For procurement and security review

What Arrowhead is accountable for, where the data boundaries sit, and how a security review actually runs. Answers your teams can act on, rather than badges.

The questions you have to answer internally

Architecture, responsibilities, and boundaries

Each answer below is already published elsewhere on this site, per solution and per service. It is collected here so a reviewer does not have to assemble it from nine pages.

What is the architecture?

A physical event is captured by RFID, barcode, mobile, printing, or vision hardware; Mobi turns the capture into an item record with the operational context configured for the deployment; your ERP, WMS, EAM, or CMMS remains the system of record and receives the result through the integration contract agreed in discovery.

Not published here: Hosting location and the deployment topology for your specific engagement are documented during the security review.

What is the deployment model?

Mobi Inventory is available today and is scoped to the sites, item records, and workflows named in the statement of work, with that scope written down in discovery rather than assumed. Integrations is Controlled Release. Generally available multi-facility stock balances are not part of either.

Who implements it?

Arrowhead supplies the hardware, configures readers, antennas, print formats, items, and workflows, installs the capture points, and delivers training. You provide network readiness, power and mounting, source-system data and its owner, operator time, and change windows.

Who is responsible for the hardware?

Arrowhead. Devices are supplied, staged, configured, and installed by Arrowhead, and repaired in-house at the Chandler depot as an authorized Zebra Elite Service Center. Onsite dispatch is available where a maintenance plan covers the device.

Who is responsible for the integration?

Arrowhead owns its side of the data contract defined in discovery: what is sent, in what shape, on what event. The system of record and its interface remain with their owner, so a fault on that side is diagnosed jointly rather than absorbed silently.

Where is the boundary between Mobi and our system of record?

Mobi holds observations — the identifier, the reader, the time, the signal — and the operational context that determines what an observation means. It does not become the master of your item, financial, or clinical data. Your system of record stays authoritative and stays with you.

Not published here: Data retention, deletion, and export terms for your engagement are set in the agreement, not published here.

What does support look like?

One intake path for device, printer, label, software, and integration issues. In-house depot repair in Chandler, Arizona. Onsite options where a maintenance plan covers the device. Published business hours are Monday to Friday, 8:00am to 5:00pm MST.

Not published here: Response targets and coverage hours are set by the service agreement you hold and are stated there.

How does a pilot work?

One site or one category, measured against acceptance criteria written during discovery, typically two to four weeks on site. If measured read rates or throughput miss the design targets, Arrowhead revises the design before a rollout is committed. Cost is quoted against the design rather than as a package, and is driven by the physical build — read points, devices, tags, and the labour around them — rather than by software licensing.

Can we speak to a reference?

Yes. Named references are made available during technical discovery, with the customer's permission and under your confidentiality terms. Arrowhead does not publish customer names or logos without written permission, which is why you will not find a logo wall on this site.

Security review

How Arrowhead answers your security review

Arrowhead answers your security review rather than asking you to accept a marketing page in place of one. What follows is the process, and what is genuinely available at each step.

  1. You send your questionnaire

    Your standard vendor security questionnaire, in your format. Arrowhead completes it against the deployment being scoped rather than against a generic product.

  2. Arrowhead answers in writing, under your terms

    Answers are provided under the confidentiality terms your procurement process requires. Where something is not in place, the answer says so rather than being written around.

  3. Architecture and data boundaries are documented

    What is captured, where it is held, what leaves the deployment, and what stays with your system of record — for the design in front of you, not in the abstract.

  4. Open items are named and owned

    Anything your review requires that Arrowhead cannot meet is identified with a named owner and a date, or identified as out of scope. It is not deferred silently.

Available on request

  • Completed security questionnaire, in your format
  • Architecture and data-boundary statement for the scoped deployment
  • Statement of work with the responsibility split named on both sides
  • Certificate of insurance and W-9
  • Zebra Elite Service Center authorization

Documents are provided during review under your confidentiality terms, not downloaded from this page.

What this page deliberately does not claim

Arrowhead does not publish certifications, service-level commitments, tenancy models, identity capabilities, retention periods, or recovery objectives on this site. Where one exists it belongs in a document your legal and security teams can rely on, and where one does not, saying so during review is the only honest answer. Ask, and you will get a straight response either way.

Software Arrowhead builds and runs

Can a hardware integrator really operate software?

A fair question, and the honest answer is not a customer logo — it is the systems Arrowhead runs for its own business every day. Each is demonstrable on request.

Arrowhead-operated system

Customer Portal

An authenticated, ERP-integrated portal Arrowhead runs for its own customers.

Passwordless access per user, invoices with NET-terms aging and printable statements, order tracking, stock, pricing agreements, and deal registration — reading from Arrowhead's own ERP rather than a static export.

Take a look
Arrowhead-operated system

Proposal Portal

A production document system that turns sales proposals into one locked standard.

Every commercial field is validated against the source document, the parsed source is treated as immutable, and an administrator override is audited rather than silent.

Arrowhead-operated system

Device qualification programs

A running program that configures, qualifies, and ships replacement devices at scale.

Devices are received and assigned by serial, the qualification guide is executed digitally with two independent technician signoffs, the completed documentation is generated on the customer's own official template, and each unit ships with its own tracking.

Arrowhead-operated system

Print and verify reporting

Label print jobs produce a verification report rather than an assurance.

Each report is an immutable, versioned snapshot — labels printed, labels verified good, the verdict, and any open anomalies — and it is delivered into the customer's own portal. The account it belongs to is resolved server-side from the authenticated session and is never accepted from the browser.

Arrowhead-operated system

RFID Workshop field app

A mobile field app Arrowhead built, in production use on iOS and Android today.

Pairs Zebra RFD-series sleds, captures inventory reads, verifies found and missing EPCs against an expected list, locates a tag with signal-guided feedback, and drives printer workflows. It reaches devices through TestFlight and a production APK, so it deploys through your MDM without waiting on a public listing.

Take a look
Arrowhead-operated system

Free GS1 tools

Three working tools, published free: a Digital Link generator, a Sunrise 2027 readiness checker, and label templates.

Built and maintained by Arrowhead, usable without an account or a sales conversation.

Take a look

These are Arrowhead's own systems, which is exactly why they can be shown without asking anyone's permission. They are evidence that Arrowhead builds, ships, and operates software — not a claim about what any of them would do in your environment. That is what discovery is for.

The vocabulary

What each label on this site means

Arrowhead delivering a system, a vendor publishing somebody else's result, a credential a third party issued us, software we run ourselves, a capability we offer, and a direction we have not shipped are six different things. They are labeled differently everywhere they appear.

  • Arrowhead-delivered result

    Arrowhead delivered the system and the result was measured in the customer's operation. Any partner that supplied part of the system is named.

  • Vendor-supported result

    A vendor published this result from a deployment another partner delivered. Arrowhead did not deliver it.

  • Accredited capability

    A credential or facility fact verified by a third party, such as an authorized service centre or a certified technician. Not a customer outcome.

  • General capability

    Something Arrowhead offers every customer. Not a customer outcome and not a promise about your operation.

  • Customer relationship

    A named account relationship. It says who we work with, never what was delivered or what it achieved.

  • Technology partner

    A vendor or partner relationship. Partner hardware in a building is not evidence that Arrowhead delivered that building's system.

  • Unpublished reference

    A real engagement we are not free to publish. Ask for the reference during discovery.

  • Arrowhead-operated system

    Software Arrowhead built and runs in production today, demonstrable on request. A fact about our own system, never a customer outcome.

  • Future direction

    Not available today. A direction, not a capability you can buy.

Only two of these may carry a number. A measured customer figure appears under Arrowhead-delivered result or Vendor-supported result and nowhere else. A percentage beside a capability is how a capability quietly becomes a result, so the build fails if one appears.

Reference policy

What we publish, and what we do not

Arrowhead has operated since 1989 and works with organizations that will not let a vendor put their name on a marketing page. Rather than publish logos we cannot substantiate, this is the policy.

What we publish

  • Customer results we can source, labeled with who delivered the system and who measured the result.
  • Industry references published by a technology vendor, labeled as that vendor's published result and not as ours.
  • Credentials a third party issued us, named with the body that issued them.
  • Software Arrowhead built and runs in production, demonstrable on request.

What we do not publish

  • A customer name or logo without written permission from that customer.
  • A result Arrowhead did not deliver, presented as though we did.
  • A metric next to a relationship, where the relationship is all the evidence supports.
  • A certification, service level, or security control we have not confirmed.

Named references are made available during technical discovery, with the customer's permission and under the confidentiality terms your procurement process requires.

Send us your security questionnaire

In your format, against the deployment being scoped. Where something is not in place, the answer will say so.

Start procurement review