v1.4 policiesEffective from v1.4 general availability.
Arbiter Security Aletheia v1.4

Subprocessors and Data Residency

Status: v1.4 disclosure. Effective at general availability.

The v1.4 hosted service is designed for London-region processing and local-first analysis. Provider contracts, support access, routing, and model processing can create international transfers; contractual safeguards and provider data controls are used where applicable.

Provider Purpose Expected region or transfer
Fly.io Control plane, authenticated web application, and local-node coordination London (lhr)
Neon Postgres operational and derived evidence London region
Cloudflare DNS, encrypted backup objects, purge registry Global edge; configured R2 account
Clerk Authentication and account identity Provider-managed regions
Stripe Billing and payment records Provider-managed global service
Anthropic and enabled model providers Agent inference for user-requested sessions The configured Aletheia Anthropic workspace uses the US data location; customer-selected provider accounts follow their selected provider regions and terms
Sentry Opt-in, filtered error diagnostics Configured Aletheia project uses Germany; provider terms govern support access and transfers
PostHog Bounded product analytics when enabled Configured Aletheia project uses PostHog EU
Grafana Cloud Aggregate operational metrics and alerting, including readiness, backup freshness and spending counters Configured Aletheia stack uses London (prod-gb-south-1)
GitHub Signed release distribution and operational workflows Provider-managed regions

Raw customer binaries remain encrypted on the customer's device. Analysis decrypts them only into an owner-only ephemeral local session directory and bind-mounts them read-only into a signed, networkless Docker worker on that device. Raw binaries, recognizable binary fragments, local paths, and file names do not enter the Fly control plane, model prompts, logs, metrics, Neon, R2, or other subprocessors. Only bounded derived evidence permitted by the data-class policy may enter Postgres.

Model prompts and evidence sent during an agent session depend on the selected provider and customer action. Provider capabilities, retention, and zero-data-retention status are surfaced separately and should be evaluated before using sensitive material.

Material subprocessor changes will be published here. DPA and transfer requests may be sent to privacy@arbitersec.com.

Configuration facts checked: 2026-09-07. Legal approval remains a separate release checkpoint.