Security at Prometrix

Protecting your data is at the core of everything we build. We follow best-in-class practices to ensure that your personal, marketing, and business data remains secure and confidential.

Last Updated: May 24, 2025

GDPR Compliant
SOC 2 In Progress
ISO 27001 Infrastructure

Our Security Philosophy

We adopt a "Security by Design" and "Privacy by Default" approach, building security and privacy considerations into every level of our architecture.

Security by Design

Security isn't an afterthought – it's built into our architecture from the ground up, from code to cloud infrastructure.

Data Encryption

  • TLS 1.3 for data in transit
  • AES-256 for data at rest
  • Tokenized secrets & API keys

Authentication & Access

  • Multi-Factor Authentication (MFA)
  • Role-Based Access Control (RBAC)
  • Session timeouts & IP restrictions

Infrastructure Security

  • ISO 27001-certified cloud platforms
  • Virtual Private Cloud (VPC)
  • Regular patching & hardened OS

Application Security

  • Regular penetration testing
  • OWASP Top 10 best practices
  • Rate limiting & bot detection

Security Monitoring

  • 24/7 real-time monitoring
  • SIEM tools for log correlation
  • Automated incident response

Business Continuity

  • Daily encrypted backups
  • Multi-zone deployment
  • Quarterly DR testing

Compliance & Certifications

We adhere to the following standards and frameworks to ensure your data is handled with the highest level of care and compliance.

GDPR

Full compliance for all EU users with comprehensive data protection rights.

CCPA

Rights and transparency for California users with comprehensive privacy controls.

SOC 2

Type I/II certification in progress for Prometrix enterprise systems.

ISO/IEC 27001

Our infrastructure providers are certified under this international standard.

Responsible Disclosure

We welcome reports of potential vulnerabilities from the security community. Our responsible disclosure program ensures that security issues are handled professionally and transparently.

Bug Bounty Program

Eligible reports may qualify for rewards under our private bug bounty program. We recognize and reward security researchers who help us maintain the highest standards of security.

Rewards available for qualifying submissions
Professional and timely response
Coordinated disclosure process
Recognition for valid findings

Report a Security Issue

security@prometrix.ai

🔒 Encrypted communications welcome
PGP key available upon request

Have Questions About Our Security?

Our security team is here to answer any questions about our practices, compliance, or how we protect your data.