Security
How dplmdpjvht protects your data · Last updated:
Draft — not yet effective. Prism Portal is pre-launch and the operating legal entity has not been formed. Items marked to be completed require counsel review before these pages are relied on commercially. Draft for review — confirm each control reflects your actual production deployment (hosting region, backup cadence, any certifications) before publishing to prospects. Remove claims you can't yet stand behind.
Shared Responsibility
We secure the platform and infrastructure; you are responsible for managing your users, roles, and the accuracy and legality of the data you upload. Together these keep your operation's data safe.
Authentication & Access Control
- Passwords hashed with industry-standard algorithms; optional two-factor authentication (TOTP).
- Optional single sign-on (Google), restricted to pre-provisioned accounts.
- Granular role-based access control across every module.
- Session protection and CSRF defenses on all state-changing requests.
- Time-limited, single-use tokens for password reset and team invitations.
Data Protection
- Integration credentials (Shopify, Walmart, Amazon, etc.) encrypted at rest.
- All traffic served over HTTPS/TLS.
- Security headers (X-Frame-Options, X-Content-Type-Options, CSP) on responses.
- Uploaded files are type- and size-validated and access-controlled.
- Input validation and concurrency-safe writes to protect data integrity.
Operational Security
- Automated daily database backups with rotating retention. Off-box backup copies are not yet enabled — backups currently reside on the same host as the Service. We are closing this gap before general availability.
- Full audit trail — every change is logged with user, action, and timestamp.
- Hosting: Amazon Web Services (AWS), US East (N. Virginia) —
us-east-1.
- Monitoring/uptime published at /status.
Incident Response
If we become aware of a security incident affecting your data, we will investigate, take remediation steps, and notify affected customers without undue delay as required by applicable law. [Define your notification timeline and contact process.]
Sub-processors
We use a limited set of vetted sub-processors (hosting, transactional email, and integrations you enable). See the Privacy Policy; a current list is available on request.
Compliance
[State any certifications or roadmap — e.g. SOC 2, ISO 27001 — only if accurate. Remove if none yet.]
Reporting a Vulnerability
Please report suspected security issues to hello@prismportal.cloud. We support responsible disclosure and will acknowledge and respond promptly.