This page summarizes how Arista Labs secures the SMEme platform and the expert reasoning systems hosted on it. For binding terms, see the Terms of Use and Privacy Policy.
Where data is stored
The Service is hosted on cloud infrastructure in the United States. Application data—including account information, Expert Assets, and Generated Outputs—is stored in managed PostgreSQL databases provided by our infrastructure vendors. Authentication credentials and session state are managed through our authentication provider.
Deterministic reasoning evaluation (the automated reasoning engine for published workflows) runs on SMEme application servers hosted by Render Services, Inc.—not on OpenAI or other third-party AI model APIs. See our Subprocessors page for how AI-assisted features differ.
See our Subprocessors page for the vendors we use to operate the Service.
Encryption in transit
Connections to the Service use HTTPS (TLS). API traffic, web sessions, and integrations with third-party services are encrypted in transit using industry-standard protocols.
Encryption at rest
Data at rest is protected through encryption and access controls provided by our cloud infrastructure and database vendors. We do not operate our own physical data centers.
Backups
Database backups are performed by our infrastructure providers on a regular schedule to support disaster recovery and operational continuity. Backup retention follows provider defaults and our operational requirements. Deleted data may persist in backups for a limited period before being overwritten.
Authentication
Web authentication is handled through Clerk, which supports secure sign-in flows including email verification and optional multi-factor authentication configured in your account settings. API and MCP access for connected agents uses OAuth 2.1 bearer tokens with scoped permissions.
Access controls
Access to production systems is restricted to authorized personnel with a legitimate operational need. Application-level authorization ensures users can access only their own Expert Assets and workflows unless they have been explicitly granted access through platform features (for example, published public workflows or organization-scoped sharing when available).
Monitoring and incident response
We monitor platform availability and security-relevant events. If you believe you have discovered a security vulnerability or unauthorized access related to the Service, contact us promptly at contact@aristalabs.ai.
We will investigate good-faith reports and take reasonable steps to address confirmed issues. Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to respond.
Your responsibilities
You are responsible for safeguarding your account credentials, reviewing Generated Outputs before relying on them, and configuring access to your Expert Assets appropriately. We provide the SMEme platform; you control what expertise you encode and who may use it.