# Security you can audit

> SOC 2 Type II, GDPR compliant, and fully open source. We protect your data with strong controls, and let you verify every one of them.

Canonical: https://argos-ci.com/security

## Compliance

- SOC 2 Type II — independently audited security controls. Request the report from the trust center: https://argos-ci.com/trust-center
- GDPR compliant — privacy and data protection for the EU.

## How we keep your data safe

The essentials, without the security-theater checklist. Every claim below is enforced in code you can read.

- **Open source, auditable** — Every line of the platform and the SDKs is public. Read the code, verify our claims, and send a PR.
- **Encrypted access tokens** — Your GitHub and GitLab access tokens are encrypted at rest, never stored in plain text.
- **Screenshots on secure S3** — Stored on AWS S3 in the US and replicated to the EU, encrypted at rest and in transit with modern protocols.
- **SOC 2 Type II** — Independently audited controls across infrastructure, access management, and data protection.
- **No source code access** — Argos never needs your source. An optional GitHub mode works without any content permission.
- **Least-privilege access** — Access to your data is role-based, logged, and monitored, and deleted when you leave.

## SOC 2 Type II

SOC 2 is the AICPA framework for how organizations manage customer data across security, availability, processing integrity, confidentiality, and privacy. Type II verifies our controls work over time, not just on paper. This is a long-term security investment, not a short-term growth play.

- Framework: AICPA SOC 2 Type II
- Auditor: Prescient Security (https://prescientassurance.com)
- Continuous monitoring: Vanta (https://vanta.com)
- Report: https://argos-ci.com/trust-center

## GDPR

Many of our customers are based in Europe or serve European users. We align our operations with GDPR, from how we handle data to how we design our systems. Data is stored in the US and replicated to the EU, with Standard Contractual Clauses covering lawful transfers.

GDPR gives individuals the right to:

- Know how their data is used
- Access and correct their data
- Delete their data
- Limit or object to processing
- Data portability
- Protection from solely automated decisions

- **Data Encryption** — All datastores are encrypted at rest. Sensitive information is encrypted at the application level.
- **Access Control** — We implement strict access controls to ensure that only authorized personnel can access sensitive data.
- **Data Minimization** — We only collect and process the minimum amount of personal data necessary for our services.

Privacy policy: https://argos-ci.com/privacy · Data Processing Agreement: https://argos-ci.com/dpa

## Responsible disclosure

We value input from the community to help us detect vulnerabilities. If you believe you have found a security issue, please follow our disclosure policy to report it: https://github.com/argos-ci/argos/security/policy

## Frequently asked questions

### Are my builds and screenshots publicly visible?

Open source projects on Argos are public by default, meaning their builds and screenshots are visible to anyone. Private projects are accessible only to authorized users within your organization. All data is secured and access-controlled.

### How secure is Argos?

Yes. Argos is SOC 2 Type II compliant, fully open source, and trusted by security-conscious companies, including cybersecurity firms and banks. We follow strong security practices and operate with full transparency.

### Where are screenshots stored?

Screenshots are securely stored on AWS S3 in the United States and replicated to the European Union. All data is encrypted at rest and in transit using modern encryption protocols.

### Can Argos access my builds?

Only authorized Argos engineers can access builds for support or debugging purposes. Access is strictly role-based, logged, and monitored.

### Is Argos open source?

Yes. Argos is fully open source. You can audit our codebase at github.com/argos-ci.

### What data does Argos collect?

Argos collects only the data required for visual testing: screenshots you upload, commit metadata, and pull request information. It does not collect analytics, behavioral data, or source code.

### Can I delete my data from Argos?

Yes. You can delete builds, screenshots, or projects at any time from the Argos dashboard, or contact support for full data removal.
