Security Overview
Public security and credential-protection information
01. Security Approach
Prolter is designed for freelancers, agencies, and business users who need to manage clients, projects, digital assets, team access, and sensitive credentials in one workspace.
Security is treated as a shared responsibility. Prolter implements safeguards within the Services, while customers remain responsible for account security, user permissions, and the security of their own devices and third-party systems.
02. Credential Protection
Prolter supports storage of sensitive credentials such as passwords, API keys, tokens, usernames, hosting information, and related access information.
03. Encryption and Transport Security
Prolter uses encrypted network connections for communications between users and the Services and uses encryption to protect sensitive stored information. Specific cryptographic algorithms and key-management details may change as the platform evolves and are not treated as a guarantee of a particular implementation.
04. Access Controls
- Authentication is required to access protected workspace functionality.
- Workspace and role-based permissions are used to control access to customer information.
- Customers are responsible for assigning appropriate roles to employees, contractors, clients, and other users.
- Administrative access is restricted to authorized personnel and service mechanisms.
05. Activity and Audit Logging
Prolter may record authentication, workspace, asset, project, task, permission, security, and other relevant events to support auditing, troubleshooting, abuse prevention, incident investigation, and service operation.
06. Hosting and Infrastructure
Prolter’s primary application and database infrastructure is currently hosted through OVHcloud in Germany. Infrastructure providers and server locations may change as the Services evolve, subject to applicable law and security standards.
07. Backups and Availability
Prolter may maintain backups and recovery mechanisms appropriate to the Services. Backups are intended to support operational recovery and do not replace a customer’s independent backup responsibilities.
Prolter does not guarantee uninterrupted availability or that every item of Customer Data can always be recovered.
08. Security Incident Response
Prolter maintains processes intended to identify, investigate, contain, and remediate security incidents. Where a confirmed incident creates notification obligations under applicable law, Prolter will make the required notifications or cooperate with affected customers as required.
09. Customer Security Responsibilities
As part of the shared responsibility model, customers are responsible for:
- Using strong, unique account credentials;
- Protecting the email account and devices used to access Prolter;
- Using available multi-factor authentication or additional security controls where provided;
- Assigning only the permissions required for each team member or contractor;
- Removing access promptly when a person leaves a project or organization;
- Rotating or revoking third-party credentials immediately if compromise is suspected;
- Maintaining independent backups or recovery methods for critical systems.
10. Responsible Disclosure
If you believe you have discovered a security vulnerability affecting Prolter, please report it privately to [email protected] with sufficient information to reproduce the issue. Do not publicly disclose sensitive vulnerability details before Prolter has had a reasonable opportunity to investigate and address the issue.
11. Important Security Disclaimer
No internet-connected service can guarantee absolute security.
Prolter’s security statements describe measures designed to reduce risk; they are not a guarantee that Customer Data, Credentials, accounts, or infrastructure will never be compromised.
12. Contact Information
For questions regarding our security architecture or to submit a report: