Technical and Organizational Measures

A factual security overview for Archivian's current architecture.


Updated at: 25 September 2026

This overview describes measures visible in the code and deployment configuration. It is not a certification, penetration-test report, SLA, or claim of complete security. Operational practices not visible in the repository are marked for confirmation in the owner audit.

1. Access control and authentication

2. Secrets and credentials

3. Network and service separation

4. Data storage and transmission

5. Logging, monitoring, and incident visibility

6. Availability and recovery

7. Secure development and deployment

8. Deletion and data minimization

9. Personnel and incident response

Archivian is currently operated as a small founder-led service. Access should be limited to people who need it, reviewed when access changes, and protected with strong authentication. The internal breach procedure covers detection, containment, evidence, role analysis, notification assessment, remediation, and documentation. Its escalation contacts are not yet filled in, and formal access-review evidence and provider-access inventories require owner confirmation.

Domain registration is held with Namecheap, while authoritative DNS is served by Cloudflare rather than the registrar. Registrar and DNS accounts are administrative controls over service availability and certificate issuance, and are treated as privileged access alongside infrastructure accounts.

10. Known gaps before paid launch