Security and Privacy
You are trusting us with records
that outlive portals.
This page is written for your IT, security, legal and procurement teams. It describes Arrota’s current controls and identifies the claims we do not yet make.
What is in our care
What Arrota protects.
Record content
The information an issuer places in a credential, kept for the holder and available through the appropriate link.
Personal data
Names, identifiers, and contact details are minimised and are not sold or used for profiling.
Access history
The dated, attributed history of each record change.
Access control
Access is reviewed. Visibility is scoped.
- 01Issuer access is reviewed. Organisations do not receive issuer access through self-serve signup.
- 02Team access is attributable. Organisation activity is associated with the account that performed it and appears in record history.
- 03Holders control their exposure. Vaults are private by default; public profiles and private shares are explicit, scoped, revocable decisions.
- 04Public pages expose public records. Nothing else. Verification requires no account precisely so it grants no powers.
Northstar University · access
- OrganisationIdentity reviewed
- Team activityAttributed
- Record changesShown in History
Product preview only. Specific permission controls are confirmed during implementation.
Data protection and integrity
The record is the unit of protection.
Arrota’s strongest protection is structural: a record cannot be silently rewritten. Corrections, supersessions and revocations are the only ways content changes. Each action is attributed, dated, and visible in history.
Signed when issued
A cryptographic signature is recorded at issuance, so later tampering with the record’s origin leaves evidence.
Encrypted in transit
Traffic to and from Arrota is served over TLS. Records move between issuer, holder and verifier over the same channel.
Least exposure by design
Public pages show public records. Private shares show selections. Vaults show their owner. Boundaries are the default, not a setting to find.
Logging, incidents and disclosure
When something happens, there is a trail and a route.
Audit trail
Every lifecycle action is attributed and dated on the record itself. Holders and verifiers see the same history.
Incident response
Security reports use a dedicated route, separate from sales and product support. Response expectations are confirmed when a report is received.
Responsible disclosure
Found something that should not be possible? Email security@arrota.com. Please test only against the demonstration credentials.
Privacy rights
A direct route for privacy requests.
Access, export, correction and deletion requests go to a dedicated privacy inbox, handled separately from everything else. The Privacy Notice is the canonical description of handling as it is approved.
- Retention
- Records are designed to remain accessible beyond the issuing relationship. The Privacy Notice contains the approved retention terms.
- Subprocessors
- A complete subprocessor list will be published on this page when the information is final. We do not publish partial lists.
Formal verification controls
Authorised, logged, minimum-disclosure.
Business verifier organisations are identity reviewed and operate under a declared, logged purpose. Authorisation expires. Disclosure follows the issuer’s policy and the holder’s consent. Activity is recorded in a reviewable history, and mismatched source values are never silently revealed.
What we do not claim
No badges we cannot support.
You will not find SOC 2, ISO 27001, GDPR or CCPA compliance badges on this page. Certifications and compliance attestations will appear when they are genuinely held.
If your review needs something Arrota cannot yet evidence, we would rather tell you that directly than decorate around it.