SSO & corporate directory
Sign-in through your identity provider; accounts and roles follow your directory.
Deployment models, data boundaries, identity controls, auditability and procurement materials — in one place for security, privacy and architecture teams.
The exact control set is agreed per engagement. This public matrix describes the supported architectural profiles, not a blanket certification.
| Control point | Your cloud | Your infrastructure | On-premises | Air-gapped |
|---|---|---|---|---|
| Platform data storage | Your cloud tenancy | Servers and networks you control | Your data centre | Isolated environment |
| Inference | Approved public or local endpoint | Approved public or local endpoint | Approved public or local endpoint | Local endpoint only |
| Inbound access | By customer policy | Not required for operation | Not required for operation | None |
| Release path | Controlled deployment pipeline | Customer-controlled pull | Signed offline-capable package | Pull-only/offline package |
| Typical fit | Enterprise cloud estates | Sovereign customer environments | Regulated operations | Highly restricted environments |
Platform location does not determine where model requests are processed. Public AI services receive the content sent to them. Air-gap requires suitable local models and dependencies; the selected profile is checked before production.
Platform hosting and model inference are separate choices. If a deployment uses public AI services, those providers process the content sent in model requests. Providers, regions and permitted data flows are agreed with your team.
Inference endpoints and outbound connections are restricted by the deployment’s approved configuration. An isolated profile requires local models and dependencies; their suitability is checked against the task requirements.
Sign-in through your identity provider; accounts and roles follow your directory.
AI can never exceed the rights of the person who launched it; authorization is re-checked per request.
Access is scoped by role and area; administrative actions are separated from everyday use.
Source references, tool calls, actions and recorded decisions form an execution trace for review and audit.
Document access is logged per read, not per session.
People approve operating rules and permitted actions. Disputed cases and actions requiring separate approval return to a responsible person.
We use public AI services and can use on-premises models when their quality meets the task requirements. Provider selection, credential storage and access to model endpoints are agreed as part of the system design.
Encryption extends to the derived AI plane: abstracts, digests and claims are encrypted, not just the source data.
Public documents can be used immediately. Engagement-specific materials are issued after scope and deployment boundaries are known.
Versioned English summary of the controls and honest limits published in this Trust Center.
Download MarkdownWebsite data handling, legal bases, retention principles, recipients and data-subject rights.
Open policyPrepared for the applicable services, roles, data categories and deployment model.
Request DPACompleted against the actual solution scope rather than a generic product profile.
Start reviewDetailed boundaries, integrations, ports, identities and operational responsibilities.
Request architecture packThe applicable provider list and processing roles depend on channel and deployment choices.
Review public categoriesThis is the public baseline for the website. A named, engagement-specific schedule is provided where ARBA acts as processor.
| Surface | When used | Data involved | Primary control |
|---|---|---|---|
| Website delivery & security | Public-site access | IP address and request metadata | Limited operational retention and access |
| CRM & operational notifications | Inquiry submission | Business contact details and inquiry content | Need-to-know access and purpose limitation |
| Messaging channels | Only when that channel is selected | Channel identifiers and message content | Channel-specific terms and user choice |
See the Privacy Policy for legal bases, retention principles and international-transfer safeguards.
Send a reproducible report to info@arba-international.com with the subject “Security disclosure”. Include the affected surface, impact, steps to reproduce and a safe contact method. We aim to acknowledge a credible report within five business days.
Do not access, change or retain data that is not yours; do not disrupt services; and allow a reasonable remediation window before public disclosure. ARBA does not currently operate a public bug-bounty programme.
We will review the actual deployment boundary, controls and open questions with them.