> ## Documentation Index
> Fetch the complete documentation index at: https://archie.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Archie FAQ: Security, compliance, and data

> How Archie secures your app, SOC 2, HIPAA, and GDPR, who owns your code and data, exporting, and lock-in.

How Archie protects your app and your data, and what you own.

## Is Archie secure?

Yes. Security is part of the platform, not something you add later. Archie Core ships with:

* [Role-based access](/docs/features/backend/app-services/role-based-access) with read, write, update, and delete permissions on every table, plus [row-level filters](/docs/features/backend/app-services/row-level-filters)
* [Archie Auth](/docs/features/backend/app-services/authentication-providers/archie-auth/security) with password hashing, signed and encrypted tokens, refresh-token rotation, rate limiting, and account lockout
* [Field-level encryption](/docs/features/backend/app-services/encryption/overview) for sensitive columns
* Credentials encrypted at rest with AES-256-GCM
* Configurable [CORS and rate limiting](/docs/features/backend/settings/network)

Your prototype becomes your production app directly — there's no separate "demo" version to harden later.

## How do I secure my Archie account?

Turn on two-factor authentication, and review your active sessions and connected devices, from your account's [Security](/docs/introduction/account/security) settings.

## Is Archie SOC 2 compliant?

SOC 2 is available as an add-on for Enterprise plans. The infrastructure is built to be compliance-ready, and the formal certification is layered on as part of a dedicated Enterprise engagement. See [Enterprise](/docs/introduction/enterprise/overview).

## Is Archie HIPAA compliant?

HIPAA compliance is available as an add-on for Enterprise plans. If you're building healthcare applications that handle protected health information, we provide the compliance framework, Business Associate Agreement, and required controls as part of an Enterprise engagement. See [Enterprise](/docs/introduction/enterprise/overview).

## Is Archie GDPR compliant?

GDPR compliance is available as an add-on for Enterprise plans. It includes Data Processing Agreements, data residency controls, right-to-erasure workflows, and breach notification procedures as part of the engagement. See [Enterprise](/docs/introduction/enterprise/overview).

## Who owns the code and data I create with Archie?

You do. Every application you build with Archie belongs to you — the code, the architecture, and the data. You can export your code to GitHub at any time, and your data lives in a standard PostgreSQL or MySQL database that is fully portable. Full ownership and IP terms are in our Terms of Service.

## Can I export my code?

Yes. Paid plans include GitHub sync and full code export. Push your codebase to your own GitHub repository and work on it in your own environment whenever you want. Exporting is always free — it never uses AI credits.

## Can I export my data?

Yes. You can [export any table to CSV](/docs/features/backend/data-model/exporting-data), query your data directly with SQL in the [SQL Playground](/docs/features/backend/data-model/sql-playground), or read it through the auto-generated [GraphQL](/docs/features/backend/graphql-api-explorer/overview) and [REST](/docs/features/backend/rest-api-explorer/overview) APIs.

## Does Archie lock me into its platform?

No. Archie uses standard languages, standard databases, and major cloud providers. Your code lives in your GitHub repository and your data lives in PostgreSQL or MySQL. Archie adds a lot on top — the plan, the generation, the managed backend — but if you ever want to leave, you can export everything and replace the parts Archie runs with your own code or open-source tools.

## Can Archie be self-hosted or run on-premise?

Yes. A self-hosted option is available with Enterprise backends. Schedule a call with our sales team to learn more — see [Enterprise](/docs/introduction/enterprise/overview).
