Trust Center
Governed by design. Transparent by principle.
ARWIX is built on the premise that governance, accountability, and transparency are not features to be configured — they are design principles reflected in how the platform operates. This page explains our approach across ten dimensions of trust.
What this page covers: ARWIX's design philosophy and operational principles related to security, privacy, governance, and accountability. This page does not claim certifications not currently held. ARWIX is not FedRAMP authorized, SOC 2 certified, ISO certified, DoD authorized, or HIPAA/PCI covered. Specific compliance requirements depend on the client implementation environment and are discussed during implementation planning.
Security Philosophy
Security is treated as a platform design principle — not a configuration option.
ARWIX is designed with security-conscious principles built into its architecture — not added as a layer after the core system was built. Access controls, data scoping, session management, and input validation are platform characteristics rather than configurable modules.
ARWIX does not make claims about specific security certifications, infrastructure configurations, or hosting environments that depend on factors outside the platform itself. Organizations operating under specific security requirements should evaluate ARWIX against their applicable standards and work with their implementation team to configure the deployment environment appropriately.
In Practice
- → Access controls applied at the platform architecture level
- → Data scoping enforced by role, not by trust
- → Session management designed to limit exposure
- → Input validation and data handling practices aligned with security-conscious design
Privacy
Participant data is scoped, purposeful, and protected by platform design.
ARWIX is designed around the principle that participant data should be accessible only to participants with a legitimate need to see it — and only for purposes that serve the relocation case they are authorized to manage.
Every participant workspace exposes only the data their role requires. Cross-participant data access is explicitly scoped rather than permissive by default. Employees see their own relocation. Carriers see their assigned shipments. Coordinators see cases they are authorized to manage.
In Practice
- → Participant data scoped to authorized roles, not accessible by default
- → Employee personal information protected from carrier and supplier visibility
- → Data minimization by design — workspaces expose what is needed, not everything available
- → Data exchange with external systems managed through defined contracts, not open access
Role-Based Access Control
Every participant sees exactly what their role authorizes — and nothing more.
Role-based access control in ARWIX is enforced at the platform level — not as a post-implementation configuration that can be bypassed or overridden by coordinator discretion. Every participant's access scope is determined by their assigned role, and that scope governs what they can view, what actions they can take, and what cases they can affect.
Administrators configure roles; the platform enforces them. A coordinator cannot see cases outside their authority. A carrier cannot see case information beyond their assigned shipments. A finance reviewer cannot take operational actions reserved for coordinators.
In Practice
- → Granular permission scopes per participant role
- → Least-privilege principles applied by platform default
- → Role assignment controlled by authorized administrators
- → Carrier and supplier access scoped to specific shipments and services
- → Finance and audit roles with read-only visibility to case financial records
Governed Access & Policy Enforcement
Policy is enforced by the platform — not left to individual interpretation.
Governance in ARWIX is not a reporting feature or an audit module. It is the operational foundation of the platform. Policy rules — for Corporate, FAR, FTR, and JTR frameworks — are configured as platform constructs that govern how cases progress, how entitlements are applied, and how exceptions are handled.
When a coordinator makes an entitlement determination, the platform enforces the applicable policy rule. When an exception is proposed, the platform routes it through the configured approval path. The result is consistent policy application across every case, regardless of which coordinator manages it.
In Practice
- → Framework-level policy rules enforced as platform constructs
- → Consistent policy application across cases, coordinators, and programs
- → Exception handling routed through configured authority tiers
- → Policy change events logged in the governance audit trail
- → Organizational hierarchy reflected in approval routing
Auditability & Traceability
Every action, approval, and decision leaves a documented record.
ARWIX is designed to produce audit evidence as a natural output of normal operation — not through after-the-fact report generation. Every approval, authorization, exception, document change, and policy decision is logged with a timestamp, the identity of the actor, and the applicable rule or context.
The audit trail is designed to be meaningful — providing sufficient context to understand what happened, who decided it, and why — not just a log of events. Organizations responding to program audits or oversight inquiries can present complete case documentation without reconstruction.
In Practice
- → Case event timeline per relocation — every action, actor, and timestamp
- → Governance event log for policy and configuration changes
- → Approver audit log with decision records and authority basis
- → E-signature packet with SHA-256 hash and timestamp evidence
- → Exception records documenting approval chain and basis
Responsible Intelligence
Guidance with evidence. Recommendations that can be explained.
ARWIX provides policy-aware guidance and decision support — surfacing relevant rules, flagging exceptions, and helping coordinators understand what applies and why. This guidance is designed to be explainable: every recommendation can be traced to the policy rule, organizational configuration, or precedent that informed it.
ARWIX does not make consequential decisions autonomously. It does not determine entitlements, approve authorizations, or resolve exceptions without human review. Intelligent features are designed to support better-informed human decisions — not to remove humans from the decision process.
In Practice
- → Policy-aware guidance derived from configured rules — not generic recommendations
- → Every recommendation traceable to its source policy or configuration
- → Human review required for consequential authorization decisions
- → Exception routing to authorized human reviewers, not automated resolution
- → No autonomous action on decisions with financial or legal weight
Human Accountability
People remain accountable for the decisions that affect people.
ARWIX is built on the principle that consequential decisions in relocation program management — entitlement determinations, authorization approvals, exception resolutions — must remain with accountable humans. The platform supports those decisions with better information, clearer policy guidance, and documented precedents. It does not replace them.
This is not a limitation of ARWIX's capability. It is a deliberate design choice. When an entitlement determination is challenged, there is a person who made it and can be asked about it. When an exception was approved, there is an approver with a documented basis. When automation took an action, there is a logged rule and a logged trigger. Accountability is preserved at every step.
In Practice
- → Authorization decisions require human approval at configured authority tiers
- → Automated actions logged with rule citation, trigger, and actor
- → Exception routing preserves human decision authority
- → Coordinator identity attributed to every case action
- → Approval authority configurable to organizational hierarchy, not platform defaults
Platform Reliability
Designed to operate consistently — because relocation timelines are not flexible.
Relocation programs depend on consistent platform availability. A coordinator cannot request an exception when the approval workflow is unavailable. An employee cannot sign a time-sensitive document when the platform is inaccessible. Carriers cannot confirm service schedules when the coordination interface is down.
ARWIX is designed with reliability as an operational requirement — not a best-effort goal. Specific uptime commitments, infrastructure architecture, and disaster recovery capabilities are discussed during implementation planning and reflected in service agreements. ARWIX does not make specific uptime claims on this page that depend on implementation context.
In Practice
- → Availability designed to support time-sensitive relocation milestones
- → Platform architecture oriented toward consistent, predictable performance
- → Specific reliability commitments discussed during implementation planning
- → Incident response and escalation processes in place for operational issues
Configuration Responsibility
The platform provides the infrastructure. Organizations configure it responsibly.
ARWIX provides configurable governance infrastructure — role assignments, policy rules, approval authorities, workflow parameters, and access scopes. The platform enforces whatever is configured. This creates shared responsibility: ARWIX is responsible for enforcing the configuration; the organization is responsible for the quality and accuracy of the configuration itself.
Organizations that configure ARWIX with inaccurate policy rules, inappropriate role assignments, or insufficient approval authority structures will not benefit fully from the platform's governance capabilities. ARWIX provides the tools. Appropriate program administration applies them.
In Practice
- → Policy accuracy is the organization's responsibility — ARWIX enforces what is configured
- → Role assignments must reflect actual authority — the platform enforces, not validates
- → Approval authority thresholds configured by authorized administrators
- → Implementation teams support organizations in applying configuration best practices
- → Periodic configuration review is recommended as programs evolve
Data Stewardship
Relocation data is sensitive. It is treated accordingly.
Relocation cases contain sensitive information about individuals — their family composition, their financial circumstances, their physical location, and their personal documents. ARWIX treats this information as belonging to the organization and the individuals it describes — not as platform property.
Data stewardship in ARWIX means scoped access, purposeful collection, and careful handling at every point in the case lifecycle. It means not collecting information that is not needed. It means not sharing information with participants who have no authorized use for it. It means retaining documentation for legitimate audit and records purposes without indefinite data accumulation.
In Practice
- → Relocation data scoped to case participants with authorized need
- → Personal information protected from unauthorized cross-participant access
- → Data collection oriented to relocation lifecycle requirements, not platform analytics
- → Records retention designed to support audit and program management requirements
- → Data exchange with external systems controlled through defined integration contracts
Certifications & Authorizations
ARWIX does not currently hold formal certifications or government authorizations.
We believe in transparency about what ARWIX is and is not. ARWIX is a commercial relocation platform designed with security-conscious principles and governed-access architecture. It is not FedRAMP authorized, SOC 2 certified, ISO certified, DoD authorized, or HIPAA/PCI covered.
Organizations operating under specific regulatory, security, or data classification requirements should evaluate ARWIX against their applicable standards. Security requirements, hosting configuration, and compliance boundaries are addressed during implementation planning and reflected in contractual commitments.
Have Questions About ARWIX Trust and Governance?
We are direct about what ARWIX does and does not claim. Request a conversation with our team to discuss your organization's specific security, governance, and accountability requirements.