Introducing the CData Arc Q3 2026 Release: Encryption at Rest, AI Diagnostics, Version Control, and Database Migration

by Zak Reynolds | July 28, 2026

CData Arc Q3 2026 ReleaseThe CData Arc Q3 2026 release is built for teams running integration in environments where security is non-negotiable; configuration changes carry real operational risk, and diagnosing problems quickly matters.

This release introduces application-level encryption at rest for all message data, a built in MCP server that connects AI clients directly to a live Arc instance, significant version control enhancements including local repository support, a guided database migration utility, and a broad set of improvements to scripting, connectivity, file transfer, and platform administration.

Encryption at rest for all message data

For organizations operating under PCI DSS, HIPAA, GDPR, or SOX requirements, protecting data at rest is a compliance baseline. Arc has long protected sensitive configuration values, but message data moving through internal storage directories was left in plaintext on disk.

Arc can now encrypt all message data at rest using AES-256-GCM. Encryption and decryption happen transparently; no changes to existing workflows are required, and files are still delivered to downstream systems and trading partners in plaintext as expected. Four configurable modes let teams manage the transition at their own pace, from a compatibility mode that writes plaintext while accepting either format, to a strict mode for environments that must reject plaintext files entirely. The feature uses Arc's existing master key mechanism, so no separate key setup is required to get started.

AI diagnostics through a built-in MCP server

When something goes wrong in a complex multi-connector flow, diagnosing it means navigating the Transaction tab, pulling application logs, and cross-referencing connector settings often across multiple screens. It works, but it's slow.

Arc now ships with a built in MCP (Model Context Protocol) server that lets AI clients Claude Desktop, GitHub Copilot CLI, OpenAI Codex, or any MCP compatible tool connect directly to a running Arc instance and interact with it in natural language. Teams can ask questions like "What certificates are expiring in the next 30 days?", "Trace this message across its flow," or "Show me all AS2 errors from the last 24 hours" and get answers without touching the Arc UI. The server exposes 14 read-only diagnostic tools covering workspaces, connectors, messages, files, logs, certificates, vault entries, and system health. It is enabled by default and respects all existing access controls.

Version control enhancements: local repos and readable diffs

Git-based configuration management came to Arc in v26. The Q3 release removes the one prerequisite that makes it harder to adopt: a remote Git server. Teams can now enable a Local repository option that creates a standalone Git repo directly on the Arc server, with full commit history, branching, and VCS activity available from day one. Teams that want to connect to a remote server later can do so without losing their history.

For teams already using version control, configuration diffs on connector settings, shared connections, and workspace settings now display in a structured, form-based layout changes grouped by section with old and new values side by side instead of raw unified-diff text. This improved view appears everywhere settings changes are reviewed: committing, discarding, restoring, or browsing commit history.

Database migration, built in

Teams that outgrow Arc's embedded database have historically faced a hard choice: migrate manually with third-party tooling, or start fresh and lose transaction history, connector state, and audit logs.

Arc now includes a guided database migration utility under Settings > Advanced that moves all application data from the embedded database to SQL Server, MySQL, or PostgreSQL without external tools and without data loss. Before migration begins, Arc enters Safe Mode, pausing all connectors, background services, and inbound endpoints to ensure a clean, consistent transfer. Progress is written to the UI as the migration proceeds table by table. Crash recovery is built in: if Arc terminates unexpectedly mid-migration, the state is persisted and the migration can be resumed from where it left off.

New connectors, scripting, and connectivity

This release adds two new connectors that eliminate common workarounds. The Python connector runs Python natively within a flow using the same interface as the existing Script connector. The AES connector handles encryption and decryption of message content directly in Arc, supporting GCM, CBC, and five other cipher modes, replacing the previous approach of utilizing ArcScript.

ArcScript also gains a new _state item providing persistent key/value storage scoped to the connector instance, useful for duplicate file detection, lookup tables, and stateful processing across executions.

On connectivity, database and application connectors now include a visual JOIN designer that combines data from multiple related tables in a single query without writing SQL, a meaningful improvement for rate limited APIs like Salesforce where n+1 query patterns are expensive. The CData API Profile catalog is now accessible directly in Arc's Connections interface, and NetSuite custom schemas can be created and managed from the connection settings UI rather than through manual file management on disk.

AI-assisted mapping in XML Map now handles more complex field relationships, generating ArcScript transformations for non-1:1 mapping that were previously skipped. RBAC is extended to both Connections and Flow APIs, with a new service account type that supports token and OAuth-only authentication for automated systems

Platform and file transfer improvements

Log Pattern Analysis groups for similar application log entries on the Activity page, so teams can spot repeated issues faster in high-volume environments. Connector-level service status indicators now appear directly on server-type connector pages SFTP Server, FTP Server, TCP Server, AMQP, MQTT, IDoc, OFTP, and HL7 MLLP without navigating to the Profiles page. The Admin API gains a moveConnector action that relocates a connector between workspaces while preserving all configuration and transaction history, and two new resources exposing workspace flow topology as JSON for programmatic access. ED25519 and X25519 certificate creation is now supported natively in Arc, required for eDelivery v2 AS4 profiles, and the AS4 Profile page gains a dedicated Personal Certificate section with separate signing and decryption certificate fields for eDelivery V2 and ENTSOG V4 trading partners.

On file transfer: SFTP and FTP connectors now support date macros in remote paths for date-based folder structures. The Email Receive connector can move processed messages to a configurable archive folder. A new Finalize on Disconnect setting on SFTP Server delays message finalization until the client fully disconnects, preventing errors for clients that issue follow-up commands after uploading. A configurable Home Directory on SFTP Server, and FTP Server controls the landing folder at login, useful for automated systems that cannot issue cd commands. The Sent Folder setting is deprecated in favor of the Success Path via File connector, which is covered by encryption at rest. The Connector Backoff UI now surfaces a clear status indicator when a connector has entered backoff mode, so teams understand why unsent files are accumulating and what will clear it.

Getting started with the Q3 2026 release

On-premises customers can download the latest version from our builds page. Arc Cloud customers should contact support to schedule their upgrade.

For full details on everything in this release, visit our documentation or reach out to our support team.

B2B integration built for the real world.

From AS2 to X12 to custom APIs, CData Arc handles the full spectrum of B2B data exchange — so you can onboard partners faster and keep every transaction running smoothly.

Take the tour