SOC2C

Is this your company? Buyers are checking Armsrm here. Claim armsrm.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Armsrm logo

Armsrm

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Armsrm is SOC 2 Type II compliant. Armsrm also holds NIST CSF, HIPAA, PCI DSS, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

ARMStrong RM is the Largest Receivable Management Firm in North America ====================================================================================== ARMStrong Information Security, Privacy, and Compliance teams work together to build and maintain the trust of our members through visibility into our security posture and compliance readiness. Through our Trust Center we aim to demonstrate to both our members and prospective members that we have the processes and protocols in place to safeguard your data.

Compliance & infrastructure

Hosting
AWSAzure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

29

Subprocessors

24
  • S
    Salesforce · CRM platform and client relationship management
    Cloud, United States
  • B
    BitDefender · Advanced endpoint threat protection
    Cloud, United States
  • A
    Alienvault · Security Information and Event Management (SIEM)
    Cloud, United States
  • C
    CodeTwo · Centralized email signature management
    Cloud, United States
  • C
    Crimson Security · Security
    3rd Party Vendor
  • M
    Microsoft (Azure & 365) · Cloud hosting, productivity, identity management
    Cloud, United States
  • O
    Office 365 · Cloud hosting, productivity, identity management
    Cloud, United States
  • K
    KnowBe4 · Security awareness & phishing simulation
    Cloud, United States
  • Z
    Zoom · Communication platform
    Cloud, United States
  • C
    Cisco Umbrella · DNS filtering, cloud-delivered threat protection
    Cloud, United States
  • P
    Pulseway · Remote monitoring and management (RMM)
    Cloud, United States
  • I
    IT-Glue · IT documentation management
    Cloud, United States
Show all 24 subprocessors
  • A
    AdminDroid Office 365 Reporter - Sign In · Microsoft 365 reporting and auditing
    ARMStrong Data Center, United States
  • A
    Amazon Web Services · Cloud hosting and data storage for certain applications
    Cloud, United States
  • F
    Freshservice · IT service management (ITSM) and ticketing
    Cloud, United States
  • S
    Spanning Backup · Backup and recovery for Microsoft 365 and Salesforce
    Cloud, United States
  • T
    TCN · Cloud-based contact center and outbound dialing platform
    Cloud, United States
  • T
    TransUnion · Phone number validation and DID verification
    Cloud, United State
  • T
    TRX Services, LLC · Credit card payment processing
    Cloud, United States
  • U
    US Signal · Data center and colocation services
    Illinois, United States
  • V
    Vanta · Continuous security monitoring and compliance automation
    Cloud, United States
  • V
    Veeam · Backup, disaster recovery, and replication
    ARMStrong Data Centers, United States
  • V
    VMWare · Virtualization and infrastructure management
    ARMStrong Data Centers, United States
  • Z
    ZoomInfo · Business contact enrichment and prospect data intelligence
    Cloud, United States

Compliance leadership

The person who leads Armsrm's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Armsrm's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Armsrm SOC 2 compliant?
Armsrm is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Armsrm NIST CSF compliant?
According to Armsrm's public trust center, Armsrm is NIST CSF compliant. On SOC2C this listing is Listed.
Is Armsrm HIPAA compliant?
According to Armsrm's public trust center, Armsrm is HIPAA compliant. On SOC2C this listing is Listed.
Is Armsrm PCI DSS compliant?
According to Armsrm's public trust center, Armsrm is PCI DSS compliant. On SOC2C this listing is Listed.
Is Armsrm GDPR compliant?
According to Armsrm's public trust center, Armsrm is GDPR compliant. On SOC2C this listing is Listed.

Answers published by Armsrm

Reproduced from Armsrm's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How is client data protected at ARMStrong?
Client data is protected through enterprise-grade encryption both in transit and at rest. We utilize Microsoft Entra and Intune for identity and device access management, and our environments are regularly audited under SOC 2 Type II and PCI-DSS 4.0 frameworks.
Do you encrypt data at rest?
Yes. All sensitive data is encrypted at rest using AES-256 encryption, and in transit using TLS 1.2+ protocols across all environments.
What endpoint security solutions do you use?
We use a multi-layered approach to endpoint protection that includes Microsoft Defender for Endpoint, Bitdefender Enterprise for advanced threat prevention, and Cisco Umbrella for DNS-layer protection. In addition, we leverage AT&T Cybersecurity (AlienVault) SIEM for real-time threat detection and centralized log analysis. All endpoints are managed and monitored through Microsoft Intune, ensuring compliance and rapid response to any anomalies.
How is physical security handled for your infrastructure?
Our data is hosted in Tier IV data centers with multi-layered physical security, including biometric access controls, video surveillance, and 24/7 monitoring.
Are you SOC 1/2 or PCI compliant?
Yes. ARMStrong maintains SOC 1 Type II and SOC 2 Type II certification and adheres to PCI-DSS 4.0 standards for handling sensitive financial data.

Business & Industrial peers that completed SOC 2