SECURITY & SOVEREIGNTY

Data security, sovereignty and confidentiality

A SaaS CRM built for the demands of M&A advisors and private equity firms.

Arx provides a SaaS CRM dedicated to Corporate Finance, M&A, Private Equity and deal flow professionals.

Our clients handle highly sensitive data: mandates, acquisition or disposal opportunities, investor information, strategic contacts, interaction histories, confidential pipelines and documents related to transactions. In this context, security, confidentiality, availability and data sovereignty are not merely technical requirements but business prerequisites.

That is why Arx has designed its security framework around a defence-in-depth approach, combining European infrastructure, strict access control, encryption, continuous monitoring, structured vulnerability management, service continuity and auditability.

Sovereign infrastructure, hosted exclusively in Europe

Arx relies exclusively on OVHcloud to host its platform. Data is not hosted on AWS, Microsoft Azure or Google Cloud.

Our architecture is built on an independent European infrastructure:

Production
Paris, France
Backups
Strasbourg, France
Disaster recovery
Berlin, Germany

This architecture allows Arx to offer a hosting environment aligned with the challenges of digital sovereignty, control over data location, and reduced exposure to non-European jurisdictions.

Protection against extraterritorial laws

Data sovereignty is not limited to geographic location. It also means controlling the jurisdictions to which the providers, infrastructure and technical components used by the platform are subject.

Arx has chosen an independent European infrastructure to avoid exposing its clients to foreign extraterritorial legislation, such as the Cloud Act, the Patriot Act, the Foreign Intelligence Surveillance Act (FISA), or more generally any mechanism allowing non-European authorities to compel access to data from providers subject to their jurisdiction.

None of the hosting components used by Arx for the platform is operated by AWS, Microsoft Azure or Google Cloud. Data is hosted exclusively with OVHcloud, within a European infrastructure, with production in France, backups in France and a disaster recovery site in Germany.

This approach allows Arx to provide a sovereign hosting environment, designed to protect the sensitive data of M&A advisors, investment funds, in-house M&A teams and Corporate Finance departments against the risks associated with non-European extraterritorial laws.

In practice, the data entrusted to Arx remains hosted in Europe, within a European legal framework, with no dependency on cloud infrastructure subject to the main US extraterritorial regimes.

A certified European cloud foundation

By relying on OVHcloud, Arx benefits from a European cloud foundation committed to a recognized approach to security, compliance and certification.

The OVHcloud certifications and frameworks relevant to our domain notably include:

ISO/IEC 27001Information security managementISO/IEC 27017Cloud security best practicesISO/IEC 27018Personal data protection in the cloudISO/IEC 27701Privacy & personal data managementSOC 1 · 2 · 3Security, availability & confidentiality controlsCSA STARCloud best-practices frameworkGDPRPersonal data processing

These frameworks complement Arx’s own security measures and help meet the expectations of organizations subject to high requirements in audit, governance, confidentiality and compliance.

A cloud-native, scalable and continuously monitored architecture

The Arx platform is built on a cloud-native architecture based on Infrastructure-as-Code and GitOps principles, designed to support our clients’ requirements for security, performance, scaling and high availability.

KubernetesGitOpsArgo CDPrometheusGrafanaAlertmanager

We use Kubernetes to ensure stability, resilience and scalability, GitOps and Argo CD for controlled, traceable and secure deployments, and Prometheus, Grafana and Alertmanager for continuous platform monitoring.

This architecture maintains a high level of operational control while meeting the availability needs of the teams who use Arx daily to manage their opportunities, investor relations, transactions and mandates.

Platform technical security

Arx applies a multi-layered technical security approach to protect the platform, the data and user access. The architecture is multi-tenant, with logical segregation per client and isolation mechanisms designed for the separation of data, rights and usage. This is complemented by physical separation of certain infrastructure components, as well as strict separation of the production, pre-production and development environments.

TLS 1.3AES-256WAF / WAAPAnti-DDoSRole-based accessSSOMFA (mandatory)

Data in transit is encrypted with TLS 1.3 and stored data, including backups, is encrypted with AES-256. The platform is protected by WAF / WAAP and anti-DDoS mechanisms. Access is governed by controls based on roles, responsibilities and business needs. SSO is available and MFA is mandatory on sensitive environments. Arx also continuously monitors its critical components, with event logs, application audit trails, regular vulnerability scans and continuous analysis of code, dependencies and container images.

Service continuity and disaster recovery

Arx is organized to maintain or restore critical services through automated infrastructure, regular backups and a documented recovery plan.

< 4h
RTO target
< 24h
RPO target
15 weeks
Backup retention

Our continuity measures include:

These measures aim to ensure operational continuity for the teams that rely on Arx to manage their deal flow, investor relations, opportunities and transactions.

A regularly audited organization

Arx works with clients subject to strong requirements in security, compliance, confidentiality and continuity, particularly in the banking and financial sector.

Our security framework is regularly subject to technical, organizational and GDPR audits carried out by our prospects or clients. These audits challenge our practices and help us continuously raise our standards.

The latest audits conducted by demanding players, notably in the banking and M&A sector, have confirmed the robustness of our framework and supported both ongoing and new engagements with clients operating under stringent security constraints.

Our security commitment

Arx secures its clients’ data within a sovereign infrastructure through an approach structured around four pillars:

Prevent
Reduce risk exposure through a secure architecture, strict access controls, encryption and environment separation.
Detect
Identify threats, vulnerabilities and abnormal behaviour through continuous platform monitoring.
Correct
Address gaps quickly and for the long term through patch management, testing, traceability and continuous improvement.
Withstand
Ensure the continuity of critical services through regular backups, automated infrastructure and a documented recovery plan.

With Arx, M&A advisors and investment funds benefit from a secure, sovereign SaaS CRM, designed to protect the strategic data at the heart of their operations.

They are Talking About Us

Find out why they trust Arx

Trusted by leading corporate finance institutions

Ready to transform your deal-making?

See how Arx fits your workflow in a 30-minute personalized demo.