Managing risks and being compliant is in our blood. If you're evaluating SaaS, you're responsible for your organization's data and program. At Archer, we have taken great steps to be as secure and as transparent as we can for our clients. We partnered with AWS to make sure our clients data is safe and ready to use.
Visit our Trust Center to see our security documentation. This site is updated regularly and has everything your supplier risk team will ask for, including:
- SSAE 18 SOC2 Type 2
- ISO Certifications
- External Penetration Test Results
- Web Application Security Assessments
- Our Full SIG Questionnaire
- IT Security Policies
- Privacy, Legal, and Human Resource Statements
- Secure Coding Practices
- and more
In addition to accessing the Trust Center, below are some answers to common concerns from our clients.
Where is Archer SaaS Hosted?
We run on AWS across seven global service offerings. Every offering uses multiple AWS availability zones within its region, so the absence of a secondary backup region does not mean a single data center.
| Service offering | Primary region | Secondary / backup region |
|---|---|---|
| US | US-WEST-2 (Oregon, USA) | US-EAST-1 (N. Virginia, USA) |
| EMEA | EU-WEST-1 (Ireland) | EU-CENTRAL-1 (Frankfurt, Germany) |
| APJ | AP-SOUTHEAST-2 (Sydney, Australia) | AP-SOUTHEAST-4 (Melbourne, Australia) |
| Canada | CA-CENTRAL-1 (Montreal, Canada) | CA-WEST-1 (Calgary, Canada) |
| UAE | ME-CENTRAL-1 (Dubai & Abu Dhabi, UAE) | EU-CENTRAL-1 (Frankfurt Germany) |
| India | AP-SOUTH-1 (Mumbai) | AP-SOUTH-2 (Hyderabad) |
We host over 1,600 Archer SaaS instances. Each one has unique configurations, sizes, and user populations.
Is My Data Safe?
Yes. Below are some quick notes about our security.
- Availability: 99.5% composite SLA, backed by service credits calculated per minute of downtime.
- Certifications: ISO 27001, ISO 27017, and ISO 27701.
- Encryption and backups: Secure storage with automated backups and encryption at rest and in transit. AES-256 + TLS 1.3.
- SaaS-specific protections: Field Level Encryption is available in Archer SaaS with Bring Your Own Key (BYOK) support for clients who want to manage their own encryption keys.
- Continuous assurance: ongoing compliance auditing and third-party penetration testing.
Is This a Multi-Tenant Environment?
Most commonly yes, Archer SaaS operates within a multi-tenant environment. While hardware infrastructure is shared, client data is segmented on a per-instance basis. Each instance is logically separated using distinct directories and databases, ensuring no client data is commingled. No data is accessible by anyone other than you.
In addition to our multi-tenant deployment, clients can choose to deploy with a dedicated database infrastructure, at an additional cost. For clients with extra security concerns, Archer also offers single-tenant environments, at an additional cost.
What About "Noisy Neighbors"?
A common multi-tenant concern: will another client's load slow me down? Our architecture is built specifically to prevent this. We have implemented rate limiting, a Resource Governor in the Archer database, scale-out caching to absorb peak loads, and serverless cloud jobs.
We invest in performance continuously. To learn more, see Continual Performance Improvements in Archer SaaS for the architectural detail.
What About Other Archer Products?
In addition to our best-in-class GRC platform, Archer sells a variety of add-on tools that enhance the experience, such as Engage, Insight, Document Governance, and Evolv. We protect these systems as well, and because of differences in architecture and purpose, we have conducted independent audits on those software components. Visit our Trust Center to see our security documentation on these specific products.
Comments
0 comments
Please sign in to leave a comment.