Security overview

Chainline · ARC Loops · Last updated: July 2026

Chainline is designed so IT, compliance, and security reviewers can understand how identity, access, files, and audit trails work — before a dedicated deployment.

Authentication

Users sign in with Microsoft Entra ID (Azure AD) only. There is no separate Chainline password store. API requests carry validated Microsoft tokens.

Authorisation

Access is role-based (requester, approver, vetter, auditor, administrator). Navigation and APIs are gated so people only see what their role allows. Auditors have organisation-wide read access without day-to-day approval authority.

Documents

Files are stored in private object storage. Upload and download use short-lived signed URLs. Documents can be versioned during approval and locked after final approval. PDF preview is available in-app where supported.

Auditability

Material actions — approvals, returns, rejects, vetting, chain changes, and file updates — are recorded in an event trail with actor, time, and context for compliance review and export.

Microsoft 365 integration

  • SSO and directory sync via Entra ID / Microsoft Graph
  • People search from the customer tenant
  • Teams chat notifications with deep links (as configured)
  • Teams personal tab packaging for admin centre deployment

Dedicated deployments

Most enterprise customers receive an isolated environment bound to their Microsoft tenant, with optional custom domain, named onboarding, and contractual SLA. Shared multi-tenant production is a later phase; isolation is the default for serious rollouts.

Subprocessors (typical)

Depending on the deployment, Chainline may rely on:

  • Application hosting (edge / managed Node hosting)
  • Managed PostgreSQL
  • Private S3-compatible object storage (e.g. Cloudflare R2)
  • Microsoft 365 (Entra ID, Graph, Teams) in the customer’s tenant

Exact subprocessors and regions for a given customer are confirmed in the order / DPA package.

Roadmap

Formal certifications (for example SOC 2) and third-party penetration test reports are on the trust roadmap. Enterprise buyers receive a security questionnaire response and architecture review as part of onboarding.

Contact

Security enquiries: hello@arcloops.io