Home / Security policy
Security policy
How Propelon secures the company and the platform. Stated as commitments we operate by, not badges.
Effective September 19, 2026 · Quest 2 Excel, Inc., dba Propelon
The principle
Propelon sells verification, so we hold our own security to the standard we ask customers to hold their AI portfolios to: controls that leave evidence, access that is attested by a named person, and claims stated at the strength of what can be shown. This page summarizes the program; detailed documentation is available under NDA through the Security portal.
Data protection in the platform
Customer data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. Each customer’s environment is logically isolated; one customer’s data is never visible to another. Production access follows the access governance model: least privilege, time-bound elevation with named approval, and logging of administrative actions.
Secure development
Changes reach production through review and automated checks — dependency and vulnerability scanning, tests, and staged rollout — with the deployment record tied to the change. Secrets are managed in a dedicated store, never in source.
Monitoring and incident response
Production systems are logged and monitored, with alerting on anomalous access and availability. We maintain an incident response process with defined severities and on-call ownership; customers affected by a security incident involving their data are notified without undue delay, consistent with the data processing agreement and applicable law.
People
Personnel receive security training on joining and periodically after; access is provisioned by role, reviewed on a schedule, and removed on the day a role ends. Background checks are performed where the law permits.
Vendors
Subprocessors and vendors that touch customer data are reviewed before use and bound to confidentiality and security obligations. The current subprocessor list is available to customers on request.
Assessments
The program is exercised through internal review and independent assessment; current assessment status and reports are shared with customers and prospects under NDA through the Security portal, and we describe status exactly as it is rather than by implication.
Reporting a vulnerability
We welcome good-faith reports — see the vulnerability disclosure process for scope and safe-harbor terms.