Security
Security at Proopsys
Last updated: August 19, 2026
We take security seriously. Here is exactly how we protect your business data.
1. How your data is protected
Encryption in transit: All data between your browser and our servers is encrypted using TLS 1.3. Your connection is always secure.
Encryption at rest: Your data is encrypted at the database level using AES-256. Even if someone accessed our servers, your data would be unreadable.
Authentication: We use secure session tokens with short expiry windows. Passwords are hashed using bcrypt before storage. We never store passwords in plain text.
Row-level security: Your data is only accessible to you. Our database enforces that no user can access another user’s records, even if there were an application error.
2. Our infrastructure
Proopsys runs on Vercel and Supabase, both of which hold SOC 2 Type II certification. Our hosting infrastructure is maintained by teams with dedicated security operations.
We do not run our own servers. We chose enterprise-grade providers so you benefit from their security investments.
3. Payment security
We do not store payment card numbers. Ever. All payments are processed by Stripe, which is PCI DSS Level 1 certified, the highest level of payment security certification. Your card details never touch our servers.
4. Access controls
Minimal access: Our team members only have access to what they need to do their job.
Audit logging: Administrative actions are logged with timestamps and user identification.
No shared credentials: Every team member has individual access credentials.
5. What we ask of you
- Use a strong, unique password for your Proopsys account.
- Do not share your account credentials.
- Log out of shared devices.
- Contact us immediately if you suspect unauthorized access.
6. Responsible disclosure
Found a security issue? We want to know.
Email: security@proopsys.com
We respond within 24 hours on business days. We will acknowledge valid reports and fix confirmed issues promptly. We do not take legal action against good-faith security researchers.