Security
How we protect data and systems, for our own operations and in the AI systems we build and deploy for clients.
Last updated June 20, 2026
Our approach
Security is an engineering discipline we practice continuously, not a certificate on a wall. We design systems to be defensible from day one and we hold our own infrastructure to the same standard we set for client work.
Data protection
- Encryption of data in transit (TLS) and at rest with reputable providers.
- Least-privilege access, with credentials scoped to what each task needs.
- Secrets kept out of source code and managed through secure stores.
Access control
Access to systems and client data is limited to the people who need it, protected by strong authentication, and reviewed regularly. We remove access promptly when it is no longer required.
Secure development
Security is built into how we ship: code review, dependency and supply-chain awareness, and, for AI systems, adversarial testing for prompt injection, data leakage, and abuse before launch and continuously after.
Client deployments
When it is the right fit, we deploy into your own cloud or on-premises environment, so your data stays within your security perimeter and under your controls, with support for SSO and data-residency requirements.
Monitoring and response
We monitor the systems we run for anomalies and have a process to investigate and respond to incidents, including notifying affected parties where appropriate and required.
Reporting a vulnerability
If you believe you have found a security issue in our website or a system we operate, please email hello@arosplatforms.com with details. We appreciate responsible disclosure and will work with you in good faith to confirm and fix valid issues.