Security and deployment

The boundary is carried by the key

Arena Pro is cloud-native and multi-tenant. A partner key carries its own tenant, so an integration cannot reach another library — and nothing leaves the workspace on a link without an expiry and an audit trail.

Partner API key

  • Tenant

    Carried by the key itself

  • Reach

    One library. No cross-tenant call exists

  • Rate limit

    Per key, so one integration cannot degrade the rest

  • Uploads

    Presigned URLs, issued per request

Metadata schema discovery tells an integrator which fields are writable, and of what type.

Every external link

  • Expiry

    Required, set per link

  • Password

    Optional, per link

  • Downloads

    Signed URLs, short-lived, tied to the share

  • Anonymous access

    Rate-limited

Audit trail

Who viewed or downloaded what, when, and from where

Revoke

A partner can never address another tenant's library.

Not a permission an administrator remembers to set. The key issued to a partner carries the tenant inside it, so no request shape reaches across the boundary — and per-key limits mean one busy integration cannot slow the platform for anyone else.

Where the controls actually sit

  • Identity and configuration

    Users and groups sit in a central identity layer. A platform administrator turns capabilities on per tenant — including which AI provider and model a deployment uses. That choice is yours, not ours.

  • Sharing that legal can sign off

    Expiry, optional password, download control, and an audit trail per share and per collection. Revoke a link at any moment; expired links are cleaned up by a background process.

  • Disclosure by omission

    A public gallery lists only the assets visible right now, and the count matches. Hidden and future-dated assets are never disclosed — not greyed out, not marked locked. The recipient cannot tell anything is missing.

  • Failure that stays contained

    The delete endpoint is rate-limited per user and its error path preserves the session. A rejected AI analysis fails fast with the cause recorded. Image background removal runs in the browser, so that file is never sent anywhere to be read.

What this page does not claim

Read what is above and nothing more. Five things a security review will ask for are absent, because we will not print them before they are evidenced:

  • Certification marks. No SOC 2, no ISO 27001 badge until there is a report behind it.
  • Hosting regions and data residency options.
  • Processor terms and a data processing agreement.
  • Single sign-on. Identity is centralised, but SSO is not part of the shipped product.
  • On-premise, NAS or archival storage tiers.

Ask, and you get the position on each in writing — including where it is a roadmap item rather than a product. The risk is the vendor that guesses, not the one that tells you which column each row is in.

Send the security questionnaire. Every answer will be either evidenced or marked as not yet.

Talk To Us