Skip to content

Security evidence for enterprise review

Deployment models, data boundaries, identity controls, auditability and procurement materials — in one place for security, privacy and architecture teams.

  • Customer-controlled deployment
  • Human-approved rules
  • Explicit limits
  • Project-specific review

Choose the boundary before choosing the model

The exact control set is agreed per engagement. This public matrix describes the supported architectural profiles, not a blanket certification.

Control pointYour cloudYour infrastructureOn-premisesAir-gapped
Platform data storageYour cloud tenancyServers and networks you controlYour data centreIsolated environment
InferenceApproved public or local endpointApproved public or local endpointApproved public or local endpointLocal endpoint only
Inbound accessBy customer policyNot required for operationNot required for operationNone
Release pathControlled deployment pipelineCustomer-controlled pullSigned offline-capable packagePull-only/offline package
Typical fitEnterprise cloud estatesSovereign customer environmentsRegulated operationsHighly restricted environments

Platform location does not determine where model requests are processed. Public AI services receive the content sent to them. Air-gap requires suitable local models and dependencies; the selected profile is checked before production.

Egress under control

Platform hosting and model inference are separate choices. If a deployment uses public AI services, those providers process the content sent in model requests. Providers, regions and permitted data flows are agreed with your team.

Inference endpoints and outbound connections are restricted by the deployment’s approved configuration. An isolated profile requires local models and dependencies; their suitability is checked against the task requirements.

The AI never outruns the person

SSO & corporate directory

Sign-in through your identity provider; accounts and roles follow your directory.

On-behalf-of execution

AI can never exceed the rights of the person who launched it; authorization is re-checked per request.

Role-based permissions

Access is scoped by role and area; administrative actions are separated from everyday use.

Every step accountable

Append-only trace

Source references, tool calls, actions and recorded decisions form an execution trace for review and audit.

Per-read access logging

Document access is logged per read, not per session.

Human-approved rules and decisions

People approve operating rules and permitted actions. Disputed cases and actions requiring separate approval return to a responsible person.

Model providers and access

We use public AI services and can use on-premises models when their quality meets the task requirements. Provider selection, credential storage and access to model endpoints are agreed as part of the system design.

Encryption extends to the derived AI plane: abstracts, digests and claims are encrypted, not just the source data.

What we do not claim

  • We do not currently claim ISO or SOC certification; our security posture is demonstrated architecturally and per engagement
  • Specific capabilities depend on the deployment mode — cloud, on-prem and air-gap profiles differ
  • A security review with your team is part of every engagement before production

Materials for vendor, security and privacy review

Public documents can be used immediately. Engagement-specific materials are issued after scope and deployment boundaries are known.

Security overview

Public

Versioned English summary of the controls and honest limits published in this Trust Center.

Download Markdown

Privacy policy

Public

Website data handling, legal bases, retention principles, recipients and data-subject rights.

Open policy

Data Processing Agreement

On request

Prepared for the applicable services, roles, data categories and deployment model.

Request DPA

Security questionnaire

On request

Completed against the actual solution scope rather than a generic product profile.

Start review

Architecture & data-flow pack

Under NDA

Detailed boundaries, integrations, ports, identities and operational responsibilities.

Request architecture pack

Processor schedule

Engagement-specific

The applicable provider list and processing roles depend on channel and deployment choices.

Review public categories

Public categories of providers and processing

This is the public baseline for the website. A named, engagement-specific schedule is provided where ARBA acts as processor.

SurfaceWhen usedData involvedPrimary control
Website delivery & securityPublic-site accessIP address and request metadataLimited operational retention and access
CRM & operational notificationsInquiry submissionBusiness contact details and inquiry contentNeed-to-know access and purpose limitation
Messaging channelsOnly when that channel is selectedChannel identifiers and message contentChannel-specific terms and user choice

See the Privacy Policy for legal bases, retention principles and international-transfer safeguards.

Report a potential security issue

Send a reproducible report to info@arba-international.com with the subject “Security disclosure”. Include the affected surface, impact, steps to reproduce and a safe contact method. We aim to acknowledge a credible report within five business days.

Do not access, change or retain data that is not yours; do not disrupt services; and allow a reasonable remediation window before public disclosure. ARBA does not currently operate a public bug-bounty programme.

  • test only against accounts, tenants and data you are authorized to use
  • use the minimum proof needed to demonstrate the issue
  • coordinate disclosure timing while remediation is in progress

Trust Center FAQ

No. ARBA does not currently claim ISO or SOC certification. Controls are demonstrated architecturally and assessed for the specific engagement.
An isolated configuration requires suitable local models and dependencies. With public AI services, request content is processed by the approved provider. We agree data flows and check the chosen configuration before production.
Yes. Security review, data-flow agreement and responsibility boundaries are part of the path to production.

Bring your security, privacy and architecture teams

We will review the actual deployment boundary, controls and open questions with them.