Data & Compliance

Last updated: July 14, 2026

1. Why this page exists

Most tools that make claims about your architecture need an agent in production. AridNova does not. But it does need to read your source code, which is usually the most sensitive asset an engineering organisation has. If you are evaluating us, you are entitled to a straight answer about where that code goes.

This page describes our data handling for the platform. Website analytics and visitor information are covered separately in our Privacy Policy, and the rules for using the demo are in the Terms of Use.

2. Static analysis only, no production access

AridNova reconstructs your dependency map from source code. There is no runtime agent, no instrumentation, and no sidecar. We do not connect to your production environment, we do not read production traffic, and we do not need production credentials to perform an analysis.

The one exception is deliberate and driven entirely by you: the test executor runs generated tests against a target URL that you configure, using tokens you supply. Nothing runs against a live system unless you explicitly point it there. See Credentials and secrets below.

3. What the platform processes

CategoryWhat it isWhere it comes from
Source codeThe contents of repositories you select, pinned to a branch and commitA repository or GitHub organisation you connect, or metadata you upload
Intermediate representation (IR)A structured model of your services, endpoints, roles, and relationships, derived from your codeGenerated by AridNova from the source above
Analysis artifactsVerification results, policy findings, change-impact deltas, generated test scenarios and suitesDerived from the IR
Saved sessionsA named snapshot of a workspace so an analysis can be reopened laterCreated when you save a session
CredentialsA GitHub token for private repositories; target URL and auth tokens for test executionEntered by you

4. The public demo is not a private environment

This is the most important operational point on this page. The demo at our public toolkit URL is a shared, non-production sandbox intended for exploring the product against open-source repositories.

Do not analyse private, proprietary, regulated, or organisational repositories in the public demo, and do not enter real credentials or production tokens into it. It is periodically reset, it carries no confidentiality commitment, and it is not covered by any data protection agreement. If you need to evaluate AridNova against private code, contact team@aridnova.cloud and we will arrange a scoped environment under a signed agreement.

5. Credentials and secrets

If you provide a GitHub token to analyse a private repository, it is masked after saving and is not displayed again in the interface. If you configure the test executor, the target URL and the admin and user tokens you supply are used to make the requests you asked for.

Our guidance, in order of preference:

  • Use tokens scoped to the narrowest read access that will do the job, never an organisation-wide admin token.
  • Use short-lived tokens and revoke them when your evaluation is finished.
  • Never put a production credential into the public demo. Use a staging or throwaway target.

6. AI-assisted features

Several features — the LLM prompter, AI risk triage, and the AI insights summaries — use large language models to summarise analysis results and draft test scenarios. This means material derived from your code can be sent to a third-party model provider for processing.

If you are evaluating AridNova for a regulated environment, this is a question you should ask us directly rather than infer from a web page. Email team@aridnova.cloud and we will tell you which model providers are in use for the features you care about, what is sent to them, and what options exist for deployments that cannot use third-party model providers.

7. Hosting and infrastructure

AridNova runs on Microsoft Azure in the United States (East US region). The website, the demo environment, and supporting services are hosted there. We are based in Tucson, Arizona, United States.

8. Subprocessors

These third parties may process data on our behalf. We will update this list when it changes.

ProviderPurposeLocation
Microsoft AzureApplication hosting, container registry, and demo infrastructureUnited States (East US)
PostHogProduct and marketing analytics for the aridnova.net websiteUnited States
Google (Analytics / Tag Manager)Aggregate website traffic measurement, where enabledUnited States
GitHubSource of repositories you choose to analyse, when you connect a repository or organisationUnited States
YouTube (Google)Embedded product walkthrough videos on documentation pagesUnited States

9. Retention and deletion

For pilots and paid engagements, retention and deletion are defined in your agreement with us, including what is kept, for how long, and what happens at the end of the engagement. We would rather agree that with you explicitly than publish a number here that does not match your contract.

For the public demo, treat nothing as retained and nothing as protected. It is reset periodically and is not intended to store anything you care about.

To request deletion of data associated with your evaluation, email team@aridnova.cloud.

10. Security measures

We currently:

  • serve all traffic over HTTPS, with HSTS enabled;
  • apply standard browser hardening headers, including a strict referrer policy, clickjacking protection, MIME-sniffing protection, and a permissions policy that disables camera, microphone, and geolocation;
  • restrict access to production infrastructure to the people who need it;
  • keep analysis workloads separate from the marketing website.

11. What we do not claim

We would rather tell you this now than have you discover it in a security review.

  • We do not hold SOC 2, ISO 27001, or equivalent certification today. If your procurement process requires one, tell us early so we can be honest about timelines.
  • We do not currently offer a HIPAA Business Associate Agreement. We work with healthcare IT and fintech teams, but AridNova analyses source code rather than patient or customer records, and engagements should be scoped so that regulated data is not processed by the platform.
  • AridNova's findings are analysis, not assurance. Static analysis, formal verification, and AI-generated output are all subject to false positives and false negatives. A clean result is not evidence of compliance and is not a substitute for security review or professional judgement.

12. Reporting a vulnerability

If you find a security issue in AridNova, email team@aridnova.cloud with enough detail to reproduce it. Please give us a reasonable opportunity to fix it before disclosing it publicly. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and do not access or modify data that is not their own.

13. Contact

For data protection, security, or compliance questions, including security questionnaires and due diligence, team@aridnova.cloud reaches the team directly.