Security Center
Your customer relationship data is critical. We build security into our architecture, pipeline testing, dependency validation, and vulnerability disclosures.
Secure by design.
We prioritize security compliance across code authorship, dependencies, data storage, and access tokens.
Data Encryption
All customer records, credentials, and API secret keys are encrypted at rest using AES-256 and in transit via TLS 1.3.
Granular RBAC
Granular roles, teams, and field-level permission structures block unauthorized access and prevent accidental data disclosure.
Security Auditing
Our automated build pipeline runs static application security testing (SAST) and software composition analysis (SCA) on every commit.
Supply Chain Security
We pin dependencies to exact hashes, compile secure binaries, and publish regular Software Bills of Materials (SBOMs).
Responsible Disclosure Policy
We value the work of security researchers who help keep ProInsights safe. If you find a security vulnerability, we ask that you disclose it to us privately to give us time to verify, patch, and release a fix.
Disclosure Steps:
- Submit via Email: Send a description of the vulnerability, reproduction steps, and impact to security@proinsights.io.
- Validation & Response: We will acknowledge your submission within 24 hours and verify the impact.
- Release Patch: If verified, we will develop a patch and coordinate the public release timeline.
- Credit: We will credit your name or company in our release changelog.
Security FAQ
How do I report a security vulnerability?
Please do NOT open a public issue. Email security reports directly to security@proinsights.io. We coordinate responsible disclosures and release patches within 48 hours of verification.
Are database backups encrypted?
Yes. All database backups generated by our scheduler are encrypted using AES-256 GCM before transit to S3 or remote storage targets.
Does ProInsights support Single Sign-On (SSO)?
Yes, our enterprise plan features native SAML 2.0 and OIDC integrations to connect with Okta, Active Directory, and Google Workspace.