Trust Center

Security Claims You Can Review Before You Buy

A plain-language view of ArrivSure's documented safeguards, privacy posture, AI boundaries, and the responsibilities that remain with each customer.

Documented practices

The controls currently described by the product

This page intentionally avoids certification, hosting, recovery, penetration-testing, and uptime claims that have not been confirmed for publication.

Protected connections

ArrivSure uses TLS-protected connections for data moving between supported kiosks, web experiences, and staff apps. Sensitive staff-message content is also protected at rest.

Access scoped by responsibility

Role, tenant, facility, and workspace permissions are designed to limit what an authorized user can view or manage. Customers are responsible for assigning and reviewing access.

Supported activity history

Configured workflows retain activity and version history that can support internal review, record retrieval, and legal-preservation processes where available.

Protected staff access on iPhone

The Companion app can use Face ID or Touch ID on supported devices and stores app credentials using the iOS Keychain.

Privacy by purpose. ArrivSure does not sell personal information or use it to build advertising profiles. Customer data is used to provide, secure, support, and improve the service as described in the Privacy Policy.

Healthcare and sensitive workflows

A Business Associate Agreement can be considered for eligible healthcare use after the intended workflow and data flow are reviewed. A BAA is one part of an appropriate HIPAA arrangement, not a blanket product certification.

Customers remain responsible for configuration, minimum-necessary access, policies, training, device administration, and determining what information their workflow may lawfully collect.

AI with human review

AI features are assistive: summaries, drafts, pre-fills, and possible matches require human review.

Permission-scoped query tools are designed to read authorized records rather than make operational changes.

Regulated PHI should not be placed into an AI workflow unless the use case, data flow, written approval, and applicable agreement have been reviewed first.

Shared responsibility

What ArrivSure does—and what it does not do

ArrivSure records the configured digital workflow. It does not authenticate identity, unlock doors, replace physical emergency accountability, determine legal eligibility, or guarantee regulatory or reporting outcomes. Customers control what is collected, who receives access, physical-entry decisions, and applicable policy.

Review before implementation

Bring us your actual security questions.

We’ll review the intended data, users, locations, integrations, and healthcare requirements before representing the fit.