Skip to content

Security

ARROW Manager is the dashboard that runs on the device itself, where you check its health, manage connectivity, and deploy VMs. Because it controls the device, its security matters as much as anything in the Console. This page covers how it is protected. For platform-wide protections, start with Security.

ARROW Manager is reachable only over the private VPN. The device does not publish the dashboard to the client network it is plugged into, and there is no public address that exposes it. To open ARROW Manager you first have to be on the VPN, the same requirement that protects ARROW Control. If you are not on the VPN, the dashboard simply does not answer.

Reaching ARROW Manager over the VPN is the first gate, not the last one. The dashboard still requires you to authenticate before it will show you anything or let you make changes. Sessions do not stay open forever, so a device left unattended does not stay logged in indefinitely.

ARROW Manager lives on the device’s encrypted storage. If the hardware is lost or seized, the dashboard, its settings, and everything else on the disk stay sealed behind full-disk encryption. See Hardware Security for what protects the device physically.

Part of ARROW Manager’s job is to keep the device’s traffic on a known path. The health banner on the dashboard continuously checks that the device can reach the VPN and tells you in plain language whether it is good to go. When you route the device’s traffic through the transparent proxy, its outbound connections egress through the VPN rather than leaking straight onto the local network. That keeps the device’s activity deliberate and accounted for instead of noisy on a network you are only visiting.

  • Keep the health banner green. If it reports that the device cannot reach the VPN, connectivity is degraded and remote access may be affected. Re-check from the banner, and contact support if it does not clear.
  • Sign out on shared machines. If you open ARROW Manager from a computer other than your own, sign out when you are done.
  • Treat the device as sensitive. Anyone with physical access and the system credentials can reach the dashboard locally, so handle the device the way you would handle any tool that holds engagement data. See Hardware Security.