Security

Last updated Next review by April 2027 arbostar.com/security

This page explains how ArboStar protects your company's data. It covers the ArboStar platform (the web app and the mobile app your team uses every day) and the ArboStar Hub (our billing and contract portal). It says what we do, what we do not do, and what we can show you on request.

For security questionnaires and due-diligence requests, write to info@arbostar.com or jump to Contact and documents.

At a glance

Security facts at a glance, each linked to its section
HostingAmazon Web Services, US West (Oregon) region, United States.
Encryption in transitTLS 1.2 or TLS 1.3; older versions are not accepted.
Encryption at restAWS encryption on databases, uploaded files and backups.
BackupsPlatform: daily, kept 30 days. Hub: daily, kept 7 days.
Sign-inMulti-factor authentication available per user (email or SMS code); company-wide enforcement is on the roadmap.
Breach noticeAccount owner emailed within 72 hours of confirming an incident that affects your data.
Independent testing2025 external risk assessment against the CIS Controls v8.1 done; penetration test not yet performed.
CertificationsArboStar holds no SOC 2, ISO 27001 or PCI DSS attestation of its own; AWS holds them for the infrastructure layer.
Security contactsecurity@arbostar.com

Where your data is kept

The ArboStar platform is hosted on Amazon Web Services (AWS), primarily in the AWS US West (Oregon) region in the United States. Customers in Canada, the United Kingdom and Australia are served from the same region.

The ArboStar Hub, our billing and contract portal, runs on AWS in the United States.

Customers share the same platform infrastructure. Each customer's data is tied to its own company account, and the application limits every user to the data of the account they belong to. Dedicated hosting is not part of the standard service.

Physical security of the servers is AWS's responsibility under AWS's own certifications. Those certifications cover the infrastructure, not ArboStar; see Certifications and independent testing for what ArboStar itself holds.

Certifications and independent testing

What we hold

  • 2025 independent cybersecurity risk assessment by an external vCISO holding CISSP and ISO 27001 Lead Auditor credentials. It was not a penetration test, a vulnerability scan, a SOC 2 report or an ISO 27001 certification. On request, and under a mutual NDA, we share an executive summary of its findings with customers and prospects.

What we do not hold

  • Penetration test: not yet performed. Our standard is an independent penetration test of the platform at least once a year, with critical findings fixed within 14 days and high-severity findings within 30 days. We do not yet have a dated report, so we do not claim one. The date of the latest test will appear here once the first report exists, and its summary will be available on request under NDA.
  • SOC 2, ISO 27001, PCI DSS: ArboStar does not currently hold a SOC 2 report, an ISO 27001 certification or a PCI DSS attestation of its own. We will update this page if that changes. AWS holds those certifications for the infrastructure layer; they do not transfer to ArboStar.

About the 2025 assessment

The assessment measured our controls against the CIS Critical Security Controls v8.1. It covered all 18 control groups and focused on the safeguards CIS sets for Implementation Groups 1 and 2: essential cyber hygiene and enhanced protection. It also covered cyber risk management, disaster recovery and incident response, and it estimated risk with the FAIR method.

The assessor reviewed our documentation and interviewed people from our infrastructure and site reliability engineering, HR and senior leadership teams. The results were compared with the information-sector findings of the 2024 Verizon Data Breach Investigations Report.

The assessment recorded these controls in place:

  • Continuous monitoring of system health and network activity, with automated alerts sent to engineers in real time.
  • Automated vulnerability scanning.
  • Application logging and telemetry that track how our applications behave.
  • Centrally managed access, with least privilege enforced consistently.
  • Tracking of our infrastructure and cloud service assets.
  • Encryption on all critical systems.
  • A documented incident response plan.
  • Security responsibilities clearly assigned within the infrastructure and engineering teams.
  • Defined onboarding and access-provisioning workflows, with training, so staff are given appropriate access from their first day to their last.
  • Background checks for staff with access to production environments.

Encryption

Connections to the platform are encrypted in transit with TLS 1.2 or TLS 1.3, and our web servers do not accept older versions. The mobile app uses the same encrypted connections.

Production data on our servers is encrypted at rest using AWS encryption: the databases, uploaded photos and files, and backups.

Signed contract documents held in the Hub are stored in private, versioned storage, encrypted with AES-256. Credentials the Hub uses to talk to other services are stored encrypted with AES-256-GCM.

Backups and recovery

  • Platform: databases are backed up automatically every day, and each backup is kept for 30 days.
  • Hub: database backups are taken every day and kept for 7 days.

Backups are stored in AWS in the United States, in the same region as the live system, and are encrypted.

After a major failure we aim to have the platform running again within 8 hours and to lose no more than 24 hours of data. We test restoring from backup at least twice a year and record the date and result of each test.

Access control

Inside your company

Platform users are either support (office) users or field users, and any user can be given admin rights. Admins set what each user can see and do, user by user, in the Permissions section of the user profile:

  • Permissions cover clients and projects, scheduling, the mobile app, HR and payroll, and reports.
  • For clients, projects and equipment, an admin can give a user full access, access to their own records only, or no access.
  • Admins can hide client contact details from field staff and limit the mobile app to the current day's jobs.

When someone leaves, their user is set to inactive or dismissed rather than deleted, so the record of what they did stays intact.

Admins can see each user's login history (date, time and IP address) under Business Intelligence, Personnel, Users Login Activity.

ArboStar staff

ArboStar staff access customer data only to provide support and to keep the service running, and each such access is logged. Staff access is managed centrally and limited to the roles that need it, and background checks are done for staff with access to production environments.

Passwords and sessions

  • Platform: passwords are stored hashed, never in plain text. An account is locked for 15 minutes after 10 failed sign-in attempts, and web sessions end after 24 hours of inactivity.
  • Hub: passwords are stored hashed with Argon2id, sessions expire after 1 hour, and sign-in is rate-limited per account and per IP address.

Multi-factor authentication

Multi-factor authentication (MFA) can be switched on in the user profile, by the user or by an admin. When it is on, a six-digit code is sent by email or SMS at sign-in from a device that is not trusted. Codes expire after 5 minutes. A user can mark a device as trusted for 30 days; the trust is withdrawn when the password changes, when the user signs out of all sessions, or when an admin turns MFA off and on again.

On the mobile app, Face ID, Touch ID or fingerprint sign-in can replace the password and code on that device.

Today MFA is turned on per user. Company-wide enforcement, so that an admin can require it for every user, is on our roadmap.

Your clients' portal

Your own clients sign in to their customer portal without a password. They receive a one-time code or a sign-in link by email, or a six-digit one-time code by SMS. A direct portal link sent from a client's profile works once and expires after 15 minutes.

API keys

API access uses a company API key that an admin creates under Company Management, API Access Management, and sends with each request over HTTPS. The API limits the number of requests per minute. An admin can regenerate or switch off the key at any time.

Activity log

The platform records each login with the user's name, date, time and IP address, and admins can review and filter these by user. The platform also keeps a history of changes to records such as clients, estimates and invoices, so managers can see who changed what and when. Log entries cannot be edited or deleted by users and are kept for at least 12 months. Admins can ask us for an export of the log.

In the Hub, the audit log is append-only: entries cannot be edited or deleted, and they are kept indefinitely, as set out in our Privacy Policy.

Application security

  • Hub: every build runs an automated check of its software dependencies for known vulnerabilities. The Hub sends HTTP security headers (HSTS, a content security policy, and frame and referrer restrictions), uses secure, same-site session cookies, and checks the signature on every payment notification it receives from Authorize.net before acting on it.
  • arbostar.com: sends HSTS and frame, content-type and referrer restrictions.
  • Platform: sends the same security headers, uses secure, same-site session cookies, and has its dependencies checked for known vulnerabilities in every build.

Incident response

We monitor the platform continuously with automated health checks and alerting, and an on-call engineer responds to alerts. Outside support hours, response is on a best-effort basis.

We have a documented incident response plan, and a named engineering lead owns each incident. If we confirm an incident that affects your data, we email your account owner without undue delay, and within 72 hours of confirming it. Some customer contracts set shorter periods, and those apply instead. We review the plan after every incident and run a tabletop exercise of it at least once a year.

If we become aware of a personal data breach likely to affect you, we will notify you and any required regulator without undue delay, as the law requires.

Privacy and data ownership

For data about your own clients, you are the controller and ArboStar is the processor. We process it only on your instructions, under our Data Processing Agreement, available on request from info@arbostar.com. We do not sell personal data.

We comply with Canada's federal privacy law (PIPEDA), Canada's Anti-Spam Legislation (CASL) and Quebec's Law 25. For transfers from the EEA and the UK we rely on Canada's adequacy status, on the EU-US Data Privacy Framework where a US provider is certified, and on Standard Contractual Clauses otherwise. Details are in our Privacy Policy.

Your data belongs to you. You can export lists such as users, clients, estimates and invoices from the platform as CSV files at any time. You can also ask us for a full export of your data, including attachments, and we deliver it within 30 days of your request.

When you close your account, you can ask for an export for 30 days; after that, your data is deleted and backup copies overwritten on the timeline in our Privacy Policy, which also covers the e-signature and saved-card steps. The same timeline applies to the data you hold about your own clients in the platform.

Payments

Your subscription payments to ArboStar run through Authorize.net's hosted payment fields, and card payments you take from your own clients inside the platform are entered in the payment processor's hosted fields. In both cases ArboStar never receives or stores full card numbers: we keep a token or the processor's reference, and the last four digits. For companies using Authorize.net, the platform lets you configure Authorize.net's fraud-detection filters.

Subprocessors

As of , these are the companies that hold or transmit customer data for ArboStar. The same list, as a document, is available on request from info@arbostar.com.

Companies that process customer data for ArboStar
Company Purpose Country
Amazon Web ServicesHosting, storage and backups for the platform and the HubUnited States
Amazon Simple Email ServiceInvoices, receipts and reminders sent by the HubUnited States
Authorize.netCard payments for ArboStar subscriptions, and card payments you take inside the platformUnited States
TwilioText messages sent from the platformUnited States
BrevoEmail sent from the platformFrance
SentryError monitoringUnited States

Marketing and analytics tools used on arbostar.com are listed in our Privacy Policy. We give customers at least 30 days' notice by email before a new company starts processing their data.

How to report a security problem

  • Email security@arbostar.com. We acknowledge every report within 3 business days.
  • If you find a security problem and report it to us in good faith, we will not take legal action against you for that research, as long as you do not access, change or keep other people's data, do not disrupt the service, and give us reasonable time to fix the problem before making it public. This covers ArboStar's own systems only.
  • We do not run a paid bug bounty program.

Contact and documents

We aim to answer a standard security questionnaire within 10 business days; we confirm receipt and tell you when to expect the reply.

Who to write to
Security questionnaires and due diligenceinfo@arbostar.com
Vulnerability reportssecurity@arbostar.com
General supportsupport@arbostar.com

Available on request

  • Our Data Processing Agreement.
  • Our subprocessor list.
  • An executive summary of the 2025 risk assessment, under NDA.
  • A certificate of insurance.
  • Service terms: availability target, support hours, response times and incident notice.
  • Privacy Policy: what personal data we collect, retention and deletion timelines, and the marketing tools used on arbostar.com.
  • Terms and Conditions: the agreement that governs your use of the platform.
  • Cookie Policy: cookies used on arbostar.com.

What changed

  • : added the scope, method and recorded controls of the 2025 risk assessment.
  • : first version.

We review this page at least every 6 months, and whenever something it describes changes.