At PROMTP, security is our top priority. We implement industry-leading security measures to protect your data and ensure the integrity of our platform.
Data Encryption
All data is encrypted both in transit and at rest. We use TLS 1.3 for data transmission and AES-256 encryption for stored data. Your sensitive information is protected using the same encryption standards used by banks and financial institutions.
Authentication & Access Control
We use enterprise-grade authentication powered by Supabase:
- Secure password hashing using bcrypt
- Email verification for new accounts
- Session management with automatic timeout
- Row-level security to ensure data isolation between users
- Organization-based access controls
Database Security
Our database infrastructure is designed with security at every layer:
- Automated daily backups with point-in-time recovery
- Database replication for high availability
- Network isolation and firewall protection
- Regular security patches and updates
- SQL injection prevention through parameterized queries
Privacy & Data Protection
Your data belongs to you, and we respect your privacy:
- We never sell or share your data with third parties
- Payment information is handled exclusively by Stripe (PCI-DSS compliant)
- We collect only the minimum data necessary to provide our service
- You can export or delete your data at any time
- GDPR and CCPA compliant data handling
Application Security
We follow secure development practices:
- Regular security audits and penetration testing
- Input validation and sanitization to prevent XSS attacks
- CSRF protection on all state-changing operations
- Content Security Policy (CSP) headers
- Dependency scanning for vulnerable packages
- Secure API design with rate limiting
Incident Response
We have a comprehensive incident response plan in place:
- 24/7 monitoring and alerting for security events
- Rapid response team for security incidents
- Transparent communication with affected users
- Post-incident analysis and remediation
Infrastructure & Hosting
PROMTP is built on trusted, secure infrastructure:
- Supabase: Enterprise-grade PostgreSQL database with built-in security
- Vercel/AWS: SOC 2 compliant hosting infrastructure
- Stripe: PCI-DSS Level 1 certified payment processing
- Edge Functions: Serverless functions with isolated execution environments
Compliance
We adhere to industry standards and regulations:
- GDPR (General Data Protection Regulation) compliant
- CCPA (California Consumer Privacy Act) compliant
- SOC 2 Type II standards
- Regular third-party security assessments
Best Practices for Users
Help us keep your account secure:
- Use a strong, unique password
- Never share your login credentials
- Log out when using shared devices
- Review your account activity regularly
- Report suspicious activity immediately
Report a Security Issue
If you discover a security vulnerability, please report it responsibly:
Email: security@promtp.com
We take all security reports seriously and will respond promptly. We appreciate responsible disclosure and will work with you to address any issues quickly.