Security

Security built into the foundation.

Security at Arteliox isn’t a feature bolted on at the end — it’s how the platform is built. Every solution inherits the same protections from day one.

Per-tenant isolation

Row-level security and composite foreign keys enforce tenant separation in the database. One tenant can never read another’s data.

Private file delivery

Files live in a private object store and are served only through short-lived signed URLs. Raw file keys never leave the server.

No payment data on us

Payments run through Stripe with your business as merchant of record. Arteliox never touches card data or holds your funds.

Least-privilege access

Role-based access across every module, and the app connects to the database as a non-owner, non-superuser role — by design.

Append-only audit trail

Sensitive actions — payments, file access, status changes — are recorded to an append-only audit log you can trace.

Reliable by design

A durable workflow engine delivers each message exactly once, surviving retries and restarts — no duplicate or dropped emails.

The path a delivery takes

From your studio to your client — with the checks that keep it private at every hop.

Diagram: a delivery flows from your studio through the Arteliox core (row-level security, private file store, signed URLs, pay-to-unlock) to your client's one-link portal, with an append-only audit trail underneath
Questions about security?

We’re happy to go deeper.

Reach out and we’ll walk you through how Arteliox protects your studio and your clients’ data.