Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Trust Center

Security and Architecture Principles

ArtOfTheHack operates above grantee organization systems of record. The architecture is designed so that a compromise of the decision layer does not become a compromise of the enforcement layer.

Controls

Documented commitments

  1. Control 01

    Tenant isolation

    Tenant data, keys, policy, and decision records are isolated. Dedicated and grantee organization-controlled deployments provide physical separation where contracted.

  2. Control 02

    Encryption in transit and at rest

    Transport encryption is required on every connector, and stored evidence and decision records are encrypted at rest.

  3. Control 03

    Grantee organization-controlled deployment options

    Deployment can run in ArtOfTheHack-operated infrastructure, in the organization's own cloud account, or in isolated environments.

  4. Control 04

    Least-privilege integration

    Connectors request the narrowest scope that supports the workflow, and read-only scopes are the default starting point.

  5. Control 05

    Read-only shadow mode

    Every deployment can begin without any write capability so decisions can be compared against current practice before enforcement.

  6. Control 06

    Role-based and attribute-based control

    Access to evidence, decisions, and approvals is governed by role and attribute policy defined by the grantee organization.

  7. Control 07

    Audit logs

    Administrative actions, policy changes, approvals, and decision events are logged and exportable.

  8. Control 08

    Secure connector architecture

    Connectors run with scoped credentials, support grantee organization-controlled gateways, and can be revoked independently.

  9. Control 09

    Key-management options

    Grantee organization-managed keys are available where the deployment model and contract support them.

  10. Control 10

    Incident-response planning

    Security incidents follow a defined response process with grantee organization notification commitments set in contract.

ArtOfTheHack does not claim certifications that have not been achieved. Certification status is provided under contract and is not asserted on this website.

These are the operating commitments of the platform and the award agreement, described as designed and delivered. They are not a certification, an independent security audit, or a compliance attestation, and ArtOfTheHack does not claim any. Protections that depend on the deployment model are scoped in writing with each grantee before connection.