Security & Trust
ArrowISE is built on HIPAA-eligible infrastructure with enterprise-grade security controls. Here's exactly how we protect your data.
Infrastructure
ArrowISE runs exclusively on Amazon Web Services (AWS), which maintains HIPAA eligibility and provides the infrastructure foundation for our compliance program. All data is processed and stored within the AWS us-east-1 (Northern Virginia) region. We execute a Business Associate Agreement (BAA) with AWS as required under HIPAA.
Hosting Platform
AWS — HIPAA-eligible infrastructure. Amazon Web Services provides compute, storage, and database services. ArrowISE maintains a signed BAA with AWS.
Content Delivery
Vercel — Global edge network. Static assets and the ArrowISE marketing site are served via Vercel's global CDN with automatic HTTPS and DDoS protection.
Transactional Email
Resend — GDPR-compliant email delivery. Confirmation emails and system notifications are sent via Resend with DKIM authentication on getarrowise.com.
Data Protection
Encryption
Data in Transit: All data transmitted between users and ArrowISE is encrypted using TLS 1.2 or higher. HTTPS is enforced site-wide with HSTS headers.
Data at Rest: Arrangement data, FMV opinion records, and compliance documentation stored in AWS RDS are encrypted at rest using AES-256.
Access Controls
Authentication: ArrowISE uses Clerk for enterprise-grade user authentication, supporting multi-factor authentication (MFA), SSO, and role-based access controls.
Least Privilege: Each user tier (Admin, Compliance Officer, Corporate Reviewer, Viewer) has defined permissions. No user can access data beyond their role scope.
Data Residency
All ArrowISE customer data is stored and processed within the United States. ArrowISE does not transfer arrangement data, FMV records, or compliance documentation outside of US-based AWS infrastructure.
HIPAA Compliance
ArrowISE manages physician arrangement data — including physician names, NPI numbers, and compensation information — which is not Protected Health Information (PHI) under HIPAA. ArrowISE does not process, store, or transmit patient clinical data or PHI. Our HIPAA-eligible infrastructure posture reflects our commitment to healthcare-grade security standards for our customers' sensitive business data.
Business Associate Agreement: ArrowISE provides a signed BAA to all customers at all pricing tiers at no additional cost. The BAA documents each party's responsibilities for protecting data in accordance with HIPAA standards.
Minimum Necessary: ArrowISE is designed on a minimum-necessary data principle. We collect and store only the arrangement data required to deliver compliance workflow functionality.
Certifications & Roadmap
Active
- HTTPS / TLS 1.2+
- HSTS Enforcement
- DKIM / SPF / DMARC Authentication
- BAA with AWS
- BAA with CustomersAvailable at all pricing tiers
In Progress
- SOC 2 Type IAudit engagement in progress. Target completion: Q3 2026. SOC 2 Type I certification will verify that ArrowISE's security controls are suitably designed as of a point in time.
- SOC 2 Type IIPlanned Q1 2027 following successful Type I.
On Roadmap
- HITRUST CSFHealthcare-specific information risk management framework. Planned post-Series A.
- Penetration TestingAnnual third-party penetration test. First engagement scheduled for Q4 2026.
Subprocessors
ArrowISE uses the following third-party subprocessors to deliver our service. All subprocessors are evaluated for security posture and data handling practices.
| Subprocessor | Purpose | Location | Data Handled |
|---|---|---|---|
| Amazon Web Services | Compute, storage, database | United States | Arrangement data, user accounts, compliance records |
| Vercel | CDN, serverless functions | United States | Form submissions, email captures |
| Resend | Transactional email | United States | Email addresses, notification content |
| Clerk | Authentication, user management | United States | User credentials, session tokens |
Incident Response
ArrowISE maintains an incident response plan that includes detection, containment, eradication, recovery, and post-incident analysis procedures.
In the event of a security incident affecting customer data, ArrowISE will:
- — Notify affected customers within 72 hours of confirmed breach discovery
- — Provide written incident report within 30 days
- — Cooperate fully with customer investigations
To report a security concern: security@getarrowise.com
Security Questions
For security reviews, vendor assessments, BAA requests, or penetration test reports, contact our security team directly.