Terms & Conditions

These terms summarise how Arc requirements management and verification software is offered and used. Arc is typically supplied through enterprise agreements, so a signed order form, security schedule, data-processing agreement or service description may set more specific terms and will control where it conflicts with this public summary. This page is a high-level public summary only.

Last updated .

Scope

By accessing Arc’s website or using Arc software, you agree to these terms. If your company signs a separate agreement with Arc, that signed agreement controls where it conflicts with this page.

Using Arc

  • You may use Arc only for lawful purposes and only with requirements, architecture, interfaces, risks, verification records, evidence, systems and environments you are authorised to access.
  • You must not misuse Arc to bypass permissions, interfere with security controls, or process data you do not have authority to handle.
  • Access credentials and admin tools must be protected and used only by authorised personnel.
  • Users should understand which programme information, integrations, AI workflows and permissions have been approved for their Arc deployment.

Deployment and feature control

  • Arc supports three application deployment models—multi-tenant SaaS, on-premises and air-gapped—with customer-scoped administrative controls.
  • Bring your own database is a data-ownership configuration available across all three models, not a separate hosting model. Application hosting, database ownership, model inference, backups, monitoring and update responsibility are defined for the selected architecture.
  • Connectors, engineering workflows, export features and AI processing controls can be enabled, restricted or left out based on customer requirements.
  • Arc only uses the data sources, tools and environments a customer has approved for the deployment.

Security and updates

  • Arc is designed for controlled enterprise updates, allowing customers to approve, stage, or pin releases where relevant.
  • Arc uses AES-256 encryption at rest, TLS 1.2 or later in transit, logical tenant isolation and granular role-based access controls.
  • If a customer wants behaviour changed or stopped, Arc can be controlled centrally by pausing the deployment, disabling a feature, or tightening policy.
  • Air-gapped deployments require no external calls, keep model inference local and receive updates through an offline process.

Data and privacy

Your use of Arc is also governed by the Privacy Policy.

  • Customers retain control of their programme information, including requirements, architecture, interfaces, risks, verification records, evidence, attachments, comments and approvals.
  • Workflow records, attributable decisions and audit logs may be retained as part of the customer’s selected deployment and retention policy.
  • Arc and enabled model providers never use customer content to train models. Provider inference is transient under the selected deployment policy.
  • Customer-specific retention, deletion, export, model-routing and handling rules are applied at the deployment level and under the signed customer agreement.

Ownership and limits

  • Arc retains ownership of its software, website, and related materials. Customers retain ownership of their own data and materials.
  • Arc may suspend or limit access if necessary for security, abuse prevention, legal compliance, or to protect customers and the service.
  • Unless a signed agreement says otherwise, Arc is provided on an as-available basis and uninterrupted operation is not guaranteed.
  • Service levels, commercial terms, and specific commitments are typically defined in enterprise agreements rather than in this public summary.