We use cookies for analytics, advertising, our chat widget and embedded videos. You can accept all cookies or reject non-essential ones. See our Cookie Policy.
Security
Last updated Next review by April 2027arbostar.com/security
This page explains how ArboStar protects your company's data. It covers the ArboStar platform (the web app and the mobile app your team uses every day) and the ArboStar Hub (our billing and contract portal). It says what we do, what we do not do, and what we can show you on request.
The ArboStar platform is hosted on Amazon Web Services (AWS), primarily in the AWS US West (Oregon) region in the United States. Customers in Canada, the United Kingdom and Australia are served from the same region.
The ArboStar Hub, our billing and contract portal, runs on AWS in the United States.
Customers share the same platform infrastructure. Each customer's data is tied to its own company account, and the application limits every user to the data of the account they belong to. Dedicated hosting is not part of the standard service.
Physical security of the servers is AWS's responsibility under AWS's own certifications. Those certifications cover the infrastructure, not ArboStar; see Certifications and independent testing for what ArboStar itself holds.
Certifications and independent testing
What we hold
2025 independent cybersecurity risk assessment by an external vCISO holding CISSP and ISO 27001 Lead Auditor credentials. It was not a penetration test, a vulnerability scan, a SOC 2 report or an ISO 27001 certification. On request, and under a mutual NDA, we share an executive summary of its findings with customers and prospects.
What we do not hold
Penetration test: not yet performed. Our standard is an independent penetration test of the platform at least once a year, with critical findings fixed within 14 days and high-severity findings within 30 days. We do not yet have a dated report, so we do not claim one. The date of the latest test will appear here once the first report exists, and its summary will be available on request under NDA.
SOC 2, ISO 27001, PCI DSS: ArboStar does not currently hold a SOC 2 report, an ISO 27001 certification or a PCI DSS attestation of its own. We will update this page if that changes. AWS holds those certifications for the infrastructure layer; they do not transfer to ArboStar.
About the 2025 assessment
The assessment measured our controls against the CIS Critical Security Controls v8.1. It covered all 18 control groups and focused on the safeguards CIS sets for Implementation Groups 1 and 2: essential cyber hygiene and enhanced protection. It also covered cyber risk management, disaster recovery and incident response, and it estimated risk with the FAIR method.
The assessor reviewed our documentation and interviewed people from our infrastructure and site reliability engineering, HR and senior leadership teams. The results were compared with the information-sector findings of the 2024 Verizon Data Breach Investigations Report.
The assessment recorded these controls in place:
Continuous monitoring of system health and network activity, with automated alerts sent to engineers in real time.
Automated vulnerability scanning.
Application logging and telemetry that track how our applications behave.
Centrally managed access, with least privilege enforced consistently.
Tracking of our infrastructure and cloud service assets.
Encryption on all critical systems.
A documented incident response plan.
Security responsibilities clearly assigned within the infrastructure and engineering teams.
Defined onboarding and access-provisioning workflows, with training, so staff are given appropriate access from their first day to their last.
Background checks for staff with access to production environments.
Encryption
Connections to the platform are encrypted in transit with TLS 1.2 or TLS 1.3, and our web servers do not accept older versions. The mobile app uses the same encrypted connections.
Production data on our servers is encrypted at rest using AWS encryption: the databases, uploaded photos and files, and backups.
Signed contract documents held in the Hub are stored in private, versioned storage, encrypted with AES-256. Credentials the Hub uses to talk to other services are stored encrypted with AES-256-GCM.
Backups and recovery
Platform: databases are backed up automatically every day, and each backup is kept for 30 days.
Hub: database backups are taken every day and kept for 7 days.
Backups are stored in AWS in the United States, in the same region as the live system, and are encrypted.
After a major failure we aim to have the platform running again within 8 hours and to lose no more than 24 hours of data. We test restoring from backup at least twice a year and record the date and result of each test.
Access control
Inside your company
Platform users are either support (office) users or field users, and any user can be given admin rights. Admins set what each user can see and do, user by user, in the Permissions section of the user profile:
Permissions cover clients and projects, scheduling, the mobile app, HR and payroll, and reports.
For clients, projects and equipment, an admin can give a user full access, access to their own records only, or no access.
Admins can hide client contact details from field staff and limit the mobile app to the current day's jobs.
When someone leaves, their user is set to inactive or dismissed rather than deleted, so the record of what they did stays intact.
Admins can see each user's login history (date, time and IP address) under Business Intelligence, Personnel, Users Login Activity.
ArboStar staff
ArboStar staff access customer data only to provide support and to keep the service running, and each such access is logged. Staff access is managed centrally and limited to the roles that need it, and background checks are done for staff with access to production environments.
Passwords and sessions
Platform: passwords are stored hashed, never in plain text. An account is locked for 15 minutes after 10 failed sign-in attempts, and web sessions end after 24 hours of inactivity.
Hub: passwords are stored hashed with Argon2id, sessions expire after 1 hour, and sign-in is rate-limited per account and per IP address.
Multi-factor authentication
Multi-factor authentication (MFA) can be switched on in the user profile, by the user or by an admin. When it is on, a six-digit code is sent by email or SMS at sign-in from a device that is not trusted. Codes expire after 5 minutes. A user can mark a device as trusted for 30 days; the trust is withdrawn when the password changes, when the user signs out of all sessions, or when an admin turns MFA off and on again.
On the mobile app, Face ID, Touch ID or fingerprint sign-in can replace the password and code on that device.
Today MFA is turned on per user. Company-wide enforcement, so that an admin can require it for every user, is on our roadmap.
Your clients' portal
Your own clients sign in to their customer portal without a password. They receive a one-time code or a sign-in link by email, or a six-digit one-time code by SMS. A direct portal link sent from a client's profile works once and expires after 15 minutes.
API keys
API access uses a company API key that an admin creates under Company Management, API Access Management, and sends with each request over HTTPS. The API limits the number of requests per minute. An admin can regenerate or switch off the key at any time.
Activity log
The platform records each login with the user's name, date, time and IP address, and admins can review and filter these by user. The platform also keeps a history of changes to records such as clients, estimates and invoices, so managers can see who changed what and when. Log entries cannot be edited or deleted by users and are kept for at least 12 months. Admins can ask us for an export of the log.
In the Hub, the audit log is append-only: entries cannot be edited or deleted, and they are kept indefinitely, as set out in our Privacy Policy.
Application security
Hub: every build runs an automated check of its software dependencies for known vulnerabilities. The Hub sends HTTP security headers (HSTS, a content security policy, and frame and referrer restrictions), uses secure, same-site session cookies, and checks the signature on every payment notification it receives from Authorize.net before acting on it.
arbostar.com: sends HSTS and frame, content-type and referrer restrictions.
Platform: sends the same security headers, uses secure, same-site session cookies, and has its dependencies checked for known vulnerabilities in every build.
Incident response
We monitor the platform continuously with automated health checks and alerting, and an on-call engineer responds to alerts. Outside support hours, response is on a best-effort basis.
We have a documented incident response plan, and a named engineering lead owns each incident. If we confirm an incident that affects your data, we email your account owner without undue delay, and within 72 hours of confirming it. Some customer contracts set shorter periods, and those apply instead. We review the plan after every incident and run a tabletop exercise of it at least once a year.
If we become aware of a personal data breach likely to affect you, we will notify you and any required regulator without undue delay, as the law requires.
Privacy and data ownership
For data about your own clients, you are the controller and ArboStar is the processor. We process it only on your instructions, under our Data Processing Agreement, available on request from info@arbostar.com. We do not sell personal data.
We comply with Canada's federal privacy law (PIPEDA), Canada's Anti-Spam Legislation (CASL) and Quebec's Law 25. For transfers from the EEA and the UK we rely on Canada's adequacy status, on the EU-US Data Privacy Framework where a US provider is certified, and on Standard Contractual Clauses otherwise. Details are in our Privacy Policy.
Your data belongs to you. You can export lists such as users, clients, estimates and invoices from the platform as CSV files at any time. You can also ask us for a full export of your data, including attachments, and we deliver it within 30 days of your request.
When you close your account, you can ask for an export for 30 days; after that, your data is deleted and backup copies overwritten on the timeline in our Privacy Policy, which also covers the e-signature and saved-card steps. The same timeline applies to the data you hold about your own clients in the platform.
Payments
Your subscription payments to ArboStar run through Authorize.net's hosted payment fields, and card payments you take from your own clients inside the platform are entered in the payment processor's hosted fields. In both cases ArboStar never receives or stores full card numbers: we keep a token or the processor's reference, and the last four digits. For companies using Authorize.net, the platform lets you configure Authorize.net's fraud-detection filters.
Subprocessors
As of , these are the companies that hold or transmit customer data for ArboStar. The same list, as a document, is available on request from info@arbostar.com.
Companies that process customer data for ArboStar
Company
Purpose
Country
Amazon Web Services
Hosting, storage and backups for the platform and the Hub
United States
Amazon Simple Email Service
Invoices, receipts and reminders sent by the Hub
United States
Authorize.net
Card payments for ArboStar subscriptions, and card payments you take inside the platform
United States
Twilio
Text messages sent from the platform
United States
Brevo
Email sent from the platform
France
Sentry
Error monitoring
United States
Marketing and analytics tools used on arbostar.com are listed in our Privacy Policy. We give customers at least 30 days' notice by email before a new company starts processing their data.
If you find a security problem and report it to us in good faith, we will not take legal action against you for that research, as long as you do not access, change or keep other people's data, do not disrupt the service, and give us reasonable time to fix the problem before making it public. This covers ArboStar's own systems only.
We do not run a paid bug bounty program.
Contact and documents
We aim to answer a standard security questionnaire within 10 business days; we confirm receipt and tell you when to expect the reply.