Customer trust and security are critical to everything we do at Arrows. Learn how we adhere to industry-leading standards in data protection and security compliance.
Visit our Trust CenterArrows is SOC 2 Type II and GDPR compliant, with third-party audits confirming our security practices annually. Our SOC 2 report is available in our Trust Center and has zero exceptions, demonstrating our commitment to security and data protection.
Arrows is hosted on Heroku which utilizes Amazon Web Services (AWS) data centers for hosting.
AWS provides an extensive list of compliance and regulatory assurances. See the AWS compliance and security documents for more detailed information.
Over 100 security controls are continuously monitored across the organization.
Automated alerts and evidence collection mean Arrows can confidently demonstrate its security and compliance stance any day of the year.
Customer data is encrypted at rest with AES-256 block-level storage encryption, and in transit with SSL. Battle-tested infrastructure from Heroku and AWS keeps your data secure.
Arrows works with industry leading third-party security firms to perform annual network and application layer penetration tests.
Arrows is defended from threats by a Web Application Firewall (WAF) to prevent unauthorized access and stop threats before they start.
All Arrows employees complete an annual security training program and employ best practices when handling customer data.
RBAC
Leverage role-based access to control who on your team has access to specific features.
SSO (enterprise only)
Manage user authentication with SAML single sign on and keep access grants up-to-date with SCIM.
Audit logs (enterprise only)
Track, monitor, and search in-app user activity. Export reports and alerts to your preferred tools.
Can’t find the answer you're looking for? Email us any time: help@arrows.to.