ARBITER
Platform Operations Intel Client App Security About
Request Demo

Legal · Provider App

Provider App Terms of Service

Version 1 · Effective July 8, 2026 · Current version

1. Acceptance of Terms

These Provider App Terms of Service (this “Agreement”) govern access to and use of the Arbiter Provider App (the “Provider App”) made available by ARBR Inc. d/b/a Arbiter Defense Group (“Arbiter,” “we,” “us,” or “our”) to licensed private security provider firms and their authorized personnel (each, a “Provider,” and each individual acting on a Provider’s behalf, an “Operator”). By creating an account, accessing, or using the Provider App, you and the Provider organization on whose behalf you act agree to be bound by this Agreement. If you do not agree, do not access or use the Provider App.

2. Definitions

  • “Client” means the individual or entity receiving protective-security services coordinated through the Arbiter platform and using the Arbiter Client App (the “Client App”).

  • “Engagement” means a discrete protective-security assignment established within the platform connecting one or more Providers to a Client.

  • “Entity of Interest” (“EoI”) means a person, organization, or asset tracked within an Engagement for threat-assessment purposes.

  • “Intel Product” means any dossier, brief, after-action report (“AAR”), threat-vulnerability assessment (“TVA”), or similar work product generated, in whole or part, using the platform’s research, AI-assisted drafting, or open-source intelligence (“OSINT”) tools.

  • “Platform” means the Provider App, the Client App, and the underlying Arbiter services.

3. Eligibility; Account Registration; Organizational Activation

3.1 Provider organizations are manually activated by Arbiter following identity and business-legitimacy review. Arbiter’s activation of a Provider organization is not, and must not be represented to any third party as, a verification, endorsement, or certification of that Provider’s licensure, competence, or fitness to provide protective-security services.

3.2 Each Operator must be added to the platform by an authorized administrator of the Provider organization. Operators are individually responsible for the accuracy of information they submit.

4. Credential Attestation Warranty

4.1 The platform does not independently verify Operator credentials against the issuing licensing authority. Credential status displayed within the platform is self-attested by the Operator or by the Provider administrator who entered it.

4.2 Each Operator represents and warrants, on an ongoing basis, that: (a) all professional licenses, certifications, and credentials the Operator has entered or caused to be entered into the platform are true, current, and held in good standing; (b) the Operator holds any license required by the jurisdiction in which the Operator is performing services; and (c) the Operator will promptly update the platform if any credential lapses, is suspended, or is revoked.

4.3 The Provider organization is solely responsible for vetting and supervising its Operators, including verifying credentials independently of the platform. Arbiter disclaims any obligation to verify, and any liability arising from reliance on, self-attested credential data.

5. Acceptable Use; Prohibited Content

5.1 The Provider App may be used only for lawful protective-security, threat-intelligence, and operational-coordination purposes consistent with this Agreement.

5.2 Users must not post, transmit, or store content that is unlawful, threatening, harassing, defamatory, or that infringes the rights of any third party. Arbiter provides an in-app mechanism for reporting messaging content that violates this section and reserves the right to investigate reports and take appropriate action, including content removal, account suspension, or account termination, in its discretion.

5.3 Prohibited conduct includes, without limitation: impersonating another person or entity; using the platform’s OSINT or dossier features for stalking, harassment, or any purpose unrelated to a legitimate, active protective-security Engagement; and circumventing or attempting to circumvent the platform’s access, encryption, or audit controls.

6. Recording Features; Consent

6.1 Recording laws vary by state. If you are in a state requiring all-party consent, you are responsible for obtaining consent from all parties before recording. This notice is displayed persistently and non-blocking at both in-app recording surfaces.

6.2 Each Operator represents and warrants that the Operator has the right and authority to make any recording initiated through the platform, and takes sole responsibility for obtaining any consent required by applicable law from all recorded parties.

6.3 The Operator indemnifies and holds harmless Arbiter from and against any claim, loss, or liability arising from the Operator’s recording activity, including any failure to obtain required consent.

7. Intelligence Products; OSINT Use; FCRA-Prohibited Purposes

7.1 The platform’s research tools draw on a range of commercial and open-source data sources, including public-record databases, commercial data brokers, and open-source search tools (collectively, “OSINT Sources”), each operating under its own standard public terms. The current list of OSINT Sources is disclosed in Schedule A to the Client App Privacy Policy.

7.2 Intel Products are intended solely for use within an active, legitimate protective-security Engagement. Provider and each Operator represent, warrant, and covenant that no Intel Product, and no OSINT Source data obtained through the platform, will be used, in whole or in part, as a factor in establishing an individual’s eligibility for credit, employment, insurance, housing, or any other purpose that would cause the Intel Product to constitute a “consumer report” as defined by the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq. (“FCRA”). This restriction applies regardless of whether the underlying protective-security use is itself subject to FCRA.

7.3 Certain OSINT Sources impose their own contractual restrictions on permissible use, independent of FCRA — for example, SearchBug’s non-CRA subscription tier prohibits use for “any other purpose deemed to be a permissible purpose under the FCRA.” Provider and each Operator agree to comply with all such source-level restrictions. Arbiter does not make, and this platform does not solicit, a permissible-purpose representation on a per-query basis; Provider and Operator are solely responsible for establishing and documenting a lawful basis for each research request.

7.4 Intel Products exported as PDF are watermarked with engagement-identifying and recipient-identifying (“generated for”) attribution. Recipients of an exported Intel Product may not further distribute, publish, resell, or use the Intel Product outside the scope of the Engagement for which it was generated, and may not use it for any purpose prohibited under Section 7.2.

8. Bring-Your-Own-Key (“BYOK”) Provisions

8.1 The platform offers tiered encryption-key custody for certain Engagement data: an Arbiter-held key (standard), a Provider-held key in the Provider’s own external key-management system (“KMS”), and a Client-held key in the Client’s own external KMS. Where a Provider or Client elects to hold its own key in an external KMS, Arbiter retains ciphertext only and has no technical ability to decrypt the underlying data.

8.2 Risk arising from custody of an externally-held key — including key loss, misconfiguration, unavailability, or unauthorized revocation — is confined to the party holding that key. Arbiter is not responsible for data that becomes unreadable because an externally-held key is lost, destroyed, or revoked outside the platform.

8.3 Provider and Client each indemnify Arbiter for any claim arising from that party’s key-custody decisions or key-management failures, including claims by the other party or by any third party premised on inability to access encrypted content.

8.4 Provider and Client each acknowledge that where a litigation hold or comparable legal-preservation obligation applies to an Engagement, Arbiter cannot guarantee that content protected by an externally-held key will remain readable, because Arbiter cannot compel decryption of data it does not hold the key to. The party holding an external key is responsible for its own preservation obligations with respect to that key.

8.5 Keys held by Arbiter on the standard tier are not revocable in-app; they are destroyed only upon deletion of the associated Engagement or organization, subject to Section 9. Externally-held keys are revoked solely within the holder’s own KMS, outside Arbiter’s control; Arbiter will use commercially reasonable efforts to detect and provide logged notice of a change in an externally-held key’s health status but does not guarantee real-time detection.

9. Engagement and Account Deletion

9.1 An authorized administrator of either the Provider or the Client may unilaterally terminate an Engagement and initiate deletion of associated Engagement data. Deletion of Arbiter-held encryption keys occurs on a delay of not less than twenty-four (24) hours following the deletion request, during which the request may be reviewed or, where required by law, cancelled.

9.2 A logged notice of deletion is provided to the counterparty to the Engagement. This notice is a record of the deletion and does not require, and is not, the counterparty’s consent to the deletion.

9.3 Provider acknowledges that Engagement deletion is a significant, generally irreversible action with respect to Arbiter-held keys, and agrees that Arbiter bears no liability to Provider or any third party for data rendered permanently unreadable as a result of a deletion request made by an authorized administrator, whether that administrator is Provider’s own or the counterparty’s.

9.4 Deletion of a user account cascades to that user’s profile, credentials, assignments, and memberships, but does not delete the user’s operational contributions to an Engagement; those contributions are retained as part of the Provider’s operational record with authorship anonymized.

10. Indemnification

In addition to the specific indemnification obligations elsewhere in this Agreement, Provider agrees to indemnify, defend, and hold harmless Arbiter and its officers, directors, employees, and agents from and against any claim, liability, damage, loss, and expense (including reasonable attorneys’ fees) to the extent arising out of: (a) Provider’s or any Operator’s breach of this Agreement; (b) Provider’s or any Operator’s violation of applicable law, including data-protection and consumer-reporting law; (c) any Intel Product or OSINT use described in Section 7; or (d) Provider’s or any Operator’s acts or omissions in performing services under an Engagement. This indemnification obligation does not extend to any claim arising out of Arbiter’s own negligence, breach, or willful misconduct, and does not require Provider to indemnify Arbiter against punitive damages assessed against Arbiter.

11. Limitation of Liability

11.1 To the maximum extent permitted by law, in no event will Arbiter be liable for any indirect, incidental, consequential, special, or punitive damages, or for any loss of profits, revenue, or data, arising out of or related to this Agreement or use of the platform, even if advised of the possibility of such damages.

11.2 To the maximum extent permitted by law, Arbiter’s aggregate liability arising out of or related to this Agreement will not exceed the amount paid by Provider to Arbiter in the twelve (12) months preceding the claim.

11.3 Carve-Outs. The limitations in Sections 11.1 and 11.2 do not apply to: (a) either party’s breach of its data-protection or confidentiality obligations under this Agreement or applicable law; (b) either party’s indemnification obligations under Section 10 or Section 8.3; or (c) damages arising from gross negligence or willful misconduct.

12. Disclaimer of Warranties

The platform is provided “as is” and “as available.” Arbiter disclaims all warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. Arbiter does not warrant that the platform will be uninterrupted or error-free, or that all data will be permanently retained or recoverable, including data affected by the deletion and key-custody provisions of Sections 8 and 9.

13. Arbitration Agreement; Class Action Waiver

13.1 Binding Arbitration. Except for claims that qualify for small-claims court or claims for injunctive relief to protect intellectual property or confidential information, Provider and Arbiter agree that any dispute arising out of or relating to this Agreement will be resolved by binding individual arbitration administered by the American Arbitration Association (“AAA”) under its Commercial Arbitration Rules then in effect, rather than in court.

13.2 Class Action Waiver. Provider and Arbiter agree that any arbitration or proceeding will be conducted only on an individual basis and not as a class, collective, or representative action. The arbitrator has no authority to consolidate claims or preside over any form of representative proceeding.

13.3 Severability. If any part of this arbitration agreement or class action waiver is found unenforceable, that part will be severed and the remainder will still be enforced; this Agreement does not include a provision voiding the entire arbitration agreement if one part of the class action waiver is struck.

14. Term; Termination

This Agreement remains in effect for as long as Provider maintains an active account or Engagement on the platform. Either party may terminate as provided in Section 9. Sections 4, 6.3, 7, 8, 10, 11, 12, 13, and 16 survive termination.

15. Governing Law; Venue

This Agreement is governed by the laws of the State of Delaware, without regard to conflict-of-laws principles. Venue for any matter not subject to Section 13 lies exclusively in the state and federal courts located in New Castle County, Delaware.

16. Notices

Notices to Arbiter should be sent to legal@arbiterdefense.group or by mail at 1209 Orange Street, Wilmington, Delaware 19801. Notices to Provider will be sent to the contact information associated with the Provider’s account.

17. Miscellaneous

This Agreement, together with the Provider App Privacy Policy and any Provider Firm Master Services Agreement in effect between Provider and Arbiter, constitutes the entire agreement between the parties regarding the Provider App. If any provision is held unenforceable, the remaining provisions remain in full force. Arbiter may amend this Agreement; material changes will be reflected in a version-dated posting, and continued use after the effective date constitutes acceptance. This Agreement is not assignable by Provider without Arbiter’s prior written consent.

ARBITERby Arbiter Defense Group
Platform Operations Intel Client App Security Legal Request Demo
© 2026 ARBR INC. All rights reserved. platform.arbiterdefense.group