Our private cloud is certified for compliance with industry standards for application and web site security. A "private cloud" simply means the servers are physically located within our data center on Green Arrow-dedicated hardware, rather than on a server in a closet or room at your corporate office. With either "cloud" or "on premise" deployment, the software will always be exposed to the internet — users from outside your organization must access the public web site in order to use the software. While our software does not contain any healthcare or financial information, our data center complies with these highest standards in the industry:
SSAE 16 / AICPA SOC 2 Type II certified
HIPAA compliance (Health Insurance Portability and Accountability Act)
PCI compliance (payment card industry)
Gramm Leach Bliley Act (GLBA)
Sarbanes Oxley Act (SOX)
Fair and Accurate Credit Transaction Act (FACTA)
Family Educational Rights and Privacy Act (FERPA)
Federal Information Security Management Act (FISMA)
SEC Cybersecurity Threats Disclosure Guidance
Managed Services
All Green Arrow Labs systems are hosted in a dedicated private cloud in an enterprise-class SSAE 16 SOC 2 Type II data center. Link Services is a web-based application delivered under the Software-as-a-Service (SaaS) cloud computing model. This means that the application, operating system, database, and entire computing infrastructure (beyond the user's machine) — and all the maintenance thereof — are covered by your subscription fee and our data management services agreement.
Security
All critical entry points feature two factor authentication
Biometric fingerprint readers
24/7/365 monitored video surveillance with 90 days trailing of footage onsite
Individually locking, audit-traceable rack systems
Multiple logical security systems including: intrusion detection, vulnerability and risk assessments, and coordinated strategies for combating DDOS attacks