# Security Overview Source: https://prolyticshq.com/trust/security Current content retained during the coming-soon period. Earlier launch offers are historical; this site provides no purchase or product login. Prolytics Limited Last updated: July 7, 2026 ## 1. Overview [#1-overview] This Security Overview describes the practices Prolytics Limited ("Prolytics," "we," "us," or "our") uses to protect Prolytics OS and customer data. Prolytics OS connects to product analytics, billing, reliability, and related business systems. Our security approach is based on minimizing unnecessary data storage, protecting credentials and service records, restricting access, monitoring reliability, and preserving customer-visible history needed for the product to function. No system can guarantee absolute security. This page describes our current MVP security posture and may be updated as the platform evolves. ## 2. Infrastructure [#2-infrastructure] Prolytics is hosted on Google Cloud infrastructure. Production infrastructure is deployed on a Google Cloud VM, with the production environment located in the United States, including us-west1 where configured. Production services may include: * application/API services; * worker processes; * maintenance processes; * managed PostgreSQL database services; * managed encrypted database backups; * monitoring and observability tools. ## 3. Data handling [#3-data-handling] Prolytics is designed to minimize unnecessary data storage while preserving records needed for product functionality, history, auditability, security, support, and billing. Prolytics may store: * account and organization records; * authentication session records; * provider credentials and connection state; * source identifiers where required for service records; * derived metrics and KPI summaries; * provider snapshots and evidence packs; * Health snapshots, alerts, Radar findings, watches, and issue workspace records; * Engine prompts, investigation history, evidence manifests, AI outputs, and visualizations; * Stripe billing, subscription, payment, credit, and event records; * service logs and operational records. Rebuildable provider snapshots and cache rows with explicit expiry are removed by retention cleanup. Raw Stripe webhook JSON stored in payment event records is redacted after 180 days. Canonical billing, payment, subscription, credit, tax, legal, and audit records are preserved as needed. Managed production database backups expire no later than 90 days after creation unless a legal hold or incident-preservation requirement applies. ## 4. Authentication [#4-authentication] User authentication may use: * magic link login; * GitHub login; * Google login. Authentication is implemented using Better Auth and related local application systems. Users are responsible for maintaining secure access to their accounts and connected third-party providers. ## 5. Credentials and connected sources [#5-credentials-and-connected-sources] Customers may connect third-party systems such as PostHog, Stripe, Sentry, and related business tools. Provider credentials, tokens, connector state, and mappings may be stored as service records to operate the platform. Access to connected-source data is limited to what is needed to provide the Services, subject to the permissions configured by the customer. Customers are responsible for granting appropriate scopes, removing unused integrations, and revoking access when needed. ## 6. Encryption [#6-encryption] Prolytics uses HTTPS and modern TLS for network communication. Managed production database backups are encrypted through the deployment's approved backup mechanism. Sensitive production access is restricted to authorized personnel and operational procedures. ## 7. Payments [#7-payments] Payments, subscriptions, invoices, and credit purchases are processed through Stripe. Prolytics does not store full payment card numbers or CVV codes. Stripe customer IDs, subscription IDs, payment IDs, invoice IDs, credit records, and related billing metadata may be stored for billing, tax, legal, audit, support, and product operation. ## 8. AI providers [#8-ai-providers] Prolytics may use Google Vertex AI/Gemini and Anthropic for AI-assisted features. Selected prompts, metrics, evidence packs, provider context, source metadata, and related service records may be sent to AI providers where needed to generate outputs. Production customer prompts, evidence packs, and AI outputs are not reused by Prolytics for model training or evaluation datasets by default. AI providers may process AI inputs and outputs according to their own service terms, data-processing terms, retention settings, abuse-monitoring rules, and customer configuration. ## 9. Monitoring and observability [#9-monitoring-and-observability] Prolytics may use tools such as Sentry and Better Stack for error monitoring, backend tracing, uptime monitoring, reliability diagnostics, and incident response. Operational diagnostics are intended to be aggregate or scoped. Operators should not place raw provider payloads in tickets, logs, or shared debugging records unless specifically required and authorized. ## 10. Backups and recovery [#10-backups-and-recovery] Production database backups are managed through the approved deployment backup mechanism. Managed production database backups must expire no later than 90 days after creation unless a legal hold or incident-preservation requirement applies. Operator-created logical backups must use approved procedures and must not be stored in Git, CI artifacts, application logs, or shared developer storage. Restore procedures are tested using isolated environments and controlled runbooks. ## 11. Incident response [#11-incident-response] Prolytics monitors for reliability and security issues through operational diagnostics, monitoring, and incident response procedures. If a security incident affects customer data, Prolytics will take steps to investigate, contain, remediate, and notify affected customers or authorities where required by law or contract. ## 12. Export and deletion [#12-export-and-deletion] Workspace export and deletion are support-assisted for MVP. Authorized operators may use scoped operational procedures to export workspace/application records or delete a tenant. Backup copies may remain until backup retention periods expire. Certain records may be retained where required or permitted for billing, tax, legal, security, fraud-prevention, dispute-resolution, audit, or legitimate business purposes. ## 13. Compliance status [#13-compliance-status] Prolytics does not claim SOC 2, ISO 27001, HIPAA, PCI DSS certification, or similar formal certification unless expressly stated in writing. Prolytics uses Stripe for payment processing and does not store full payment card numbers or CVV codes. Prolytics is not intended to store sensitive payment card data. The Services are not intended to process protected health information, sensitive payment card data, children's personal data, government IDs, special-category personal data, or other regulated sensitive data unless Prolytics agrees in writing. ## 14. Responsible disclosure [#14-responsible-disclosure] If you believe you have discovered a security vulnerability affecting Prolytics, contact us at: [legal@prolyticshq.com](mailto:legal@prolyticshq.com) Please include enough detail for us to understand and reproduce the issue. We ask that you avoid accessing, modifying, deleting, or exfiltrating data that does not belong to you. We appreciate responsible disclosure and will investigate reports promptly. ## 15. Contact [#15-contact] Prolytics Limited Website: prolyticshq.com Email: [legal@prolyticshq.com](mailto:legal@prolyticshq.com)