Skip to content
Install on Shopify

Security

Built on certified infra. Locked down on top.

Arbyn runs on Google Cloud, which carries SOC 2 Type 2 and ISO 27001 at the infrastructure layer. On top of that, we make a small number of deliberate choices about how your customer data moves through Arbyn. Here is the full picture.

Infra: SOC 2 Type 2 (Google Cloud)Infra: ISO 27001 (Google Cloud)AI: zero retentionData hosted in the US

Architecture

Two layers. Two different jobs.

Security here is two things stacked. The infrastructure underneath, which we outsource to a vendor whose entire business is being audited. And the application on top, which is ours to get right.

Application layer · Arbyn

How customer messages, Shopify actions, and AI inference flow through Arbyn. Voice fingerprints, kill switch, audit log, refund ceilings, and least-privilege access to production on our side. This is ours.

Owned by ONDUTYOPS
Infrastructure layer · Google Cloud

Servers, databases, networking, OS patching, physical security. Google Cloud carries SOC 2 Type 2, ISO 27001, runs independent third-party audits, and publishes a GDPR DPA. We borrow their work, on purpose.

Independently audited
01 · Application layer

What Arbyn does on top.

The choices we make about your data are the ones that earn the install. Six concrete controls, no enterprise theater, every one of them shipping today.

Zero-retention LLM

Customer messages and order context sent to the Arbyn model for inference are not retained, not logged for training, not shared with anyone. Arbyn’s AI models running under a strict no-training policy.

Encryption everywhere

TLS 1.3 in transit across every request. AES-256 at rest on the database, managed by Google Cloud SQL. API tokens stored encrypted with rotating keys.

Audit log to Shopify timeline

Every action Arbyn takes (address update, approved refund, approved return, reply) writes to the Shopify order timeline. Audit history lives where you already look. No invisible actions, ever.

One-click kill switch

One toggle in the dashboard pauses every channel instantly. Drafts pause mid-write. Auto-send disables. Customers don’t get partial replies. Resume the same way you stopped.

Refund ceilings

Hard limits on any money-moving action. Per-action, per-channel. Refunds and returns come to you for approval either way, and the ceiling caps what Arbyn is allowed to draft in the first place.

Least-privilege access, our side

Inside the company, access is locked down by default. Only the necessary team can reach live systems. When we hire, every new engineer signs the same access policy: justification required, action logged.

02 · Infrastructure layer

What Google Cloud covers.

Google Cloud is the platform Arbyn runs on: Cloud Run for compute, Cloud SQL for the database. The certifications below are Google's, and they cover the infrastructure layer: data centres, hardware, networking, physical security. Under the shared responsibility model they do not extend to Arbyn's own application, configuration or company controls. Those are ours, and they are what section 01 above is about. Arbyn does not hold SOC 2 or ISO 27001 certification of its own, and we will not imply otherwise.

SOC 2 Type 2

Google’s independent audit of Security, Confidentiality and Availability controls at the infrastructure layer. Google’s report, not Arbyn’s.

Current report period in Google Cloud’s Compliance Reports Manager

Report period published
ISO 27001

International standard for Information Security Management Systems, audited by an accredited independent third party.

Current certificate in Google Cloud’s Compliance Reports Manager

Independently certified
SOC 3

Public version of the SOC 2 report, available without NDA.

Same audit period as SOC 2

Publicly available
Third-party audits

Google Cloud regularly undergoes independent third-party audits of its products, systems and infrastructure; Google’s own security team additionally runs continuous penetration testing.

Reports published via Google’s Compliance Reports Manager

Independent
GDPR DPA

Google’s Cloud Data Processing Addendum, with EU transfer protections.

Current version published by Google

Publicly available
CCPA

Covered by Google’s Cloud Data Processing Addendum, which publishes a CCPA/CPRA privacy mapping.

Continuous

Covered
US region

Hosted on Google Cloud US infrastructure (us-central1, Iowa).

US-hosted

Region-pinned
Google Cloud’s compliance reports

Google’s Compliance Reports Manager: SOC 2 and SOC 3 reports, ISO/IEC certificates, and self-assessments, on demand.

View Google Cloud compliance

Data flow

What actually happens when a customer emails.

01 / INBOUND
Customer sends email

Inbound mail hits your support address. Arbyn forwards the message body, customer email, and order ID into the application (TLS 1.3 in transit).

Encrypted · logged
02 / CONTEXT
Arbyn pulls Shopify context

Order, customer history, fulfillment status, and your store policies pulled fresh from Shopify over a secure connection. No copy is kept once the conversation is done.

Live API call
03 / INFERENCE
Reasoning runs on Arbyn’s AI

Message and context sent to Arbyn’s AI for inference. Not retained, not used for training, returned and forgotten. Reply drafted in your voice fingerprint.

Zero retention
04 / ACTION
Reply sent, action logged

Final reply sent from your domain. Any Shopify action (address update, approved refund, approved return) writes to your store’s order timeline. Conversation stored encrypted in your region.

Audit trail

The promises

Six things we won’t do.

If we ever change one of these, we email every customer, publish it on the Changelog, and you can cancel and take your data with you. No surprises.

We will not sell your data.

No third-party data brokers, no marketing partner lists, no anonymized-but-monetized data products. Your customer data is yours.

We will not train models on your data.

Customer messages and your support history are not training data. Our AI providers’ terms confirm this. Voice fingerprint is a set of style signals, not your raw messages.

We will not take silent actions.

Every address change Arbyn makes, and every refund and return you approve, writes to the Shopify order timeline. If we did it, you’ll see it. Same place you already look.

We will not add subprocessors without notice.

30-day public notice before any new subprocessor is added. Object in writing and we’ll work it out, or cancel and your data is deleted.

We will not lock you in.

Cancel anytime from your Shopify admin. Your data is exported on cancellation, and deleted from Arbyn within 30 days, retaining only audit logs required by law.

We will not hide incidents.

Any security incident affecting your data, disclosed within 72 hours of detection, by email, with full scope and remediation. This is the GDPR floor. We treat it as the ceiling too.

Contact

Talk to a human about security.

Data processing agreements, security reviews, vulnerability reports, and GDPR data access requests. Real reply within 1 business day.

Security questions & audits
Ask a security question

For data processing agreements, security reviews, contracts, or any paperwork a larger buyer needs before signing.

Vulnerability disclosure
Report a vulnerability

Found something? Send us the details. We acknowledge within 24h and patch fast. No bug bounty program yet, but we publicly credit responsible disclosure.

Ready to try Arbyn?

Certified infra. Honest application layer.

Start free with 150 AI conversations a month. 500 is $59/month and unlimited is $99/month, both flat. Install from Shopify and your data stays in the lane you’d expect.