Security & compliance

Provider data, protected to the standard it demands.

arro handles PHI and sensitive credentialing records. We treat that data with the controls, audits, and transparency you'd expect from healthcare infrastructure.

SOC 2 Type II
In progress
HIPAA
Compliant
NCQA
Standards-aligned
BAA
Available
Data protection

How we protect provider data.

Every record is encrypted, access is least-privilege, and every action is logged. The controls below apply to all plans.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest. Keys managed in a dedicated KMS with regular rotation.

Least-privilege access

Role-based access controls, SSO, and enforced MFA. Staff see only the records their role requires.

Full audit trail

Every verification, access, and data change is timestamped and immutable, exportable for your own audits.

US data residency

All PHI stored and processed in US-based infrastructure. No offshore data handling.

Tested & monitored

Annual third-party penetration testing, continuous vulnerability scanning, and 24/7 infrastructure monitoring.

Incident response

A documented incident response plan with defined breach notification timelines under HIPAA.

Our commitments

What you can count on.

The promises behind the controls, the things we hold ourselves to in writing.

01

We sign a BAA

A Business Associate Agreement is available to every customer handling PHI, before any data moves.

02

You own your data

Your provider data is yours. Export it any time, and we delete it on request per our retention policy.

03

No data resale

We never sell or share provider data. It's used only to deliver verification and monitoring to you.

04

Sub-processors disclosed

A current list of sub-processors is published and kept up to date, with notice before changes.

Request our security package

Need our SOC 2 report or a BAA?

We'll share our security documentation under NDA as part of your evaluation.

Talk to our team
Note: attestation statuses above reflect arro's current compliance roadmap. We'll only display a certification as complete once it has been independently issued.