. Each opens through a link that lasts five minutes.
- Photos and drawings open in Arqor through links that expire in less than a day, so a link copied from Arqor stops working. Their files also still have a permanent address, one that cannot be guessed or browsed. We are closing that in October 2026, when photos and drawings become private files too.
- Links in the emails and spreadsheets Arqor sends go through Arqor, which checks who is asking each time: a snagging list’s photos open while its link does, and a receipt’s photo opens only for the people who can see your books.
- Your logo stays public, because it appears on the emails and documents you send.
Signing in
Nobody needs a password: people sign in with a one-time code or link sent to their email, or with a passkey, so there is no password to guess, reuse or phish.
- Owners prove it twice. An owner’s account can see everything in the company, so the owner also confirms with a passkey (Face ID, Touch ID or Windows Hello) at least once every 7 days.
- Passkeys cannot be phished. A passkey works only on arqor.io itself, so a fake sign-in page on any other address cannot use it.
- Arqor’s own staff follow the same rule. The support desk and the operator console need a passkey too.
- Signing out ends it. The passkey check is tied to that one session and does not carry over to another.
If Arqor is unavailable
Site work carries on.
- The Arqor app for iPhone and Android saves every photo on the phone before sending it, and sends it when the connection returns. In a web browser this works while the page stays open.
- In a phone’s web browser, drawings and documents opened before open again without signal.
- Your own copies never depend on us. Download any drawing, a folder or the whole set as a zip, a drawing as a PDF with its photo pins, or a job’s photos as a zip with a spreadsheet of their details, at any time.
- Vercel and Supabase publish their live service status. We do not yet run a status page of our own, and our terms give no uptime guarantee.
Your data is yours
- You own everything you put into Arqor, and can take it away at any time with the downloads above.
- If you leave, your data is deleted 30 days after the account closes. Payment records are kept for 7 years, as HMRC requires.
- Arqor is registered with the Information Commissioner’s Office (ZC223398) and handles personal data under UK GDPR and the Data Protection Act 2018. The privacy policy lists every provider that processes data for us.
Reporting a vulnerability
The rest of this page is our vulnerability disclosure policy.
1. Our commitment
If you believe you have found a security vulnerability in the Arqor platform (arqor.io or its APIs), we want to hear from you, and we will treat you as a partner, not a problem. We will not pursue or support legal action against anyone who researches and reports in good faith within this policy.
2. How to report
Email hello@arqor.io with a subject line starting SECURITY. Include what you found, where (URL or endpoint), steps to reproduce, and what you think the impact is. Screenshots or a proof of concept help.
What you can expect from us:
- Acknowledgement within 2 UK business days.
- An initial assessment within 7 days — severity, and what we intend to do.
- A fix on a timescale matched to severity: critical issues are handled under our incident response process (containment in hours); others through our normal tested-release pipeline, typically within 30 days.
- We will keep you informed, credit you if you would like credit, and tell you when the fix ships.
3. Good-faith ground rules
- Only test against accounts and data you own or are authorised to use — never against another customer’s data. If you encounter data that is not yours, stop, report it, and do not retain copies.
- No denial of service, spam, social engineering of our users, or physical attacks.
- Give us reasonable time to fix before public disclosure — we ask for coordinated disclosure and will agree a timeline with you.
4. In scope
- arqor.io and its application, APIs and worker/mobile surfaces
- The QR/token site surfaces and share links
- Our handling of connected mailbox data (Google OAuth integration)
5. Out of scope
- Third-party services we build on (Supabase, Vercel, Stripe, Google, Resend) — report those to the vendor, though we would like to know too
- Findings requiring physical access to a user’s unlocked device
- Reports from automated scanners with no demonstrated impact
- Rate-limit or best-practice observations with no security consequence (still welcome, just not handled under this policy’s timelines)
6. No bounty — yet
Arqor does not currently run a paid bounty programme. Good reports get a fast response, a fix, and public credit if wanted. That is a promise we keep small enough to keep.