Read-only access, and you can revoke it any time
What we connect to
Every connection is read-only. Keys are encrypted with AES-256-GCM before they reach the database, and the encryption key lives outside it.
- Stripe
- Restricted keys only (they start with
rk_live_). Paste a secret key and we refuse it. - Mercury
- A read-only API token, used to show cash in and out and to match payouts to deposits.
- Google Analytics
- One permission,
analytics.readonly, for the property you pick. Nothing else in your Google account.
What we never store
- Buyer passport or licence images
- Customer card numbers
- Full bank account or routing numbers
- Keys that can write, refund or move money
- Your Stripe, Mercury or Google passwords
Buyer ID checks
Buyers can choose to verify their identity with a passport or driving licence. Stripe Identity runs the check; the document and selfie stay with Stripe. We keep only the result, the verified name, the document type and the country.
Revoking our access
Cut us off at the source any time, without asking. Numbers already synced stay in the room until you delete it; nothing new comes in.
- Stripe
DevelopersthenAPI keysthenRestricted keys
Delete or roll the key you made for Arrhis.
- Mercury
SettingsthenAPI tokens
Revoke the token you made for Arrhis.
myaccount.google.com/permissions
Remove Arrhis from the list.
What buyers can do
Only what their stage allows. Every file view is watermarked with their email, the time and the room ID, downloads are off unless you allow them, and you can revoke one buyer without touching the rest.
Audit log
Every NDA signature, stage change, download and revoke is recorded with who and when.
- 14:05Jane Ortiz signed the NDA
- 14:06You moved Jane Ortiz to stage 2
- 14:31Jane Ortiz downloaded P&L 2025, normalized.pdf
- 16:12You revoked Tom Becker
Deleting your data
Delete a room and every buyer link stops working at once. Our policy is to delete its synced numbers, files, stored keys and buyer activity within 30 days.
What we don't claim
Arrhis holds no SOC 2 report or other security certification today. For a security questionnaire or to report a vulnerability, email [email protected].