Security Policy
Last updated: July 20, 2025
This Security Policy describes the measures taken to protect the confidentiality, integrity, and availability of data processed through our platform and services. By using our services, you acknowledge that you have read and understood this policy.
1. Scope
This policy applies to all systems, infrastructure, applications, and processes operated by prospectivapy in connection with the delivery of its services. It covers data in transit, data at rest, and data processed on behalf of users and customers.
2. Data Protection Principles
We adhere to the following core principles when handling data:
- Data is collected only to the extent necessary for the stated purpose.
- Access to data is restricted to authorized personnel with a legitimate need.
- Data is retained only for as long as required to fulfill its purpose.
- Security controls are reviewed and updated on a regular basis.
3. Infrastructure Security
3.1 Hosting and Network
Our services are hosted on infrastructure that implements industry-standard physical and logical security controls. Network traffic is segmented and monitored. Firewalls and intrusion detection systems are in place to identify and respond to anomalous activity.
3.2 Encryption
All data transmitted between users and our platform is encrypted using TLS 1.2 or higher. Sensitive data stored at rest is encrypted using recognized encryption standards. Encryption keys are managed securely and rotated periodically.
3.3 Availability and Redundancy
We maintain redundant systems and regular backups to minimize the risk of data loss or service disruption. Backup integrity is tested on a scheduled basis. Disaster recovery procedures are documented and reviewed periodically.
4. Access Control
4.1 Internal Access
Access to production systems and customer data is granted on a least-privilege basis. All internal access is authenticated and logged. Privileged access requires additional verification steps.
4.2 User Authentication
Users are required to authenticate before accessing protected areas of the platform. We support and encourage the use of strong passwords and multi-factor authentication where available. Session tokens are invalidated upon logout and expire after a defined period of inactivity.
4.3 Third-Party Access
Third-party service providers who require access to our systems are subject to security assessments and are bound by contractual obligations to maintain appropriate security standards.
5. Application Security
5.1 Secure Development
Security is considered throughout the software development lifecycle. Code changes are reviewed before deployment. We apply security patches and updates in a timely manner following responsible disclosure or vendor notification.
5.2 Vulnerability Management
We conduct periodic vulnerability assessments of our systems and applications. Identified vulnerabilities are prioritized and remediated according to their severity. Critical vulnerabilities are addressed as a matter of urgency.
5.3 Penetration Testing
We engage in periodic security testing, including penetration testing, to identify weaknesses before they can be exploited. Findings are tracked and resolved through our internal remediation process.
6. Incident Response
We maintain a documented incident response process that covers detection, containment, investigation, and recovery. In the event of a confirmed security incident that affects user data, affected parties will be notified in accordance with applicable obligations and without undue delay.
To report a suspected security incident or vulnerability, contact us at help@prospectivapy.com.
7. Employee Security
All personnel with access to systems or data are subject to security awareness training. Background checks are conducted where appropriate and permitted. Employees are required to adhere to internal security policies and procedures. Access is revoked promptly upon termination of employment or contract.
8. Physical Security
Physical access to facilities housing our infrastructure is restricted to authorized individuals. Environmental controls are in place to protect hardware from damage caused by power fluctuation, temperature, or unauthorized physical access.
9. Monitoring and Logging
System activity, access events, and security-relevant actions are logged and retained for a defined period. Logs are protected against unauthorized modification. We monitor systems continuously for signs of unauthorized access or unusual behavior.
10. Responsible Disclosure
We welcome reports from security researchers and the broader community. If you believe you have identified a security vulnerability in our platform, please contact us at help@prospectivapy.com before disclosing it publicly. We commit to acknowledging reports promptly and working toward resolution in good faith.
Please include the following in your report:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce the issue.
- Any relevant technical details, screenshots, or proof-of-concept code.
11. Third-Party Services
We may use third-party tools and services to support platform functionality. These providers are evaluated for their security posture prior to engagement. We do not share data with third parties beyond what is necessary for service delivery.
12. Compliance
We maintain security practices aligned with widely recognized industry standards and frameworks. Our security program is reviewed periodically to reflect changes in the threat landscape, technology, and operational requirements.
13. Policy Review
This Security Policy is reviewed at least annually and updated as necessary. Continued use of our services following any update constitutes acceptance of the revised policy. We encourage users to review this page periodically.
14. Contact
For questions or concerns regarding this Security Policy, please contact us:
Prospectivapy
Sõlme 15, 11612 Tallinn, Estonia
Email: help@prospectivapy.com
Phone: +3724330222