Security & Trust

    Built to clear enterprise IT, and to make it easy.

    We have cleared IT and procurement at Fortune 500 companies and government, with launches across North America, Europe, and Asia. Here is the honest picture, the controls behind it, and a page you can forward straight to your IT team.

    GDPR & CCPA alignedEncrypted in transit & at restMFA & least-privilege accessNIST CSF & OWASP ASVS alignedIndependent penetration testing72-hour breach notification
    The controls behind it

    Every layer documented, every layer tested.

    Encryption

    Data is encrypted in transit (TLS) and at rest (AES), with formal key management and rotation. Encryption extends to data on portable devices and over public networks.

    Access control

    Role-based access on a least-privilege, need-to-know basis. Multi-factor authentication on remote and privileged accounts, periodic access reviews, and immediate revocation at offboarding.

    Privacy & data rights

    GDPR and CCPA aligned. We honor access, correction, deletion, portability, and objection rights. Data is retained no longer than needed and no longer than a year past account termination. EU Standard Contractual Clauses cover international transfers, and production data resides in the United States.

    Incident response

    A documented incident response plan with severity classification, defined breach notification (within 72 hours to the relevant authority under GDPR), post-incident reviews, and annual tabletop exercises.

    Independent testing

    Regular third-party penetration testing, vulnerability assessments, and security audits, with our program mapped to the NIST Cybersecurity Framework and OWASP ASVS.

    People

    Background checks on personnel with access to sensitive data, ongoing security awareness training, and phishing and social-engineering simulations.

    Data governance

    Formal data classification and a tracked asset inventory, encrypted and regularly tested backups, and a disaster recovery plan. Secure disposal of equipment and media.

    Vendor management

    Security due diligence before we engage any provider, contractual security clauses, and continuous monitoring of third-party compliance.

    Clearing us is fast

    Most of the work is already done for you.

    What we need from you

    Just a name and an email address. Optionally department, role, or region, used only for reporting. Data minimization by design, and we never sell personal data.

    How it is delivered

    Daily MicroActions by email or text. No app to install, no login, a magic link. Microsoft Teams delivery is available at scale.

    Whitelisting

    Allowlist our sending domain and IPs so messages land, and we run a deliverability test with one or two users before launch. The wildcard-domain step is the one that trips most rollouts, so we make it explicit.

    Forward this to IT

    A ready clearance note with our domains, IPs, data scope, and deliverability test, so your IT team can approve us in one pass.

    Trusted at enterprise scale

    The most demanding buyers on earth have already vetted us.

    Our full security, privacy, encryption, access, incident-response, and vendor policies are documented and mapped to the NIST Cybersecurity Framework and OWASP ASVS, and available for your team to review under NDA. ProHabits has been cleared and deployed by 21 Fortune 500 companies and government, with launches across North America, Europe, and Asia.