Home / Security portal
Security portal
One place for security reviews: the program, the documents, and the vulnerability disclosure process.
Evidence first, here as everywhere
Security review of Propelon works the way the product works: documents over assurances, status stated exactly, decision lineage on every gate, and a named person on every answer. Start with the summaries below; the detailed set is shared under NDA.
Security policy
Encryption, isolation, secure development, monitoring, incident response, people, and vendors.
Data protection
The processor model, what the platform processes, telemetry restraint, and DPA commitments.
Access governance
SSO and MFA, least privilege, gated elevation, reviews, and offboarding.
Requesting security documentation
Write to compliance@propelon.ai with the subject “Security review” for questionnaires, the DPA and the subprocessor list; vulnerability reports go to security@propelon.ai. Accept the mutual NDA online (or send us yours), and the document set follows: the security whitepaper, the DPA, the subprocessor list, current assessment status, and answers to your questionnaire. During an active evaluation, questionnaire turnaround is treated with the same priority as the evaluation itself.
Vulnerability disclosure
We welcome good-faith security research on propelon.ai and the Propelon platform. Report suspected vulnerabilities to security@propelon.ai with the subject “Vulnerability report”, including steps to reproduce; we acknowledge reports promptly, keep you informed as we remediate, and credit researchers who want credit.
Safe harbor. Research that stays in scope — no access to data that is not yours, no service disruption, no social engineering of our people or customers, and a reasonable window for remediation before public disclosure — will not be met with legal action by Propelon. Out of scope: denial of service, physical attacks, spam, and findings on third-party services we do not operate.
Abuse of the site or the platform — spam, impersonation, misuse of an account — is reported to abuse@propelon.ai.