Security answers, including the awkward ones.
How your data is handled, who can see it, what happens when someone leaves, and a plain list of the certifications we do not hold. Written for the person who has to sign off on us.
What we hold, and what we do not.
Most vendor pages in our category lead with badges. We would rather lead with the honest version, because procurement finds out either way and it is cheaper for both of us if you find out now.
We do not hold SOC 2 or ISO 27001
Not "in progress", not "aligned to". We do not have them. If your procurement process requires an attestation report before signing, we are not your vendor yet, and we will tell you that on the first call rather than the fifth.
Several larger competitors do claim both. That is a real advantage for them and a fair reason to choose them.
What we do have
- A signed NDA from every VA before they touch your systems
- Role-based access, scoped per client and per project
- Tracked work data that only you and we can see
- Named accountability: an operations manager who owns your account
- Teams trained to work inside HIPAA, PCI DSS, TCPA, GLBA and FERPA programs
Who can see what.
Our own systems record how your work gets done. That data is only useful if it is also protected, so here is exactly how it is handled.
Tracked work data
Trckr records hours, activity level and periodic screenshots. Screenshots are never served as public files. They can only be delivered through an authenticated request, so a link on its own gets you nothing.
Scoped per client
A VA who works across more than one client is scoped by project. You see your own work only. Another client never sees yours, and this is enforced in the system rather than by policy.
Encrypted in transit
Every Armasourcing surface is HTTPS only, with strict transport security, frame protection and content type protection enforced at the server.
The control that actually matters.
Most offshore data incidents are not sophisticated attacks. They are an account nobody closed and a person nobody managed.
Joining
- NDA signed before any access is granted
- Access limited to the tools the role actually needs
- Briefed on your handling rules, not just ours
- Interviewed by you before they start, so you know who has the keys
Leaving
- You revoke your own systems, we revoke ours
- Tracked data for the engagement stays available to you
- Handover to the replacement is supervised, not left to the outgoing VA
- Offboarding is a checklist we run, not an email we hope someone reads
If you operate under a framework.
Our contact center teams are trained and set up to work inside five of them. The detail, including what each one changes about how an agent handles a call, is on its own page.
Being compliance ready is not the same as holding your certification for you, and we will not let that blur. It means our people and processes are built to operate inside your compliance program. The obligation stays yours, we make it possible for an offshore team to work inside it without becoming your weakest link.
What buyers ask us.
Will you sign our NDA, MSA or DPA?
Yes to an NDA and an MSA. On a data processing agreement, send it over and we will tell you honestly which clauses we can meet today and which we cannot. We would rather redline something than sign a document we cannot actually honor.
Can we run our own security review?
Yes. Send the questionnaire. You will get straight answers including the ones that are 'no', and we will not pad it with controls we do not run.
Where is our data stored?
Work happens in your systems, so most of your data never leaves them. What we hold is the operational layer: tracked hours, activity, screenshots and QA records, on our own infrastructure, reachable only through authenticated access.
Can we turn screenshot capture off?
Yes, if your work is sensitive enough that screen capture is itself a risk. Some clients in legal and healthcare do exactly that. You lose that verification layer, which is a real trade, so we will talk it through rather than just flipping it.
What happens if there is an incident?
You hear it from us, with what we know and what we do not yet know, rather than a reassuring summary a week later. Then we contain it and tell you what changed so it does not happen again.
Are you planning to get SOC 2?
It is under consideration and it is not promised. When a certification exists it will be on this page with its date and scope. Until then this page says we do not have one.
Send us your security questionnaire.
We will fill it in properly, including the questions where the answer is no. Book a 15 minute call and we will tell you quickly whether we clear your bar.
Book a Free Discovery Call