The whole device, on one dashboard
The moment the device powers on at a client site, it phones home over the VPN, no one there ever has to touch it. Monitor its health, deploy VMs, configure networking, and run a terminal from ARROW Manager, from anywhere.
Hardened as steel, from the firmware up
Every ARROW device is built to survive supply-chain compromise and physical tampering, the same protections on every unit, whether it is on your desk or intercepted in transit.
Secure Boot
Custom ARROW signing keys validate the entire boot chain. Only signed code runs, so rootkits and tampered firmware never load.
TPM 2.0 Root of Trust
A hardware security chip measures the boot state and releases disk keys only when integrity checks pass, even against an attacker with physical access.
BIOS Lockdown
A unique, random BIOS password per device blocks boot-order changes and any attempt to disable Secure Boot, with tamper auditing on every try.
Two-Factor Data Drive
Sensitive data sits on a separate encrypted drive that unlocks only with device integrity plus an operator password, set fresh for each deployment.
Full-Disk Encryption
LUKS full-disk encryption with customer-held keys the device never stores, so a seized or intercepted unit gives up nothing.
Supply-Chain Resistant
From fabrication to delivery, no unauthorized firmware can load, so a device tampered with in transit still boots to a known-good state.
Full control of the on-site appliance
Everything happening on the device, in one dashboard you reach over the VPN, the LAN, or its own hotspot.
Live Health Monitoring
Real-time CPU load and temperature, RAM, per-drive storage, network IPs, cellular signal, and VPN connectivity.
VM Deployment
Deploy disposable VMs from pre-built templates onto LUKS-encrypted storage, ready to run in minutes.
Networking & VPN
Static or DHCP addressing, LTE bridge mode, dual-SIM and eSIM, Wi-Fi hotspot, and live VPN peer and relay status.
Browser Terminal
Full shell sessions in tabbed browser windows with adjustable font size, no separate SSH client required.
Hands-Off Updates
Updates are scheduled centrally and installed in the background with no downtime, keeping the whole fleet consistent.
Encrypted by Default
VM storage is protected by a LUKS passphrase the device never stores, re-entered by the operator after every reboot.
