Trust & Safety
1.Our Commitment
ProPera Online builds security operations software, so trust is not an afterthought - it is the product. This page describes how we protect your environment, your data and your organisation while you use the ProPera Online security operations platform.
2.Security Programme
- Encryption: data is encrypted in transit (TLS 1.2 or higher) and at rest using industry-standard encryption.
- Access control: role-based access control (RBAC) across all platform roles; least-privilege administration; multi-factor authentication supported and encouraged for all accounts.
- Secrets management: customer credentials are encrypted at rest and are never written to logs. The platform supports managed identity and certificate-based authentication to avoid standing secrets.
- Audit logging: security-relevant events are recorded in an audit trail that cannot be modified by regular users, supporting investigation and compliance evidence.
- Vulnerability management: we track, prioritise and remediate vulnerabilities in our code and dependencies, and run security testing on a regular basis.
- Development practice: code review, automated tests, dependency scanning and safe deployment practices are part of our engineering workflow.
3.Data Protection
- Customer Data is processed only to provide the Service and is never sold.
- Data is retained for the minimum period needed and securely deleted afterwards, per our Privacy Policy.
- You can export your data at any time.
- We limit employee access to customer data to what is strictly necessary, with access logged and reviewed.
4.Tenant Isolation
The Service is multi-tenant. Each customer workspace is logically isolated so that one customer's data, configuration and credentials are never visible to another customer. Tenant boundaries are enforced at the application layer and verified as part of our testing and audit activities.
5.Automation Safety
Because the Service can take action in your environment - such as isolating a device, blocking an indicator or applying a patch - we build safety into automated response:
- Approval workflows: destructive or high-impact actions require administrator approval before they execute.
- Consent gating: endpoint remediation only runs after an administrator grants explicit consent (cloud + domain).
- Change controls: registry and configuration changes are flagged, and users are warned before they are applied.
- Least privilege: the platform requests only the permissions it needs, and you control which connectors and scopes are granted.
- Full audit trail: every automated action is recorded with actor, timestamp, target and result, so nothing happens invisibly.
You remain in control: you decide what the platform may do automatically and what must wait for approval.
6.Incident Response
We maintain an incident-response plan covering security incidents affecting the Service. Our commitments:
- detect and contain incidents promptly;
- investigate root cause and impact;
- remediate and verify; and
- notify affected customers and regulators as required by law and our commercial commitments.
Security incidents that put customer data at real risk of serious harm are reported in line with applicable breach-notification law. Operational status is published on our System Status page.
7.Responsible Disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in the Service, please report it privately to info@propera.online with enough detail for us to reproduce it. We ask that you:
- do not access, modify or destroy data you do not own;
- do not disrupt the Service or other users;
- give us a reasonable period to fix the issue before disclosing it publicly; and
- do not test other people's accounts or production customer data.
We will acknowledge reports promptly, keep you informed of remediation, and never take legal action against good-faith researchers who follow this policy. If you wish, we will credit you in our acknowledgements.
8.Abuse & Fair Use
We prohibit use of the Service for unlawful activity, attacks against third parties, or any use that violates our Terms & Conditions. If we become aware of abuse - including attempts to bypass tenant isolation, brute-force logins, credential stuffing or scanning of the platform - we will investigate and may suspend the offending account while we do so. You can report suspected abuse to info@propera.online.
9.Compliance & Standards
We align our controls with recognised frameworks including NIST Cybersecurity Framework, CIS Controls, ISO/IEC 27001 principles and, where applicable, NZISM, IRAP, SOC 2 and GDPR. The Service maps detections to MITRE ATT&CK and supports CIS/NIST control mapping to help your organisation evidence compliance. For framework-specific evidence, contact us and we will provide what we can under confidentiality.
Government and public-sector customers can request compliance documentation (for example security assessment questionnaires) as part of the procurement process.
10.Contact
For security or trust questions: info@propera.online. For urgent security incidents, email with "[SECURITY]" in the subject line and we will prioritise it.
Questions about this security & trust?
Email us at info@propera.online and we will respond as soon as we can.
ProPera Online · Security Operations Platform