Trust centre

Trust centre.

How ARMS protects your data, your residents and the integrity of the record.

Your data stays in Canada

Customer data is stored in Google Cloud's Toronto and Montréal regions by default, with redundancy across multiple zones and no cross-border failover. Each building is assigned to a region, and requests for it are processed only there. At onboarding you choose where AI runs: Canadian-hosted models for full Canadian residency, or leading global models.

Encrypted everywhere

TLS 1.3 in transit and AES-256 at rest, with immutable audit logs for every action. Files on Google Cloud with private, expiring links. Role-based, least-privilege access with per-building isolation. Sign in with Google or email.

Certifications

ARMS runs on Google Cloud and Firebase, whose infrastructure is independently certified to ISO/IEC 27001, 27017, 27018 and 27701, SOC 2 Type II, CSA STAR Level 2 and PCI DSS. Where a customer requires ARMS to hold its own certification, such as SOC 2, we will pursue it as part of that engagement.

Your data is yours

Export it at any time, including when you leave. Retention periods are agreed with each customer at onboarding, to match their building type and legal obligations.

Records nobody can alter

Customers can lock their records for a retention period of their choosing. Once locked, no one, including ARMS, can modify or delete a record until that period ends; it can be extended but never shortened. When it ends, records can be deleted automatically. Every record carries the time it happened on the device and the time ARMS received it, and a submitted record can only be added to, never edited.

Responsible AI

AI may recommend. Policy determines what is permitted. Verification proves what occurred. Uncertain decisions go to a person.

Accessibility

Data processing agreement

Available on request.

Providers

ARMS uses carefully selected providers for cloud hosting, AI, communications and payments. The current subprocessor list is provided with our data processing agreement.

Report a vulnerability

info@armstechnologies.ai

Bring your IT team to a technical call.