SOC2C

Is this your company? Buyers are checking Arrows here. Claim arrows.to free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Arrows logo

Arrows

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Arrows is SOC 2 Type II compliant. Arrows also holds GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Digital sales rooms and customer onboarding plans built for teams that run on HubSpot. Since day one, security has been a top priority at Arrows. This trust center provides an overview of the data security practices and procedures we've implemented.

Compliance & infrastructure

Hosting
AWSGCP

Documents

3

Subprocessors

20
  • H
    Heroku · Application hosting
    USA
  • A
    Amazon Web Services · Customer file hosting
    USA
  • S
    Segment · Product analytics
    USA
  • P
    Postmark · Application email service
    USA
  • H
    HubSpot · CRM and email marketing
    USA
  • S
    Sentry · Application error tracking, metrics, and logging
    USA
  • M
    Metabase · Product analytics
    USA
  • H
    Hightouch · Data ETL tool
    USA
  • S
    Slack · Internal communication
    USA
  • O
    OpenAI · Provider for backend support of AI-powered functionality
    USA
  • A
    Anthropic · Provider for backend support of AI-powered functionality
    USA
  • H
    Hotjar · Product analytics
    EU (Ireland)
Show all 20 subprocessors
  • G
    Google Workspace · Email communications
    USA
  • G
    Google Analytics · Marketing analytics
    USA
  • G
    Google Cloud Platform · Provider for backend support of AI-powered functionality
    USA
  • G
    Grain · Video recording
    USA
  • C
    Cloudflare · Web application firewall
    Global
  • F
    Front · Customer support
    USA
  • P
    Parallel · Web scraping and search
    USA
  • P
    PlanetScale · Application database
    USA

Compliance leadership

The person who leads Arrows's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Arrows's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Subprocessor updateMar 2026

We are adding a new subprocessor: - PlanetScale: Application database You can view our full list of subprocessors at https://trust.arrows.to/subprocessors

AI Trust & Security Overview has been updatedMar 2026

We have updated our *AI Trust & Security Overview* with clarified language and refreshed details. No material policy changes were made.

Subprocessor updateJan 2026

We are updating our list of subprocessors as follows: Added: - Cloudflare: Web application firewall - Front: Customer support - Parallel: Web scraping and search Removed: - Fathom: Call recording These subprocessors may process limited customer data as part of delivering our services. You can view our full list of subprocessors at https://trust.arrows.to/subprocessors

New Resource Uploaded – AI Trust & Security OverviewApr 2025

We’ve added a new document outlining how we securely develop and use AI features in Arrows. The _AI Trust & Security Overview_ is now available under “Resources” in our Trust Center. As always, let us know if you have any questions!

Subscribe to Updates From Arrows’ Trust CenterApr 2025

You can now subscribe to updates from Arrows’ Trust Center to be notified about changes to our compliance and security program. We’ll use this channel to share key updates like new security documentation, upcoming subprocessor changes, and developments in our security and privacy practices.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Arrows SOC 2 compliant?
Arrows is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Arrows GDPR compliant?
According to Arrows's public trust center, Arrows is GDPR compliant. On SOC2C this listing is Listed.
Is Arrows SOC 2 Type I or Type II?
Arrows is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Arrows's SOC 2 for a vendor risk assessment?
Yes. Arrows's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Arrows penetration tested?
Arrows hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Business & Industrial peers that completed SOC 2