Security
Security & compliance
How ArvoFin protects client financial data — infrastructure, encryption, access, and audit posture.

ArvoFin is SOC 2 Type II attested under the AICPA SOC for Service Organizations framework. The report is available to customers and prospects under NDA.
Client financial data is the most sensitive thing an advisory firm holds. ArvoFin is built to protect it, and we’re transparent about exactly how. This page describes the technical and organizational controls governing how ArvoFin protects customer data; it’s intended for advisors, compliance officers, and security reviewers evaluating ArvoFin.
Infrastructure and hosting
ArvoFin’s production environment is hosted exclusively on Amazon Web Services (AWS) in the us-east-2 (Ohio) region. Production workloads run within isolated Virtual Private Clouds (VPCs) with security groups and network segmentation separating production from non-production environments. Physical datacenter security is delegated to AWS under its Shared Responsibility Model; AWS maintains SOC 2 Type II, ISO 27001, and FedRAMP authorizations for underlying infrastructure. Monitoring uses AWS GuardDuty (threat detection), Datadog (observability), Pingdom (availability), and PagerDuty (alerting and on-call).
Encryption
- In transit: all external communications are encrypted using TLS 1.3; HTTPS is enforced and unencrypted connections are rejected.
- At rest: all data is encrypted at rest using AES-256 via AWS-managed encryption, with authenticated cipher suites where applicable.
Authentication and access control
ArvoFin implements role-based access control (RBAC) under a least-privilege policy. Access to production systems requires multi-factor authentication (MFA) enforced via AWS IAM. Access is provisioned within three business days of hire and revoked within two business days of termination, with periodic access reviews.
Advisor-facing authentication: advisors sign in with secure email/password. Single sign-on (SSO via SAML/OIDC) and enforced account-level MFA are on the roadmap for the enterprise tier and are not yet available.
Data residency
All customer data is stored and processed in the United States (primary region us-east-2, Ohio). ArvoFin does not replicate customer data outside the United States.
Sub-processors
| Vendor | Service | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, database, object storage | us-east-2 (Ohio), USA |
| Anthropic, PBC | AI-assisted document parsing & proposal generation; does not train on submitted content | USA |
| Vanta, Inc. | Security compliance automation | USA |
All sub-processors are subject to data processing agreements and assessed annually. EODHD provides a read-only market-data feed and does not receive customer data. See the full sub-processor list.
Backup and disaster recovery
Critical systems and databases are backed up automatically via AWS-managed services; backups are encrypted at rest and access is restricted and logged. ArvoFin maintains a documented Business Continuity and Disaster Recovery plan; a tabletop exercise (DDoS, insider data sabotage, and production human-error scenarios) was conducted on October 20, 2025 with Agency Cyber, Inc. Current operational targets: Recovery Time Objective (RTO) of 4 hours and Recovery Point Objective (RPO) of 15 minutes.
Vulnerability management
ArvoFin’s SDLC includes security controls at each stage; production changes require approval and are tracked in Jira, with separated development and production environments and documented rollback via version control. ArvoFin conducted a penetration test in April 2026 and maintains an annual pen-test schedule, with monthly vulnerability scanning and dependency auditing alongside continuous GuardDuty runtime detection.
Incident response
ArvoFin maintains a documented Incident Response plan. In a confirmed breach affecting customer data, ArvoFin will notify affected customers within 72 hours of confirmation, via email to the primary account contact, including the nature of the breach, data categories affected, and remediation steps.
Compliance and audit posture
ArvoFin completed a SOC 2 Type II audit covering the period November 18, 2025 – March 30, 2026, conducted by an independent licensed CPA firm engaged via the Vanta marketplace. ArvoFin is SOC 2 Type II attested; the report is available to customers and prospects under NDA.
ArvoFin maintains documented policies including Access Control, Password/MFA, Incident Response, Backup/DR, Change Management, Vendor & Sub-processor Management, Secure Development (SDLC), Network Segmentation, CI/CD Controls, Encryption & Key Management, and Onboarding/Offboarding. A pre-filled CSA CAIQ Lite self-assessment and a Data Processing Addendum are available on request.
Data deletion
Customer data is deleted within 30 days of account termination or a verified deletion request; backup copies are purged within 60 days. Certain audit and financial logs are retained up to 7 years to satisfy legal and regulatory obligations (FINRA Rule 4511 / SEC Rule 17a-4). Full detail: Data Deletion Policy.
Contact
Security inquiries, vulnerability disclosures, or to request documentation (SOC 2 under NDA, CAIQ, DPA): support@arvofin.com. Privacy and data-deletion requests: privacy@arvofin.com.
Questions your compliance team wants answered? Bring them to a demo — we’ll give honest answers on security, integrations, and rollout.