Skip to content

Security evidence for enterprise review

Deployment models, data boundaries, identity controls, auditability and procurement materials — in one place for security, privacy and architecture teams.

  • Customer-controlled deployment
  • Human-gated actions
  • Explicit limits
  • Reviewed 28 July 2026

Choose the boundary before choosing the model

The exact control set is agreed per engagement. This public matrix describes the supported architectural profiles, not a blanket certification.

Control pointYour cloudYour infrastructureOn-premisesAir-gapped
Data locationYour cloud tenancyServers and networks you controlYour data centreIsolated environment
InferenceApproved endpoint in your tenancyApproved endpoint inside your perimeterLocal or approved private endpointLocal endpoint only
Inbound accessBy customer policyNot required for operationNot required for operationNone
Release pathControlled deployment pipelineCustomer-controlled pullSigned offline-capable packagePull-only/offline package
Typical fitEnterprise cloud estatesSovereign customer environmentsRegulated operationsHighly restricted environments

Capabilities and responsibilities are confirmed in the solution design and security review before production.

Egress under control

In sovereign deployments the control plane holds no customer data; the only egress is a data-free licence heartbeat.

A runtime egress latch refuses to boot unless inference is pinned to an approved endpoint, and hard-blocks any call outside the perimeter.

The AI never outruns the person

SSO & corporate directory

Sign-in through your identity provider; accounts and roles follow your directory.

On-behalf-of execution

AI can never exceed the rights of the person who launched it; authorization is re-checked per request.

Role-based permissions

Access is scoped by role and area; administrative actions are separated from everyday use.

Every step accountable

Append-only trace

Every reasoning step and action lands in an append-only, replayable trace.

Per-read access logging

Document access is logged per read, not per session.

Human-gated write-back

Changes to systems of record require explicit human confirmation.

Your models, your keys

Bring your own model: OpenAI-family and Anthropic Claude lanes proven inside a customer's own cloud — keys never leave your perimeter.

Encryption extends to the derived AI plane: abstracts, digests and claims are encrypted, not just the source data.

What we do not claim

  • We do not currently claim ISO or SOC certification; our security posture is demonstrated architecturally and per engagement
  • Specific capabilities depend on the deployment mode — cloud, on-prem and air-gap profiles differ
  • A security review with your team is part of every engagement before production

Materials for vendor, security and privacy review

Public documents can be used immediately. Engagement-specific materials are issued after scope and deployment boundaries are known.

Security overview

Public

Versioned English summary of the controls and honest limits published in this Trust Center.

Download Markdown

Privacy policy

Public

Website data handling, legal bases, retention principles, recipients and data-subject rights.

Open policy

Data Processing Agreement

On request

Prepared for the applicable services, roles, data categories and deployment model.

Request DPA

Security questionnaire

On request

Completed against the actual solution scope rather than a generic product profile.

Start review

Architecture & data-flow pack

Under NDA

Detailed boundaries, integrations, ports, identities and operational responsibilities.

Request architecture pack

Processor schedule

Engagement-specific

The applicable provider list and processing roles depend on channel and deployment choices.

Review public categories

Public categories of providers and processing

This is the public baseline for the website and demo surfaces. A named, engagement-specific schedule is provided where ARBA acts as processor.

SurfaceWhen usedData involvedPrimary control
Website delivery & securityPublic-site accessIP address and request metadataLimited operational retention and access
CRM & operational notificationsInquiry submissionBusiness contact details and inquiry contentNeed-to-know access and purpose limitation
Messaging channelsOnly when that channel is selectedChannel identifiers and message contentChannel-specific terms and user choice
Aptus demo infrastructureAptus demo onlyDemo interaction and functional continuity tokenFunctional purpose and documented retention

See the Privacy Policy for legal bases, retention principles and international-transfer safeguards.

Report a potential security issue

Send a reproducible report to [email protected] with the subject “Security disclosure”. Include the affected surface, impact, steps to reproduce and a safe contact method. We aim to acknowledge a credible report within five business days.

Do not access, change or retain data that is not yours; do not disrupt services; and allow a reasonable remediation window before public disclosure. ARBA does not currently operate a public bug-bounty programme.

  • test only against accounts, tenants and data you are authorized to use
  • use the minimum proof needed to demonstrate the issue
  • coordinate disclosure timing while remediation is in progress

Trust Center FAQ

No. ARBA does not currently claim ISO or SOC certification. Controls are demonstrated architecturally and assessed for the specific engagement.
Yes, supported profiles include customer cloud, customer-controlled infrastructure, on-premises and air-gapped deployment. Exact capabilities depend on the selected profile.
Yes. Security review, data-flow agreement and responsibility boundaries are part of the path to production.

Bring your security, privacy and architecture teams

We will review the actual deployment boundary, controls and open questions with them.