Security
How we approach the protection of your health data.
Current security approach
This document describes our current security approach for the operational ARQENA service and may be updated as the service evolves.
Authenticated Access
Access to personal records and intelligence requires valid authentication. Unauthenticated requests are rejected and cannot access any user data or longitudinal analysis.
Encryption in Transit
All communications between your devices and ARQENA are transmitted over encrypted HTTPS connections. We utilize secure transport protocols to protect data while in transit.
Access Controls
Access to health data is restricted to authorized application flows. The platform utilizes standard authentication and authorization mechanisms to ensure that users only access their own information.
Controlled Infrastructure
Health data, laboratory results, and physiological signals are stored within controlled application infrastructure. We do not share your personal information with third parties for advertising or marketing purposes. Learn more about ourprivacy policy.
Security Inquiries
For security-related inquiries or responsible disclosure, please contact us at security@arqena.com. We take security concerns seriously and will respond promptly.
Last reviewed: August 2026. This page documents the protections ARQENA can state today. Encryption of stored data at rest is not documented here and should not be inferred from the transport protections above. ARQENA does not currently hold SOC 2, ISO 27001, HIPAA, or equivalent certifications. This documentation will be expanded as the platform matures.