Security & trust

Your projects are your practice

Contracts, drawings, pay applications, and client records deserve more than a password. Here’s how ARK Projex protects them.

Your firm's data is walled off

Database-enforced isolation

Row-level security on every table means one firm's data is invisible to every other firm — enforced by the database itself, not just the application.

Scoped external access

Consultants see only what's routed to them; contractors see only their submissions; clients see only their portal. External parties can never create or modify your records.

Signed, expiring file links

Project files are served through short-lived signed links — a leaked URL goes dead, fast.

Accounts are hard to steal

Two-factor authentication

Authenticator-app 2FA with single-use backup codes. Firms can require 2FA for all staff — and once a factor is enrolled, a password alone can no longer reach your data, enforced at the database layer.

Password-change alerts

Every password change emails the account owner immediately, with a clear "wasn't you?" path.

Hardened reset links

Reset links are single-use, expire within an hour, and survive corporate email scanners without being consumed. Forgot-password never reveals whether an account exists and is rate-limited.

Built on serious infrastructure

Encrypted everywhere

TLS in transit and AES-256 encryption at rest, on infrastructure operated by Vercel and Supabase (AWS).

Automated backups

The database is backed up automatically, with point-in-time history maintained by our infrastructure provider.

Audited changes

Administrative and security-sensitive actions are recorded in an audit trail.

Questions about security?

Ask them straight to the builder on a demo call — or email us and we’ll answer in writing.

Join the launch list
Security & Trust · ARK Projex · ARK Projex