Skip to content

Hardware Security

ARROW devices are made to be left behind on networks you do not control and, sometimes, in places you cannot watch. The hardware is built on the assumption that it will eventually be found, unplugged, or taken. This page covers what keeps a device safe when that happens. For the platform-wide picture, start with Security, and see ARROW Manager Security and ARROW Control Security for the software that runs on the device.

Everything here applies to both the ARROW Device and the OBSIDIAN Device.

The working storage inside every device is fully encrypted with LUKS. The operating system, your tools, engagement data, and captured results all sit behind that encryption. If a device is lost or seized while it is powered off, its disk is unreadable without the key. Someone who walks off with the hardware walks off with a locked box, not your data.

Each device uses Secure Boot together with the built-in TPM 2.0, so it will only start trusted, signed software. That closes off a common physical attack: swapping in a tampered boot image or a malicious operating system to get around the encryption. The device boots the software it is supposed to boot, or it does not boot.

An ARROW device dials home over an always-on VPN and is worked remotely through that connection. It does not open services to the network it is plugged into and does not expose a public address. On the client’s LAN it stays quiet: there is no dashboard to find, no port to scan, and no login prompt waiting on the local network. All management happens over the VPN, where access is scoped to the consultants assigned to the device. See Network Access Control.

The VPN fails over to a built-in cellular modem, so the device stays reachable even when the wired network is unavailable or has been cut. That is a convenience for getting your work done, and it is also a safety property: as long as a device can reach the network, you can keep managing it rather than losing track of one sitting on a client site.

The strongest encryption does not help against a device that is handed to the wrong person or left logged in. Treat the hardware as sensitive equipment throughout an engagement:

  • Keep chain of custody. Know where each device is, who deployed it, and who is responsible for retrieving it.
  • Do not leave a live session unattended. A powered-on, unlocked device is only as safe as the room it is in.
  • Confirm placement with the client. The device should sit where the engagement authorizes it to sit, and nowhere else.
  • Report a lost or stolen device immediately. Contact support the moment a device is unaccounted for, so its access can be cut.

A device does not carry one engagement’s data into the next. When a device is returned and re-imaged for its next deployment, its encrypted storage is wiped and re-keyed, so the new engagement starts clean and the previous client’s data does not travel with the hardware.

Lost or seized device If a device is lost, stolen, or seized, contact support right away. The encryption keeps the disk sealed, and cutting the device’s access closes off its connection to your network. Reporting it quickly is what turns a lost device into a non-event.