AArikano
PricingTrustSign In

Privacy Policy

Last updated: September 10, 2026

The short version. Arikano is a business-to-business compliance service. We collect what we need to run your account, and we ask you for logins to contractor-management portals (ISNetworld, Avetta, Veriforce) so that Arikano can read your scores and act on your behalf. Those credentials are encrypted before they are stored, are decrypted only for the moments a portal session needs them, and are never sold, shared for marketing, or used for any purpose other than the work you asked for. You can delete them, or your whole account, at any time.

1. Who we are

This policy describes how Arikano, Inc. (“Arikano”, “we”, “us”) handles personal and business information when you use the Arikano platform at arikano.com and its related APIs (the “Service”). Arikano is provided to businesses. When you use the Service on behalf of a company, that company is our customer and this policy applies to the data it entrusts to us.

2. Information we collect

2.1 Information you give us

  • Account details: your name, work email address, password (stored only as a hash by our authentication provider), company name, industry, and state.
  • Team members: names and email addresses of people you invite to your workspace, and the role you assign them.
  • Portal credentials: usernames and passwords for third-party contractor-management platforms you connect (see Section 4).
  • Compliance content: documents you upload or ask Arikano to draft, training and certification records, incident reports, insurance policies and certificates, corrective actions, deadlines, notes, and anything you type into the Arikano conversation.
  • Billing details: handled by Stripe. We store your plan tier, subscription status, and Stripe customer identifiers; we never see or store full card numbers.

2.2 Information Arikano collects on your behalf

  • Portal data: when a connected portal is scanned, Arikano reads your grades and scores, open requirements, document statuses, and expiration dates and stores a snapshot in your workspace so it can track changes over time.
  • Regulatory context: public regulatory text (federal and state OSHA standards, platform requirements) is stored in our knowledge base and is not personal to you.

2.3 Information collected automatically

  • Usage and audit logs: the actions taken in your workspace by people and by Arikano, with timestamps and the acting user, so you have an audit trail.
  • Technical data: IP address, browser type, device information, and error reports needed to keep the Service secure and working.
  • Cookies: we use strictly necessary cookies for sign-in sessions. We do not use advertising cookies or third-party tracking pixels.

3. How we use information

  • To provide the Service: monitoring your connected portals, drafting documents, tracking deadlines, sending the alerts you configure, and answering your questions through the Arikano agent.
  • To act on your behalf inside a connected portal, only for actions you or your plan have authorized (Section 4).
  • To operate, secure, and improve the Service, including debugging and preventing abuse.
  • To bill you and communicate about your account (invoices, security notices, service changes).
  • To comply with law and enforce our Terms of Service.

We do not sell personal information, and we do not use your compliance content or conversations to train general-purpose AI models. Our model providers are contractually restricted from using API inputs to train their models.

4. Portal credentials

Connecting a portal gives Arikano the same access you have. Because of that, credentials are handled differently from every other kind of data:

  • Encrypted at rest. Passwords are encrypted with AES-256-GCM before they are written to the database. The encryption key is held in application configuration, separate from the database, so a database export alone cannot reveal a credential.
  • Decrypted only in use. A credential is decrypted in memory for the duration of a portal session (a scheduled scan, a verification you request, or a submission you approve) and is discarded when the session ends. It is never written to logs, error reports, or model prompts.
  • Used only for your instructions. Read-only scans run on the schedule you set. Actions that change anything on a portal — uploading a document, updating a questionnaire answer — run only when your plan includes that capability and a member of your workspace with the right role has approved the action. Every action is recorded in your audit trail.
  • Never shown back. Once saved, a password is not displayed in the interface or returned by any API. You can replace it or delete it at any time from Settings.
  • Your responsibility. You confirm you are authorized to give us access to each portal account you connect, and you should use a dedicated portal user for Arikano where the platform allows it.

5. Who we share information with

We share information only with the service providers below (our “subprocessors”), who process it under contract and only to provide their service to us; with your own team members according to the roles you set; with professional advisers where necessary; and with authorities when the law requires it. We will notify customers before adding a subprocessor that handles customer content.

ProviderPurposeData involvedLocation
SupabasePostgres database, authentication, and file storageAll account and workspace data; portal credentials only in AES-256-GCM ciphertextUnited States
VercelApplication hosting, edge network, scheduled jobsRequest logs, IP address, application data in transitUnited States
DeepSeekPrimary language model for routing and draftingConversation and document text; never credentials or payment dataSee provider terms
AnthropicLanguage model for the Arikano agentConversation text, document excerpts, scanned portal contentUnited States
OpenAIText embeddings for the compliance knowledge baseDocument and knowledge-base text for embeddingUnited States
StripeSubscription billingBilling contact and payment method (held by Stripe, never by Arikano)United States
ResendTransactional email (alerts, invitations, digests)Recipient email address and alert contentsUnited States
BrowserlessHosted browser automation for portal scans and submissionsPortal session traffic; decrypted credentials in memory only for the sessionUnited States
SentryError and performance monitoring, cron check-insError traces and request metadata; credentials are scrubbedUnited States
GitHubSource control, CI, dependency alertsSource code and CI logs only; no customer dataUnited States

Language-model providers receive the text needed to answer a request: your message, relevant document excerpts, and the content Arikano read from a portal. They do not receive portal passwords, payment details, or your team's account credentials.

6. Retention

The windows below are what the system enforces today. A workspace owner can request deletion of the whole workspace from Settings; the request takes effect after a 7-day grace period during which it can be cancelled, and then every record, file, and login for the workspace is removed. We keep limited billing records (such as invoices) where tax and accounting law requires it.

DataKept forHow it is removed
Account and workspace recordsLife of the accountDeleted with the workspace (7-day grace period, then hard delete)
Arikano chat historyLife of the account, or until you delete the conversationConversation delete removes messages immediately
Audit logsLife of the account (400-day pruning is opt-in)Weekly retention sweep, per-tenant setting
Vault document versionsNewest 30 versions kept; older superseded versions removed after 90 daysWeekly retention sweep
Soft-deleted files30 days, then hard-deleted with the stored objectWeekly retention sweep
LLM usage ledger400 daysWeekly retention sweep
Portal credentialsUntil you disconnect the portal or delete the workspaceImmediate hard delete
Database backupsSupabase point-in-time recovery window (currently 7 days)Provider-managed; rolls off automatically

7. Your choices and rights

  • Access and correction: most information can be viewed and edited in Settings. Ask us for anything you cannot reach yourself.
  • Deletion: a workspace owner can delete the whole workspace from Settings (7-day grace period, then permanent). You can also email us from the address on your account and we will handle it for you. Workspace owners can remove individual team members and connections at any time.
  • Export: a full JSON export of your workspace, with download links for every file, is available from Settings and Reports at any time.
  • Marketing: we send transactional email only. If we ever send marketing email, every message will include an unsubscribe link.
  • Regional rights: depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR, including the right to complain to a supervisory authority. We honor those rights on request.

8. Security

We protect information with encryption in transit (TLS) and at rest, tenant isolation enforced at the database layer, role-based access within each workspace, rate limiting, security headers, and audit logging. The controls are described in detail on our Trust Center. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay, targeting 72 hours from confirmation, and as required by law.

9. International transfers

Arikano is operated from the United States and our subprocessors are located there unless noted above. If you use the Service from elsewhere, your information will be transferred to and processed in the United States.

10. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect information from children.

11. Changes to this policy

When we make material changes we will update the date at the top of this page and, for changes that affect how we handle customer content or credentials, notify workspace owners by email before the change takes effect.

12. Contact

Questions, access requests, and deletion requests: privacy@arikano.com. Security reports: security@arikano.com. Please write from the email address on your account so we can verify the request.

© 2026 Arikano, Inc. All rights reserved.·Trust CenterPrivacy PolicyTerms of Service