Principles
- Collect less. We keep only what the platform needs to do its job.
- Least privilege. People and systems get the narrowest access that works.
- Read-only where possible. Our bookkeeping connection to our own bank accounts can read transactions and cannot move money.
- A person confirms. Automated document reading never marks a field verified by itself.
Encryption
- Every page and API is served over HTTPS (TLS 1.2 or higher). Plain HTTP is redirected.
- Data at rest is encrypted by our hosting and database providers.
- API tokens and bank-connection tokens are also encrypted by us before storage, with AES-GCM and keys held outside the database.
- Documents are stored with a SHA-256 fingerprint so any later change to a file can be detected.
Access control
- No public sign-up. Accounts are created by invitation from an administrator.
- Invitation links are single-use and expire.
- Role-based permissions decide what each user can see and change. Sensitive fields, such as phone numbers, can be hidden from roles that don't need them.
- Sign-in attempts are rate-limited, and sessions use secure, HTTP-only cookies.
- Internal company systems add a trusted-device check and a PIN on top of the invitation.
- Access for a person who leaves is removed the same day.
Application security
- Incoming webhooks from carriers and form providers are signature-checked, and replays are rejected.
- Strict Content Security Policy and security headers on our applications.
- Changes to client records and administrative actions are logged with the user and time.
- Code changes go through version control with automated type checks and tests before deployment.
- Production secrets live in our providers' secret stores, never in source code.
Financial data
Prodigyflo LLC does not process payments, hold customer funds, or store payment card numbers.
For our own bookkeeping, we connect Prodigyflo LLC's business bank accounts through Plaid with read-only access to balances and transactions. That data is used only for the company's accounting and tax records, is visible only to the company's members, and is never shared with customers or sold. Account numbers are masked to the last four digits wherever they're shown.
Vendors
We use established providers and give each one only the access it needs.
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, DNS, network protection, databases and file storage |
| Vercel | Hosting for the ProdigyFlo web application |
| Twilio | Business calling and text messaging |
| Plaid | Read-only connection to the company's own bank accounts for bookkeeping |
| GitHub | Private source-code hosting |
Incidents
If we learn that customer data was accessed without authorization, we contain it, investigate, and notify affected customers without undue delay, within the time required by law, including Nevada's security-breach law (NRS 603A). Customers get a written summary of what happened and what we changed.
Report a problem
If you find a security issue, email support@prodigyflo.ai with "Security" in the subject. We reply within two business days. Please don't access data that isn't yours or disrupt the service while testing.