Security
Your data stays in the EU, encrypted in transit and at rest
Prduct runs on AWS infrastructure inside the European Union. Traffic is encrypted with TLS 1.2 or higher, stored data with AES-256, and every access is logged. This page sets out which controls are in place today and which are still being built.
- EU-only hosting
- TLS 1.2+ in transit
- AES-256 at rest
- Malware scanning on every upload
- SSO with Entra ID
Data residency
Hosted in the EU, and nowhere else
All customer data is stored and processed in AWS regions inside the European Union. Backups stay in EU availability zones, and no customer data is stored outside the EU.
- AWS regions eu-north-1 (Stockholm) and eu-central-1 (Frankfurt)
- Backup copies held in availability zones separate from the primary data
- An availability zone is one or more physically separate data centres with independent power, networking and connectivity
- Where a sub-processor processes data outside the EU, the EU Standard Contractual Clauses apply, listed in the sub-processor list
- Enterprise customers can agree specific data residency requirements in their enterprise agreement
Encryption
Encrypted in transit and at rest
Traffic between your browser and the Platform is protected with TLS 1.2 or higher, and older protocols are refused. Stored data, uploaded documents, backups and log files are encrypted with AES-256.
- TLS 1.2 or higher on every connection, with weaker protocols blocked
- AES-256 encryption at rest for the database, file uploads, backups and logs
- Database access runs through an SSH-encrypted jumpbox, on top of standard authentication
- Encrypted storage means that compromised media stays unreadable without the keys
Access control
Least privilege, enforced by role
Every user has an individual account, every role is scoped to the data it needs, and administrative access requires two-factor authentication. Organisations can sign in with single sign-on through Microsoft Entra ID using OpenID Connect.
- Single sign-on through Microsoft Entra ID using OpenID Connect
- Two-factor authentication available to every user and required for all administrative access
- Individual accounts only; credentials are never shared
- Minimum 12-character passwords with complexity requirements and automatic session timeouts
- Role-based access control with least privilege, regular access reviews and immediate revocation when people leave
- Inside your workspace you set fine-grained permissions, including exactly what each supplier connection can see
Monitoring and logging
Every access is logged
Authentication, data access, administrative actions, system errors and API patterns are logged, with continuous threat detection across the infrastructure through AWS GuardDuty and AWS Security Hub. Every file that enters the Platform is scanned for malware.
- AWS GuardDuty for continuous threat detection, with malware scanning of every uploaded file and every email attachment
- AWS Security Hub for centralised security findings
- Continuous monitoring for unauthorised activity, network intrusion detection and DNS query logging
- Audit trails covering logins, data access and modification, administrative actions and API access patterns
- Security patches applied on release, with a monthly review of advisories, IAM policies, security groups and network configuration
Backup and recovery
Encrypted backups, tested restores
Backups are encrypted to the same standard as production data, held in availability zones separate from the primary data, and restoration procedures are tested. What you are entitled to depends on your subscription tier, as set out in Schedule 1.
Starter and Plus
Encrypted backups
Regular automated backups held in separate EU availability zones.
Premium
Geo-redundant
Backups replicated across EU regions, in addition to encrypted storage.
Enterprise
365 days
Continuous backups, with recovery guaranteed for data from the preceding 365 days.
Compliance
Standards we work to
Some of these commitments are ours and some are inherited from the infrastructure we run on. Each card says which.
ISO 27001
In progressOur security controls are built to the ISO 27001:2013/2022 framework. Formal certification is under way; this page carries the current status rather than our contracts.
Ask for the current statusGDPR
In placeA published Data Processing Agreement, documented processing instructions, the EU Standard Contractual Clauses for any transfer outside the EU, and data protection impact assessments.
Read the DPAAWS certifications
InheritedOur hosting inherits ISO 27001, 27017 and 27018, SOC 1, SOC 2 and SOC 3, PCI DSS and C5 from AWS, whose data centres provide multi-layer physical security.
AWS compliance programmesSub-processors
PublishedEvery third party that processes personal data on your behalf is listed with its purpose, processing location and scope, and changes are notified 30 days in advance.
See the listSecurity testing
What is in place, and what is next
We would rather be precise about our maturity than imply a testing programme we do not yet run.
In place today
- Continuous vulnerability scanning through AWS Inspector
- Security reviews of infrastructure and applications
- Security code reviews
- Monthly review of security advisories, IAM policies and security groups
- Periodic AWS Security Hub assessment reviews and network configuration audits
Planned
- Annual third-party penetration testing
- Recurring formal vulnerability assessments
- External compliance audits, with reports available to Premium and Enterprise customers on request
Shared responsibility
Security is a shared responsibility
We secure the Platform and the infrastructure it runs on. You decide who inside your organisation, and inside your supply chain, can see what.
Contact
Reporting a security issue
If you believe you have found a vulnerability, write to us. We investigate every report and confirm receipt. Please give us a reasonable period to remediate before disclosing publicly, and do not access, alter or extract other customers' data while testing.
- Vulnerability reports security@prduct.com
- Data protection and DPO dpo@prduct.com
- Contracts and legal legal@prduct.com
Security questions we are asked
Where is our data stored?
Are you ISO 27001 certified?
Do you run penetration tests?
Are uploaded files scanned for malware?
Do you support single sign-on?
Can we audit you?
Who else processes our data?
How quickly are we told about a breach?
Bring us your supplier list and your hardest regulation. In 45 minutes you'll see your own data in Prduct - not a generic demo.