Security Policy
Last updated: 2026
At AR People ("we", "our", or "us"), protecting your data is a core priority. This Security Policy describes the measures we take to keep your information safe and the practices we expect from our users.
Data Protection
- Sensitive data is transmitted over encrypted (HTTPS/TLS) connections.
- Passwords and one-time codes are encrypted and never stored in plain text.
- Access to data is restricted based on role and permission (RBAC).
Authentication & Access Control
- Secure sign-in with password and optional email OTP verification.
- Session tokens are signed and validated on every request.
- Device-based validation helps detect and block unauthorized logins.
- A Security Center lets users review active sessions, devices, and login history.
Monitoring & Alerts
We monitor for suspicious activity such as logins from new devices and notify users of important security events so they can act quickly if something looks wrong.
Your Responsibilities
- Keep your password confidential and use a strong, unique password.
- Sign out on shared or public devices.
- Review your active devices and sessions regularly in the Security Center.
- Report any suspicious activity to your administrator immediately.
Incident Response
In the event of a security incident, we take prompt steps to contain and investigate the issue, remediate affected systems, and notify impacted users where required by law.
Responsible Disclosure
If you believe you have found a security vulnerability, please report it to us responsibly so we can investigate and address it. We appreciate the efforts of security researchers who help keep our users safe.
Contact Us
To report a security concern or ask a question, contact us at:
[email protected]