Trust Center
Security and Architecture Principles
ArtOfTheHack operates above grantee organization systems of record. The architecture is designed so that a compromise of the decision layer does not become a compromise of the enforcement layer.
Controls
Documented commitments
Control 01
Tenant isolation
Tenant data, keys, policy, and decision records are isolated. Dedicated and grantee organization-controlled deployments provide physical separation where contracted.
Control 02
Encryption in transit and at rest
Transport encryption is required on every connector, and stored evidence and decision records are encrypted at rest.
Control 03
Grantee organization-controlled deployment options
Deployment can run in ArtOfTheHack-operated infrastructure, in the organization's own cloud account, or in isolated environments.
Control 04
Least-privilege integration
Connectors request the narrowest scope that supports the workflow, and read-only scopes are the default starting point.
Control 05
Read-only shadow mode
Every deployment can begin without any write capability so decisions can be compared against current practice before enforcement.
Control 06
Role-based and attribute-based control
Access to evidence, decisions, and approvals is governed by role and attribute policy defined by the grantee organization.
Control 07
Audit logs
Administrative actions, policy changes, approvals, and decision events are logged and exportable.
Control 08
Secure connector architecture
Connectors run with scoped credentials, support grantee organization-controlled gateways, and can be revoked independently.
Control 09
Key-management options
Grantee organization-managed keys are available where the deployment model and contract support them.
Control 10
Incident-response planning
Security incidents follow a defined response process with grantee organization notification commitments set in contract.
ArtOfTheHack does not claim certifications that have not been achieved. Certification status is provided under contract and is not asserted on this website.
These are the operating commitments of the platform and the award agreement, described as designed and delivered. They are not a certification, an independent security audit, or a compliance attestation, and ArtOfTheHack does not claim any. Protections that depend on the deployment model are scoped in writing with each grantee before connection.
Continue
