Trust & Security

Security Overview

Public security and credential-protection information

Effective Date: September 14, 2026Status: Active

01. Security Approach

Prolter is designed for freelancers, agencies, and business users who need to manage clients, projects, digital assets, team access, and sensitive credentials in one workspace.

Security is treated as a shared responsibility. Prolter implements safeguards within the Services, while customers remain responsible for account security, user permissions, and the security of their own devices and third-party systems.

02. Credential Protection

Prolter supports storage of sensitive credentials such as passwords, API keys, tokens, usernames, hosting information, and related access information.

Sensitive stored credentials are protected using encryption.
Credentials are not intentionally stored in ordinary plaintext database fields.
Credential access requires an authenticated and appropriately authorized user session.
When an authorized user explicitly requests a credential through the interface, the application may decrypt the credential server-side and return it to the authorized browser session.
Access and security-related actions may be recorded in audit/activity logs.

03. Encryption and Transport Security

Prolter uses encrypted network connections for communications between users and the Services and uses encryption to protect sensitive stored information. Specific cryptographic algorithms and key-management details may change as the platform evolves and are not treated as a guarantee of a particular implementation.

04. Access Controls

  • Authentication is required to access protected workspace functionality.
  • Workspace and role-based permissions are used to control access to customer information.
  • Customers are responsible for assigning appropriate roles to employees, contractors, clients, and other users.
  • Administrative access is restricted to authorized personnel and service mechanisms.

05. Activity and Audit Logging

Prolter may record authentication, workspace, asset, project, task, permission, security, and other relevant events to support auditing, troubleshooting, abuse prevention, incident investigation, and service operation.

06. Hosting and Infrastructure

Prolter’s primary application and database infrastructure is currently hosted through OVHcloud in Germany. Infrastructure providers and server locations may change as the Services evolve, subject to applicable law and security standards.

07. Backups and Availability

Prolter may maintain backups and recovery mechanisms appropriate to the Services. Backups are intended to support operational recovery and do not replace a customer’s independent backup responsibilities.

Prolter does not guarantee uninterrupted availability or that every item of Customer Data can always be recovered.

08. Security Incident Response

Prolter maintains processes intended to identify, investigate, contain, and remediate security incidents. Where a confirmed incident creates notification obligations under applicable law, Prolter will make the required notifications or cooperate with affected customers as required.

09. Customer Security Responsibilities

As part of the shared responsibility model, customers are responsible for:

  • Using strong, unique account credentials;
  • Protecting the email account and devices used to access Prolter;
  • Using available multi-factor authentication or additional security controls where provided;
  • Assigning only the permissions required for each team member or contractor;
  • Removing access promptly when a person leaves a project or organization;
  • Rotating or revoking third-party credentials immediately if compromise is suspected;
  • Maintaining independent backups or recovery methods for critical systems.

10. Responsible Disclosure

If you believe you have discovered a security vulnerability affecting Prolter, please report it privately to [email protected] with sufficient information to reproduce the issue. Do not publicly disclose sensitive vulnerability details before Prolter has had a reasonable opportunity to investigate and address the issue.

11. Important Security Disclaimer

No internet-connected service can guarantee absolute security.

Prolter’s security statements describe measures designed to reduce risk; they are not a guarantee that Customer Data, Credentials, accounts, or infrastructure will never be compromised.

12. Contact Information

For questions regarding our security architecture or to submit a report:

Prolter Security Team
Security Contact: [email protected]
Security reports are prioritized and investigated promptly by our engineering team.