BOWTY Expert Security Policy
Version 1.0 · Last updated in October 2026
1. The software you install
- Signed builds. The macOS app and its disk image are signed with Arborion Global's Apple Developer ID (team G877G6T4PP), notarized by Apple and stapled. macOS refuses to open a copy that has been altered. The Windows installer and portable version are to be code-signed with Arborion Global's certificate; until they are, Windows may show a SmartScreen notice when they are first run, and Smart App Control or company policy may block them. Versions installed from the Microsoft Store are signed by Microsoft. The download page publishes the SHA-256 checksum of every file so that you can check a download.
- Hardened application. BOWTY Expert's own code is bundled and packaged in an archive whose integrity is checked when the app starts. The windows that display your bow ties run in a sandbox with a strict content security policy, cannot load remote content, and cannot open links except to an approved list of Arborion, sign-in and payment addresses. Development and debugging switches are disabled in release builds.
- Sign-in. You sign in inside BOWTY Expert with your Arborion account. BOWTY Expert sends your password only to Arborion Accounts (accounts.arborionglobal.com), over an encrypted connection, and never stores it; Arborion Accounts keeps only a one-way hash of it. The licensing service never receives your password: it accepts only a fresh, single-use sign-in confirmation signed by Arborion Accounts for BOWTY Expert, and asks for your password again after one of your computers has been released.
- Licence protection.
- Each computer is activated once. The activation is bound to that computer by one-way hashes of its identifiers, and a copy on another computer is rejected.
- Licences are checked with leases that are digitally signed (Ed25519) by the licensing service, valid for up to seven days offline and renewed online at least every seven days. BOWTY Expert also tries to renew the lease after each update.
- A lease or checkpoint cannot be forged or altered without Arborion Global's private signing key, which is generated and kept in Azure Key Vault and never stored on a developer's computer. Earlier public keys stay in BOWTY Expert so that older signed checkpoints remain verifiable after a key is replaced.
- Setting the computer's clock back is detected.
- The licence record and your Arborion account session on your computer are encrypted with your operating system's protected storage (the macOS Keychain or Windows data protection). Windows data protection protects them from other users of the computer, not from other programs running under your own user account.
- No remote access. BOWTY Expert does not listen on the network, does not download or execute code, and has no remote-control or telemetry features. Its own network connections are to Arborion Accounts (to sign in), the licensing service and, for copies installed from our website, a check for new versions that reads a public file from our download storage; all use HTTPS. Checkout opens in your web browser. Updates are never installed automatically: BOWTY Expert tells you a new version exists and opens the download page.
- Local files. Licence state, crash-recovery copies and temporary files are kept in your user profile and are readable only by your user account.
2. The licensing service
- Hosted on Microsoft Azure in the Central India region and reachable only over HTTPS.
- Device sessions are stored only as one-way (SHA-256) hashes, and verification codes only as hashes that expire after 15 minutes. Computers are identified only by one-way hashes of their identifiers.
- Signing keys and other secrets are kept in Azure Key Vault.
- Requests are rate-limited.
- Staff access requires an individual staff account with a role, and a second factor (a time-based one-time code) for every administrative session. Every staff action is recorded in an audit log.
- Records are backed up regularly. Licensing and billing events, invoices and credit notes are also written to write-once storage, so that records can be restored after a failure and cannot be altered.
- Access is limited to authorised Arborion Global staff.
3. Your part
Security also depends on the environment BOWTY Expert runs in. We recommend that you:
- keep your operating system updated;
- use disk encryption and screen locks;
- restrict who can read and change the folders that hold your bow ties;
- keep backups;
- install BOWTY Expert only from www.arborionglobal.com/bowty/download, the Microsoft Store once BOWTY Expert is listed there, or your organisation's software distribution, and check the SHA-256 of a downloaded file;
- keep your password to yourself and do not reuse it from other services;
- treat verification and password reset codes as confidential.
4. Reporting a vulnerability
Please report suspected vulnerabilities to support@arborionglobal.com. Include the BOWTY Expert version, your operating system, the steps to reproduce, and the likely impact.
We will acknowledge your report promptly and keep you informed while we investigate. Please do not disclose the issue publicly until a fix is available. Security fixes are released as updates of BOWTY Expert and of the licensing service. We do not take action against good-faith research that respects these rules and does not access other people's data.
5. Incidents
If a security incident affects personal data we hold (see the BOWTY Expert Privacy Statement), we will notify affected customers and the authorities as the law requires. We aim to do so without undue delay and, where applicable, within 72 hours of becoming aware of it.