Built to clear enterprise IT, and to make it easy.
We have cleared IT and procurement at Fortune 500 companies and government, with launches across North America, Europe, and Asia. Here is the honest picture, the controls behind it, and a page you can forward straight to your IT team.
Every layer documented, every layer tested.
Encryption
Data is encrypted in transit (TLS) and at rest (AES), with formal key management and rotation. Encryption extends to data on portable devices and over public networks.
Access control
Role-based access on a least-privilege, need-to-know basis. Multi-factor authentication on remote and privileged accounts, periodic access reviews, and immediate revocation at offboarding.
Privacy & data rights
GDPR and CCPA aligned. We honor access, correction, deletion, portability, and objection rights. Data is retained no longer than needed and no longer than a year past account termination. EU Standard Contractual Clauses cover international transfers, and production data resides in the United States.
Incident response
A documented incident response plan with severity classification, defined breach notification (within 72 hours to the relevant authority under GDPR), post-incident reviews, and annual tabletop exercises.
Independent testing
Regular third-party penetration testing, vulnerability assessments, and security audits, with our program mapped to the NIST Cybersecurity Framework and OWASP ASVS.
People
Background checks on personnel with access to sensitive data, ongoing security awareness training, and phishing and social-engineering simulations.
Data governance
Formal data classification and a tracked asset inventory, encrypted and regularly tested backups, and a disaster recovery plan. Secure disposal of equipment and media.
Vendor management
Security due diligence before we engage any provider, contractual security clauses, and continuous monitoring of third-party compliance.
Most of the work is already done for you.
What we need from you
Just a name and an email address. Optionally department, role, or region, used only for reporting. Data minimization by design, and we never sell personal data.
How it is delivered
Daily MicroActions by email or text. No app to install, no login, a magic link. Microsoft Teams delivery is available at scale.
Whitelisting
Allowlist our sending domain and IPs so messages land, and we run a deliverability test with one or two users before launch. The wildcard-domain step is the one that trips most rollouts, so we make it explicit.
Forward this to IT
A ready clearance note with our domains, IPs, data scope, and deliverability test, so your IT team can approve us in one pass.
The most demanding buyers on earth have already vetted us.
Our full security, privacy, encryption, access, incident-response, and vendor policies are documented and mapped to the NIST Cybersecurity Framework and OWASP ASVS, and available for your team to review under NDA. ProHabits has been cleared and deployed by 21 Fortune 500 companies and government, with launches across North America, Europe, and Asia.