Security

Security Policy

At Arrive, we take security seriously. This document outlines our approach to protecting sensitive financial data and maintaining security across the platform.

Security Architecture

Application layer security, API security, database security, infrastructure security, network security, data encryption, and access controls.

Registration Requirements

To use our Service, you must create an account with accurate, current, and complete information.

Authentication & Authorization

  • Identity Provider: Secure authentication powered by Clerk
  • Multi-Factor Authentication (MFA): Required for all user accounts
  • Session Management: Secure session handling with automatic expiration
  • Password Security: Industry-standard password policies and secure storage

Role-Based Access Control (RBAC)

Admin, Firm Partner, Accountant, Advisor, Bookkeeper, Team Member, and Client Guest roles, each with defined access levels.

API Security

JWT-based authentication, request rate limiting, CORS protection, and separate admin token authentication.

Data Protection

  • Data in Transit: TLS 1.3
  • Data at Rest: AES-256 encryption
  • Database Encryption with secure key management
  • File Storage: Encrypted storage in AWS S3 with server-side encryption
  • Input validation, XSS protection, SQL injection prevention, secure file upload validation and malware scanning

Infrastructure Security (AWS)

VPC isolation, security groups, IAM least-privilege policies, SSM parameter management, container security (Docker/ECS with image scanning), and network security (load balancer SSL termination, VPN access, network monitoring).

Document & File Security

Secure OCR processing (AWS Textract), file validation, virus scanning, document encryption, S3 security, presigned URLs, and access logging.

Third-Party Integration Security

Stripe (PCI-compliant), DocuSign (secure signing with audit trails), Twilio, and QuickBooks (encrypted sync), using OAuth 2.0, secure API key management, and webhook signature verification.

Data Backup & Recovery

Encrypted backups (AES-256), geographic distribution, strict access controls, regular integrity testing. Recovery Time Objective: 4 hours; Recovery Point Objective: 1 hour. Regular disaster recovery testing and business continuity planning.

User Security Best Practices

Enable MFA, use strong unique passwords, review account activity regularly, report suspicious activity, avoid sharing credentials, use secure networks, keep devices updated, and log out when finished.

Reporting Security Issues

For questions about security practices or to report a concern, contact security@arrive.com.

Questions about these terms? Contact us at legal@arrive.accountants.