Trust
Security posture
Arden works by being connected to the systems your company runs. This page says exactly what that means: what it can see, what it can do, how both are limited, and how you can check.
Last updated 20 August 2026
The principle
Seeing never waits; doing is earned. What Arden may read and what Arden may write are separate permissions, granted separately, and the second always lags the first.
Access
- One grant per tool. Each connector is authorised by you, through the tool’s own sign-in (OAuth where the tool offers it). You can see every grant and revoke any one of them from the tool itself as well as from Arden.
- Least privilege. Arden requests the narrowest scopes that let it do its job for that tool, and states them on screen before you grant.
- Read-only for the first week. Always. No deployment writes to any system in its first seven days, whatever the plan or the urgency.
- Visibility mirrors your systems. What a person can see in Arden follows what their role can see in the source system. Arden does not become a side door.
Action
- Written policy gates every write. Every action Arden can take falls under a policy with one of three settings: auto-execute, approval required from a named role, or notify only. Policies are written down in plain language and you can read every one.
- Approval by default. Anything customer-facing or money-moving defaults to approval required. Auto-execution is earned, policy by policy, after you have watched Arden be right.
- Blast radius before approval. Each proposed action shows which system it writes to, what changes, what it costs, how long it stays reversible, and what the customer sees, before you approve it.
- Kill switch at three levels. Per agent, per connector, and global. One click. It stops writes immediately and does not wait for a ticket.
Audit
- Every read and write is logged with the actor (a person or a named agent), the decision it belonged to, and the evidence that decision cited.
- Every decision keeps its transcript. The reasoning behind a proposal is stored with it and can be opened and read.
- Every claim opens in its source. Evidence links back to the record in the system it came from, so “why should I believe you” is always one click.
- Append-only. Decisions, actions, outcomes and learnings are never edited in place. Corrections are new records that reference the old ones.
- A trust-incident counter, tracked forever. An action the operator regrets is recorded as an incident, and the count is reported in every monthly review. The target is zero.
Where your data lives
- Single-tenant per customer. Each deployment has its own database and its own keys. Nothing is pooled across customers.
- Encrypted in transit and at rest on the managed infrastructure the deployment runs on.
- Reasoning runs on Anthropic’s Claude models over an API. Arden Labs does not use your data to train models, and does not permit its providers to.
- Private deployment on request. Multi-entity and finance-heavy engagements can run in your own cloud account (VPC) or on premises.
When it ends
If an engagement ends, every connector is revoked the same day, and your data — the memory, the transcripts, the audit log — is exported to you on request and then deleted. You keep the history; we keep nothing you have not asked us to.
What to ask us
Before you grant anything, ask for the scope list for each tool you run, the starting policy set for your deployment, and a walk through the audit log of a live decision. We would rather answer these on the first call than after. Write to hello@ardenlabs.net.