A consolidated view of how Progull handles customer environments, data and incidents. Maintained by the Progull security team. Anything not stated here is available on request.
Architecture and controls being built to SOC 2 Type II. Audit will follow first design-partner deployments — no attestation exists yet.
ISMS being scoped alongside the platform build. Certification is on the post-pilot roadmap.
Platform is being designed to support GDPR-compliant data handling, DPAs and SCCs. Formal DPA templates will publish before the first paying customer.
BAA-readiness is on the post-pilot roadmap; not offered today.
Progull is architected to never store cardholder data. A documented descoping approach ships with v1.
Customers on Enterprise plans receive 30-day written notice of any sub-processor addition with a right to object.
PGP key available on request. Safe-harbour for good-faith research.
Standard DPA, SCCs and UK addendum available. Custom terms reviewable.
GDPR / CCPA access, rectification and deletion requests routed to the DPO.