Lunch Promo Applied! 🍔 Demo Arrellio in the month of April and get lunch for your staff on us! Claim offer

Security

Committed To Security & Compliance

In addition to being HIPAA compliant, we're the only optometry software company that holds both an ISO-27001 and SOC-2 Type II certification! Our security controls are publicly available and audited by independent third parties. Your patients trust you with their most sensitive information…you deserve a partner that treats that responsibility as seriously as you do.

HIPAA Compliant

HIPAA

Arrellio is fully HIPAA compliant and independently audited, so your patients' data is protected, always.

  • Check Independently audited and verified
  • Check End-to-end encryption on all patient health information
  • Check All data stored on HIPAA-compliant infrastructure
Visit Our Trust Center
HIPAA

SOC 2 Type II Certified

SOC 2 Type II

Arrellio is one of only two platforms in the optometry industry independently audited to meet SOC 2 Type II compliance - and the only one that also holds ISO 27001. That means the highest standards for security, availability, and confidentiality, verified twice over.

  • Check Verified by an independent third-party auditor
  • Check Controls tested across security, availability, and confidentiality
  • Check One of only two platforms in optometry to hold this certification
Visit Our Trust Center
SOC 2 Type II

ISO 27001 Certified

ISO 27001

Arrellio is ISO 27001 certified, meeting the internationally recognized standard for information security management.

  • Check Formal risk management processes, continuously maintained
  • Check Internationally recognized information security standard
  • Check Certified by an accredited third-party
Visit Our Trust Center
ISO 27001
FAQs

What We Get Asked The Most

You have questions, we have answers! Don't see your question listed below, or want more details? Reach out and a real human who's worked in a practice (not AI) will get back to you.

HIPAA (Health Insurance Portability and Accountability Act) sets federal rules for protecting patient health information. For a software platform, compliance means putting administrative, physical, and technical safeguards in place to keep patient data secure across storage, handling, and transmission.

Yes. As a platform that handles Protected Health Information (PHI) on behalf of your practice, we are a Business Associate under HIPAA. We sign BAAs with every customer.

All patient data transmitted through the Arrellio platform is encrypted in transit and at rest.

SOC 2 Type II is an independent audit that verifies not only if a company's security and operational controls are designed correctly, but if they are actually working and maintained over an extended period of time. It's a significantly higher bar than SOC 2 Type I, which only verifies controls exist at a single point in time.

SOC 2 Type II audits cover a defined period (typically 12 months) and are renewed annually. Arrellio maintains continuous compliance and undergoes regular re-audits to ensure our certification stays current.

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It requires organizations to systematically identify security risks and implement controls to manage them - and to continuously improve those controls over time. It's one of the most rigorous and globally recognized certifications a software company can hold.

Yes. As of the publication of this page, Arrellio is the only optometry software platform holding an ISO 27001 certification.

ISO 27001 certification includes annual surveillance audits and a full recertification audit every three years. Arrellio maintains continuous compliance between audits through its internal Information Security Management System.

Ready To Get Started?

Book demo