Security & data

How we handle your data

A plain-language summary of our current practices. If your organisation needs something specific written into an agreement, tell us and we will answer directly rather than guess.

Practices

What we do today

Access control

Every staff member signs in with their own account. Access to client records is limited by role, and access is removed the same day someone leaves the team.

Client data separation

Each client only sees their own projects, files, invoices and requests in the Passport portal. Separation is enforced at the database layer, not just in the interface.

Payments

Card payments are processed by Stripe. We never see or store full card numbers on our systems.

Transport security

The public site, the Passport portal and our internal workspace are served over HTTPS only.

Backups and recovery

Application data is backed up by our managed database provider. Website and store code is version controlled so we can roll back a bad release.

Change tracking

Sensitive actions inside our workspace are recorded with who did what and when, so account changes can be reviewed after the fact.

Reporting

Report a vulnerability

If you believe you have found a security issue in one of our properties, email info@prohub360.com with the words "security report" in the subject line, or call (800) 674-5153. Include the URL, what you observed and how to reproduce it. We acknowledge reports within two business days and will keep you updated until it is closed. Please do not run destructive tests or access data that is not yours.

Scope

What this page is and is not

This page describes the practices we operate today. It is not a certification, an audit result, or a compliance attestation, and it does not claim SOC 2, ISO, HIPAA or PCI status. For contractual data-processing terms, see our privacy policy and terms, or ask us for a written agreement covering your requirements.