Access control
Every staff member signs in with their own account. Access to client records is limited by role, and access is removed the same day someone leaves the team.
Security & data
A plain-language summary of our current practices. If your organisation needs something specific written into an agreement, tell us and we will answer directly rather than guess.
Practices
Every staff member signs in with their own account. Access to client records is limited by role, and access is removed the same day someone leaves the team.
Each client only sees their own projects, files, invoices and requests in the Passport portal. Separation is enforced at the database layer, not just in the interface.
Card payments are processed by Stripe. We never see or store full card numbers on our systems.
The public site, the Passport portal and our internal workspace are served over HTTPS only.
Application data is backed up by our managed database provider. Website and store code is version controlled so we can roll back a bad release.
Sensitive actions inside our workspace are recorded with who did what and when, so account changes can be reviewed after the fact.
Reporting
If you believe you have found a security issue in one of our properties, email info@prohub360.com with the words "security report" in the subject line, or call (800) 674-5153. Include the URL, what you observed and how to reproduce it. We acknowledge reports within two business days and will keep you updated until it is closed. Please do not run destructive tests or access data that is not yours.
Scope
This page describes the practices we operate today. It is not a certification, an audit result, or a compliance attestation, and it does not claim SOC 2, ISO, HIPAA or PCI status. For contractual data-processing terms, see our privacy policy and terms, or ask us for a written agreement covering your requirements.