FAQ

    The questions IT, security, and procurement actually ask.

    Straight answers on data, privacy, security, and who is accountable for what. The detail your buying committee needs to clear us fast.

    What data is collected by ProHabits?

    ProHabits collects both quantitative and qualitative data to support program delivery, participant engagement, and reporting. This includes: Engagement metrics, commitment rates, completion rates, and participation levels Participant-generated content, stories, reflections, comments, or free-text responses (if enabled) Survey data, optional pre- and post-program responses, if included in the program design User identity data, email address is the only required unique identifier Optional segmentation fields, such as name, role, location, cohort, or other attributes defined by the client based on reporting needs

    Where is data stored and processed?

    Data is stored and processed within secure AWS cloud infrastructure. Key controls include: Encryption applied in transit and at rest Role-based access controls (RBAC) and least-privilege principles Controlled and monitored access environments Data retention is defined in alignment with client requirements. Data can be deleted upon request or retained for an agreed period in accordance with documented retention policies. Additional details on region, architecture, or security documentation can be provided upon request.

    Who owns the data?

    ProHabits does not own client data. All data remains the property of the client organization. ProHabits uses data solely for agreed program delivery, support, analysis, and reporting purposes.

    Can ProHabits access or see identifiable employee data?

    ProHabits processes client-provided data solely for the purpose of delivering the service. The only required personal data element is an email address, used as a unique identifier Additional fields such as name, role, and location are optional and defined by the client Access to identifiable data is restricted to authorized personnel only, governed by least-privilege principles and role-based access controls Whether specific segmentation data is visible or identifiable depends on the fields provided by the client. Reporting can be configured to aggregate, anonymize, or restrict views based on client requirements. Analytics & Reporting

    What analytics or reporting views exist, and are they anonymized by default?

    There are two primary reporting views, both configurable based on client preferences: Individual participant view, A participant-facing dashboard showing personal progress. Optional features such as leaderboards and shared stories can be enabled, anonymized, or disabled based on client requirements. Leadership/program reporting view, Aggregated reporting delivered through Power BI dashboards, customizable across dimensions such as cohort, time period, role level, and other client-defined segments. Anonymization and aggregation are configurable for both views. Many clients choose anonymized or aggregated reporting for leadership audiences. Roles & Accountability

    What is the client's role vs. ProHabits' role in configuration, data administration, and support?

    ProHabits is responsible for: Configuring and operating the platform Supporting data administration and enabling reporting Maintaining the technical environment in line with client-approved requirements The client typically leads: Overall program design, change strategy, and content alignment Stakeholder management and interpretation of results Defining desired configuration, reporting requirements, segmentation approach, and outcomes framework

    Who is accountable if the tool fails, a data issue arises, or there is a challenge on content or outcomes?

    Accountability depends on the nature of the issue: Platform or technical issues, ProHabits is accountable for platform performance, system availability, data processing, dashboards, and technical administration. Data issues, If the issue relates to source data provided by the client, that would be addressed by the relevant data owner. If it relates to platform processing, configuration, or reporting, ProHabits leads resolution. Content or outcomes challenges, The client leads on program design, content interpretation, and change management, with ProHabits supporting where platform data or reporting is involved. Insights & Outcomes

    What types of insights does ProHabits provide?

    ProHabits provides platform-generated insights based on participation, engagement, completion, survey responses, and participant-submitted reflections or stories. Insights are drawn from three sources: Observed behavioral data, participation rates, completion rates, commitment levels, and engagement activity within the platform Self-reported data, survey responses, reflections, stories, comments, and free-text inputs Inferred insights, patterns or themes derived from aggregated platform data and analysis Any inferred insights are clearly labeled as such and not presented as definitive proof of behavior or culture change.

    Can culture change be attributed solely to ProHabits MicroActions?

    No. ProHabits should be understood as one input into a broader culture and behavior-change effort. To avoid over-attribution, reporting distinguishes between: Platform engagement and participation Self-reported sentiment or reflection Qualitative themes Broader organizational indicators and other concurrent initiatives or external factors ProHabits data can demonstrate engagement with MicroActions and surface related patterns, but culture change should be assessed through a broader evidence base. Security & Compliance

    What security practices does ProHabits follow?

    ProHabits follows industry-standard security practices, including: Encryption of data in transit and at rest Role-based access controls (RBAC) and least-privilege access principles Secure, cloud-based infrastructure hosted on AWS Controlled and monitored access to reporting environments Additional security and compliance documentation can be provided upon request.

    Does ProHabits support Single Sign-On (SSO)?

    Yes. ProHabits supports SSO via SAML 2.0 and OAuth 2.0. SSO integration is configured during client onboarding based on the client's identity provider and requirements.

    What security certifications or independent audits has ProHabits completed?

    ProHabits maintains a full set of written security, privacy, encryption, access, incident response, and vendor policies, with the program mapped to the NIST Cybersecurity Framework and the OWASP Application Security Verification Standard. We run regular third party penetration testing, vulnerability assessments, and security audits. Our complete policy pack is available for your team to review under NDA, and ProHabits has been cleared and deployed by 21 Fortune 500 companies and government.

    What happens in the event of a security incident, and how will we be notified?

    ProHabits classifies incidents by severity and follows a defined incident response process. Designated client contacts are notified by email within timeframes tied to severity level. Following resolution, a post-incident report is provided detailing the nature, impact, and remediation steps taken. Incident response procedures are available upon request under a confidentiality agreement. Operations & Business Continuity

    What are ProHabits' backup and disaster recovery practices?

    ProHabits uses AWS Backup for automated daily backups. Data is encrypted at rest (AES-256), replicated across multiple AWS Availability Zones, and retained for a minimum of 30 days. Disaster recovery plans are tested annually. Full DR and Business Continuity documentation is available upon request.

    Can the client conduct a security audit or vulnerability assessment of ProHabits?

    Yes. ProHabits supports client-initiated security audits and vulnerability scans with reasonable advance notice. Clients may also request copies of existing security documentation, scanning results, and audit reports under a confidentiality agreement.

    How are platform changes and updates communicated?

    For scheduled changes or maintenance that may affect service availability, clients receive email notification a minimum of 5 business days in advance. For unscheduled or emergency changes, clients are notified as promptly as practicable, followed by a post-incident summary. Change logs are retained and available upon request. This document is confidential and intended for client use only. · ProHabits · June 2026