Trust Center

Security you can inspect.

Proxi handles the customer signals your team already relies on: calls, tickets, billing, and product analytics. Here is the full set of 112 security controls we run, where each framework actually stands, and the documents your security reviewer is going to ask for.

One square is one control, grouped into 10 categories. All 112 reported passing on our monitored trust center as of August 13, 2026.

View live status, monitored by Oneleet →

Compliance

Current status across frameworks, stated the way our monitored trust center states it.

SOC 2

In progress

Our SOC 2 program is in progress. We do not claim a completed SOC 2 report, and no Type I or Type II designation is published yet. Progress is tracked continuously on the live trust center.

HIPAA Provider

Compliant

Every HIPAA Provider control on our monitored trust center reports passing, including business associate agreements, breach notification, and PHI handling procedures.

CCPA / CPRA
Compliant (Service Provider)

We operate as a Service Provider: we do not sell or share personal information, and we process it only for the purposes in our customer agreements.

GDPR
Aligned

Proxi is US based. Our handling aligns with purpose limitation, data minimization, storage limitation, and security.

Data Processing Agreement
Available on request

Covers our obligations as a processor: security commitments, sub-processor transparency, 72 hour breach notification, deletion, and audit rights.

Live trust centerContinuously monitored control status, always current, hosted by Oneleet.View live status, monitored by Oneleet →

Compliance program

The 112 security controls we operate, in the 10 categories our trust center groups them into. Open any category to read what each control commits us to and which framework it maps to.

112 controls10 categoriesAll reported passing

Access Control and Authorization

15 controls
  • Access granting process used
  • Access management policy established
  • Access requests to sensitive data required
  • Access requests to sensitive infrastructure required
  • Access revoking process enforced
  • Account inventory maintained
  • Automatic user logoff enforced
  • Changes to PHI logged
  • Dormant accounts disabled
  • Emergency access procedure established
  • Employee access regularly reviewed
  • MFA required for applications
  • MFA required for critical services
  • Password management policy established
  • Unique user identification implemented
Read the 15 control descriptions
Access granting process usedHIPAA Provider
Implement a formal access granting process that ensures new access privileges are assigned based on the principle of least privilege, and require at least one employee to endorse the granting of new access.
Access management policy establishedSOC 2HIPAA Provider
Systematic controls are established in the access management policy for managing user access rights, ensuring appropriate, authorized access to systems and data.
Access requests to sensitive data requiredHIPAA Provider
To access sensitive data, employees must submit access requests that are approved and monitored.
Access requests to sensitive infrastructure requiredHIPAA Provider
To access sensitive infrastructure components, employees must submit access requests that are approved and monitored. This control helps ensure that only authorized personnel can access critical infrastructure, minimizing potential risks.
Access revoking process enforcedHIPAA Provider
Implement a regular access review process to promptly remove access privileges from employees who no longer require them. This ensures that former employees or users do not retain unauthorized access to organizational resources.
Account inventory maintainedHIPAA ProviderSOC 2
An inventory of user accounts on critical and high-risk vendors that have access to in-scope systems and services is maintained, including essential details such as account owners, access privileges, associated roles, and vendor relationships where applicable. The inventory is reviewed and updated at least annually.
Automatic user logoff enforcedHIPAA Provider
Implement an automatic logoff mechanism to terminate user sessions after a period of inactivity.
Changes to PHI loggedHIPAA Provider
Track all changes made to PHI, including additions, modifications, and deletions, to ensure data integrity and enable audit trails.
Dormant accounts disabledSOC 2
Monitor for dormant user accounts and disable or remove accounts that have been inactive for an extended period.
Emergency access procedure establishedHIPAA Provider
Establish and maintain a procedure for granting authorized personnel access to critical information during emergencies.
Employee access regularly reviewedSOC 2
Employee access is reviewed at least annually to ensure that access privileges are appropriate and that former employees or users do not retain unauthorized access.
MFA required for applicationsHIPAA Provider
Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this safeguard.
MFA required for critical servicesSOC 2HIPAA Provider
Multi-factor authentication (MFA) is required for accessing critical services and infrastructure unless a documented exception is in place where MFA is not supported.
Password management policy establishedSOC 2HIPAA Provider
A password management policy is enforced that mandates strong, complex passwords and prohibits the reuse of previous passwords.
Unique user identification implementedHIPAA Provider
Enforce the use of unique user identification for all individuals and systems accessing environments where protected information is stored, processed, or transmitted.

Data Management and Protection

18 controls
  • Compliance for multiple covered functions managed
  • Confidential customer communication channel created
  • Cryptographic keys and application secrets secured
  • Data encrypted at rest
  • Data encrypted in-transit
  • Data inventory maintained
  • Data management and retention policy established
  • Data processing integrity and output validated
  • De-identification process for PHI established
  • External privacy inquiries managed
  • Facility directory disclosure process established
  • Notice of privacy practices created and distributed
  • PHI access and amendment requests managed
  • PHI disclosure records maintained
  • Patient authorization for PHI use and disclosure obtained
  • Secure disposal process established
  • Use and disclosure of PHI managed
  • Verification procedures established
Read the 18 control descriptions
Compliance for multiple covered functions managedHIPAA Provider
Entities performing multiple covered functions must establish clear processes to ensure each function adheres to its specific standards and requirements.
Confidential customer communication channel createdHIPAA Provider
Establish and maintain a secure communication channel for all customer interactions involving protected information.
Cryptographic keys and application secrets securedHIPAA Provider
Implement and maintain robust procedures to securely manage cryptographic keys and application secrets used for protecting sensitive data throughout their lifecycle. Develop and document a comprehensive key management policy and procedures, including: - Implement secure key generation processes using industry-standard algorithms and random number generators. - Establish secure key storage mechanisms, such as hardware security modules (HSMs) or encrypted key stores. - Enforce strict access controls to limit key/secret access to authorized personnel only. - Implement key rotation and expiration policies to minimize the impact of potential key compromises. - Set up secure key/secret distribution and transmission processes. - Establish and maintain an inventory of all cryptographic keys and their purposes. - Implement secure key/secret backup and recovery procedures. - Ensure proper destruction of retired or compromised keys and secrets. Regularly review and update key management practices to align with current industry standards and best practices.
Data encrypted at restSOC 2HIPAA Provider
All sensitive data is encrypted when stored on systems or devices.
Data encrypted in-transitSOC 2HIPAA Provider
All data is encrypted when transmitted over networks, both within the organization's internal network and external connections.
Data inventory maintainedHIPAA Provider
An accurate and up-to-date inventory of all data assets is maintained, covering data stored in databases, file shares, or cloud storage.
Data management and retention policy establishedSOC 2HIPAA Provider
A data management and retention policy is established, outlining guidelines for how long data should be retained and how it should be managed throughout its lifecycle.
Data processing integrity and output validatedHIPAA Provider
Define and establish quality control measures to verify the completeness, accuracy, and timeliness of your output. This can look like implementing automated data validation checks, setting up data reconciliation processes, establishing review and approval workflows for critical outputs, creating data quality dashboards for real-time monitoring, and implementing version control systems for data processing scripts. Set up real-time monitoring of these measures and create error logs and incident reports where applicable.
De-identification process for PHI establishedHIPAA Provider
Establish and implement a documented process for de-identifying protected health information (PHI) to comply with HIPAA requirements and enable the use or disclosure of data without patient authorization if required.
External privacy inquiries managedHIPAA Provider
Establish and maintain a system for handling all privacy-related inquiries, including general questions, complaints, disputes, and specific requests for personal information access and correction.
Facility directory disclosure process establishedHIPAA Provider
Establish and maintain a documented process for including protected health information (PHI) in facility directories, ensuring individuals are informed and given the opportunity to agree or object to such disclosures.
Notice of privacy practices created and distributedHIPAA Provider
Distribute a Notice of Privacy Practices (NPP) to patients, informing them of their rights under HIPAA and how their PHI will be used and disclosed.
PHI access and amendment requests managedHIPAA Provider
Establish and maintain a documented process to manage individuals' requests for accessing and amending their protected health information (PHI).
PHI disclosure records maintainedHIPAA Provider
Establish a system to track disclosures of PHI, ensuring records of disclosures meet HIPAA requirements for accountability and transparency.
Patient authorization for PHI use and disclosure obtainedHIPAA Provider
Require and maintain patient authorizations for the use or disclosure of PHI outside of permitted purposes (treatment, payment, and healthcare operations).
Secure disposal process establishedHIPAA Provider
A documented procedure is maintained for the secure disposal of electronic and physical media containing protected, classified, or personal data, rendering it unusable, unreadable, and indecipherable.
Use and disclosure of PHI managedHIPAA Provider
Implement procedures to operationalize the policy defining the permissible uses and disclosures of protected health information (PHI), ensuring compliance with HIPAA requirements in day-to-day activities.
Verification procedures establishedHIPAA Provider
Establish and maintain documented procedures for verifying the identity and authority of individuals or entities requesting access to protected information.

Disaster Recovery

8 controls
  • Automated backups enabled
  • Business continuity and disaster recovery policy established
  • Data backup and recovery policy established
  • Data recovery process established
  • Data recovery tested
  • Disaster recovery plans documented
  • Disaster recovery plans tested
  • Recovery data isolated
Read the 8 control descriptions
Automated backups enabledSOC 2HIPAA Provider
Automated backups are enabled for all high-risk data and critical systems.
Business continuity and disaster recovery policy establishedSOC 2HIPAA Provider
A comprehensive business continuity and disaster recovery policy is established, outlining the organization's strategies for responding to disruptive incidents and supporting business continuity.
Data backup and recovery policy establishedHIPAA Provider
Develop and maintain a backup and recovery policy that defines the your approach to protecting and preserving critical data.
Data recovery process establishedHIPAA Provider
Establish a data recovery process that defines procedures for recovering data in case of data loss, corruption, or system failures. A robust data recovery process helps minimize downtime and data loss in critical situations.
Data recovery testedHIPAA Provider
Regularly test the data recovery process to validate its effectiveness and ensure that data can be successfully restored from backups. Testing helps identify any issues or gaps in the data recovery plan.
Disaster recovery plans documentedHIPAA Provider
Document disaster recovery (DR) plans to recover critical systems and maintain operational continuity following disruptive incidents. These plans should address potential risks, define recovery strategies, and integrate with broader business resilience efforts.
Disaster recovery plans testedHIPAA ProviderSOC 2
Regularly test the organization's disaster recovery plans to ensure their effectiveness and identify areas for improvement. Testing helps validate the ability to recover critical systems and operations in the event of a disaster.
Recovery data isolatedHIPAA Provider
Isolate the recovery data from the production environment to prevent accidental overwriting or corruption of backups. Keeping recovery data separate helps maintain the integrity and availability of backup copies.

Email Security

3 controls
  • DMARC policy and verification used
  • Email account access restricted
  • Email settings block malicious content
Read the 3 control descriptions
DMARC policy and verification usedSOC 2HIPAA Provider
DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy and verification mechanisms are implemented to prevent email spoofing and phishing attacks.
Email account access restrictedHIPAA Provider
Access to email accounts is restricted to administrators only, and isn't delegated to other non-admin users within the organization.
Email settings block malicious contentSOC 2
Email settings are configured to block malicious content, including malicious attachments, links, and scripts.

Endpoint Security

5 controls
  • Anti-malware deployed on end-user devices
  • Automatic session locking enforced
  • Data encrypted on end-user devices
  • Firewall maintained on end-user devices
  • Mobile device management (MDM) used
Read the 5 control descriptions
Anti-malware deployed on end-user devicesSOC 2HIPAA Provider
Anti-malware or antivirus solutions are deployed on end-user devices, such as laptops and workstations.
Automatic session locking enforcedHIPAA Provider
Enforce automatic session locking to prevent unauthorized access to unattended devices. Automatic session locking helps protect sensitive data from unauthorized access and misuse.
Data encrypted on end-user devicesSOC 2HIPAA Provider
Data stored on end-user devices (e.g., laptops, mobile devices) is encrypted to protect it in case of device loss or theft.
Firewall maintained on end-user devicesSOC 2HIPAA Provider
Firewalls are installed and properly maintained on end-user devices, such as laptops and workstations.
Mobile device management (MDM) usedSOC 2
A mobile device management (MDM) solution is used to manage and secure end-user devices.

Infrastructure Security

12 controls
  • Active discovery tools used
  • Administrator access restricted
  • Automated security scanning performed on infrastructure
  • Buckets not exposed publicly
  • Cloud infrastructure used
  • Firewall restricts public access to infrastructure
  • Infrastructure changes logged
  • Network infrastructure continuously updated
  • Pull requests used
  • Unauthorized assets addressed and removed
  • VPN used
  • Web Application Firewall (WAF) used
Read the 12 control descriptions
Active discovery tools usedSOC 2
An active discovery tool is used to identify assets connected to the enterprise's network, configured to execute daily or more frequently.
Administrator access restrictedHIPAA Provider
Restrict administrator access to critical systems and sensitive data based on the principle of least privilege, granting elevated permissions only when necessary for specific tasks and revoking them promptly after completion. Implement strong authentication mechanisms, such as multi-factor authentication, and regularly review and update administrator access rights to ensure they align with job responsibilities and maintain a secure environment.
Automated security scanning performed on infrastructureSOC 2HIPAA Provider
Automated security scanning software is deployed on all infrastructure components including servers and network devices.
Buckets not exposed publiclySOC 2HIPAA Provider
Cloud storage buckets are not exposed to the public internet unless a documented business justification is in place.
Cloud infrastructure usedSOC 2
Cloud infrastructure is hosted with providers that maintain independent certifications (e.g., SOC 2) for physical and environmental security controls, rather than managed on-premises.
Firewall restricts public access to infrastructureSOC 2HIPAA Provider
Firewalls are configured to restrict public access to the organization's infrastructure components.
Infrastructure changes loggedHIPAA Provider
Maintain a log of all infrastructure changes to track and document modifications made to critical systems and services. Logging infrastructure changes aids in audit trails, incident investigations, and accountability.
Network infrastructure continuously updatedHIPAA Provider
Ensure the network infrastructure components (e.g., routers, switches, firewalls) are continuously updated with the latest security patches and firmware updates. Regular updates help address known vulnerabilities and enhance network security.
Pull requests usedSOC 2
Pull requests are used for code changes to ensure all modifications are reviewed before merging to production branches.
Unauthorized assets addressed and removedHIPAA Provider
Ensure that a process exists to address unauthorized assets on a periodic basis. This process should include regular audits of all assets and a procedure for handling unauthorized assets when they are discovered.
VPN usedHIPAA Provider
Utilize Virtual Private Network (VPN) connections to secure remote communications between users and the organization's internal network. VPNs provide encrypted and authenticated tunnels, ensuring secure data transmission over untrusted networks.
Web Application Firewall (WAF) usedHIPAA Provider
Implement a Web Application Firewall (WAF) to protect web applications from various cyber threats, such as SQL injection, cross-site scripting, and other application-layer attacks.

Monitoring and Incident Response

13 controls
  • Adequate audit log storage maintained
  • Audit logs collected
  • Breach notification process established
  • Breach notification template prepared
  • Breach response playbook established
  • Breach risk assessment template developed
  • HHS breach reporting template established
  • Incident history maintained
  • Incident response policy established
  • Incident response procedures defined
  • Infrastructure performance monitored
  • Media notification template established
  • Network infrastructure monitored
Read the 13 control descriptions
Adequate audit log storage maintainedHIPAA Provider
Ensure sufficient storage capacity to retain audit logs for the required duration. Adequate audit log storage enables historical analysis and supports compliance requirements related to log retention.
Audit logs collectedHIPAA Provider
Audit logs are collected from critical systems and applications, capturing security events for incident detection, investigation, and compliance.
Breach notification process establishedHIPAA Provider
A breach notification process is established that outlines procedures for detecting, assessing, and reporting security breaches.
Breach notification template preparedHIPAA Provider
A standardized breach notification template is maintained, enabling timely, consistent, and compliant communication with affected individuals in the event of a breach.
Breach response playbook establishedHIPAA Provider
Develop and maintain a breach response playbook focused on managing breaches after they are discovered, including detailed procedures for assessing, containing, and resolving incidents involving protected information.
Breach risk assessment template developedHIPAA Provider
Establish a standardized risk assessment template to evaluate the potential impact of breaches on affected individuals. Include criteria for assessing: - The nature and sensitivity of the breached ePHI. - The likelihood of data misuse. - Steps already taken to mitigate the breach.
HHS breach reporting template establishedHIPAA Provider
Prepare a standardized reporting template for notifying the Department of Health and Human Services (HHS) of breaches, including required elements for both small and large breaches.
Incident history maintainedHIPAA Provider
A record of past incidents is maintained, covering their identification, reporting, escalation, and resolution.
Incident response policy establishedHIPAA ProviderSOC 2
An incident response policy is established that outlines the organization's approach and procedures for detecting, responding to, and recovering from cybersecurity incidents.
Incident response procedures definedHIPAA Provider
Step-by-step incident response procedures are defined covering detection, containment, eradication, and recovery, with designated team roles and communication protocols for internal and external stakeholders.
Infrastructure performance monitoredSOC 2
The performance of the organization's infrastructure components is monitored to detect potential issues or anomalies that may impact security or reliability.
Media notification template establishedHIPAA Provider
Define and maintain standardized templates for media-related notifications to ensure consistent handling and documentation of security events
Network infrastructure monitoredHIPAA Provider
Implement monitoring mechanisms for the network infrastructure to detect and respond to suspicious or unauthorized activities. Network monitoring helps ensure the integrity and availability of network resources.

Organizational Security

27 controls
  • Acceptable use policy established
  • Asset inventory maintained
  • Asset management policy established
  • Business associate agreements managed
  • Business associate agreements with subcontractors managed
  • Change management policy established
  • Code of conduct established
  • Company security commitments externally communicated
  • Data-flow diagrams maintained
  • HIPAA training conducted
  • Human resource security policy established
  • Offboarding process established
  • Onboarding process established
  • Password manager used
  • Physical access restricted
  • Physical security policy established
  • Policies signed by relevant personnel
  • Privacy official assigned
  • Reference checks performed for employees
  • Security Violations Managed
  • Security awareness training conducted
  • Security official assigned
  • Service description communicated
  • Software development lifecycle established
  • Third-party security oversight conducted
  • Whistleblower policy established
  • Workstation use and security policy established
Read the 27 control descriptions
Acceptable use policy establishedSOC 2
Establish and maintain an acceptable use policy that outlines permissible activities, systems, and data access for all users, contractors, and third parties interacting with the organization's information assets and technologies.
Asset inventory maintainedHIPAA Provider
Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data. This can include end-user devices, network devices, IoT devices, and servers.
Asset management policy establishedHIPAA ProviderSOC 2
Establish an asset management policy that outlines the guidelines for managing the organization's assets throughout their lifecycle.
Business associate agreements managedHIPAA Provider
Establish and maintain a process for managing Business Associate Agreements (BAAs) to meet HIPAA requirements.
Business associate agreements with subcontractors managedHIPAA Provider
As a business associate, establish a process for managing contracts with subcontractors to ensure they comply with HIPAA requirements. These agreements must extend your obligations under BAAs with covered entities or upstream business associates, including safeguarding PHI, reporting breaches, and adhering to HIPAA standards.
Change management policy establishedSOC 2
Establish a change management policy that defines procedures for controlling and documenting changes to systems, applications, and infrastructure.
Code of conduct establishedSOC 2
A code of conduct is established that outlines the expected behavior and ethical standards for all employees.
Company security commitments externally communicatedSOC 2
Key company security commitments and policies are externally communicated, including the Master Service Agreement (MSA), Security Information page, or Terms of Service.
Data-flow diagrams maintainedSOC 2
Up-to-date data-flow diagram(s) are maintained that show all account data flows across systems and networks, updated as needed when changes occur in the environment.
HIPAA training conductedHIPAA Provider
Establish a process for providing HIPAA training to workforce members to build understanding of their responsibilities related to protecting protected health information (PHI) and complying with HIPAA regulations.
Human resource security policy establishedHIPAA Provider
Develop and maintain a human resource policy that addresses information security responsibilities throughout the employment lifecycle, from recruitment to termination.
Offboarding process establishedHIPAA ProviderSOC 2
An offboarding process is established for departing employees to ensure that they are removed from relevant systems and accounts.
Onboarding process establishedSOC 2HIPAA Provider
An onboarding process is established to ensure new employees are properly granted appropriate access privileges necessary to perform their job responsibilities.
Password manager usedSOC 2
A company-wide password manager is deployed to securely store and share credentials across the organization. All shared accounts and secrets are shared through the password manager using a principle of least privilege.
Physical access restrictedHIPAA ProviderSOC 2
Physical access to the organization's facilities, equipment, and systems is restricted to authorized personnel only.
Physical security policy establishedHIPAA Provider
Establish a physical security policy that outlines the organization's processes for protecting physical assets and resources.
Policies signed by relevant personnelSOC 2
Security policies are formally acknowledged and signed by all relevant personnel, establishing accountability for security responsibilities.
Privacy official assignedHIPAA Provider
A privacy official is designated who oversees compliance with privacy requirements and manages privacy-related initiatives.
Reference checks performed for employeesSOC 2
Reference checks are conducted when hiring new employees to verify their qualifications, experience, and suitability for the role.
Security Violations ManagedHIPAA Provider
Establish a security violations management process that outlines the your procedures for detecting, documenting, and addressing security violations by your employees.
Security awareness training conductedHIPAA ProviderSOC 2
Security awareness training is conducted annually for all employees, covering cybersecurity threats, social engineering, authentication best practices, and handling of sensitive data.
Security official assignedHIPAA Provider
Designate a security official who is responsible for the development, implementation, and oversight of security policies and procedures, as well as management of the incident response process.
Service description communicatedSOC 2
Clear and detailed service descriptions are communicated to customers or users, outlining the scope, features, and limitations of the services provided.
Software development lifecycle establishedSOC 2
A well-defined and documented development lifecycle is implemented for software and applications.
Third-party security oversight conductedSOC 2
Third-party security oversight and governance of the organization's security controls is conducted by a qualified provider, ensuring independent verification of control effectiveness and compliance posture.
Whistleblower policy establishedHIPAA Provider
Establish a whistleblower policy that allows employees to report any wrongdoing or unethical behavior within the organization anonymously and without fear of retaliation. A whistleblower policy promotes transparency and accountability.
Workstation use and security policy establishedHIPAA Provider
Establish a workstation use and security policy that outlines the appropriate use of workstations and security measures to protect them from unauthorized access. The policy helps safeguard the organization's assets and data.

Risk Management

6 controls
  • HIPAA compliance policy established
  • Risk assessments performed
  • Risk management policy established
  • Software supply chain risks monitored
  • Vendor inventory maintained
  • Vendor management program established
Read the 6 control descriptions
HIPAA compliance policy establishedHIPAA Provider
Establish and maintain a comprehensive compliance policy that defines how the organization identifies, monitors, and fulfills its regulatory, legal, and contractual obligations.
Risk assessments performedSOC 2HIPAA Provider
Risk assessments are conducted at least annually to identify and evaluate potential threats and vulnerabilities that could impact the organization's assets.
Risk management policy establishedSOC 2
A risk management policy is established that outlines the organization's approach to identifying, assessing, and mitigating information security risks.
Software supply chain risks monitoredSOC 2
Software supply chain risks are monitored by assessing the security of third-party libraries and open-source components used in the organization's software development lifecycle.
Vendor inventory maintainedSOC 2
An accurate and up-to-date inventory of all vendors is maintained, including details such as the services provided, contract terms, and the scope of access they have.
Vendor management program establishedHIPAA ProviderSOC 2
A vendor management policy is established to assess, monitor, and manage the risks associated with third-party vendors, ensuring that external partners meet security and compliance standards.

Vulnerability Management

5 controls
  • Penetration testing findings remediated
  • Penetration testing performed within the last 12 months
  • Vulnerabilities remediated
  • Vulnerabilities scanned
  • Vulnerability management policy established
Read the 5 control descriptions
Penetration testing findings remediatedSOC 2HIPAA Provider
Vulnerabilities identified during penetration testing are promptly remediated.
Penetration testing performed within the last 12 monthsHIPAA ProviderSOC 2
Penetration testing is conducted at least every 12 months to identify potential vulnerabilities in the organization's systems, applications, and infrastructure.
Vulnerabilities remediatedSOC 2HIPAA Provider
Detected vulnerabilities are promptly remediated to minimize the risk of exploitation. This includes establishing clear protocols for prioritizing vulnerabilities based on severity and ensuring timely resolution of critical security issues.
Vulnerabilities scannedSOC 2HIPAA Provider
Regular vulnerability scans are conducted on systems and applications to identify potential security flaws. This includes automated scanning tools that systematically examine infrastructure, applications, and code repositories for known vulnerabilities.
Vulnerability management policy establishedSOC 2HIPAA Provider
A vulnerability management policy is established that outlines the procedures for identifying, assessing, and remediating vulnerabilities in the organization's systems and applications.

Snapshot taken August 13, 2026 from our Oneleet trust center. Control status is monitored continuously, so the live trust center is the current source of truth.

Documents and resources

Audit reports and detailed security documentation are available on request via security@getproxi.ai.

Our security commitments

  • All data is encrypted in transit (TLS) and at rest (AES-256).
  • Each customer's data is isolated in its own workspace, with tenant-level scoping enforced on every request.
  • Internal access to production systems is limited to essential personnel on a least-privilege basis.
  • Credentials and integration tokens are stored encrypted on a per-connection basis.
  • We never sell customer data, and we never train AI models on it without explicit consent.
  • We notify affected customers of a confirmed breach within 72 hours.
  • Customers can delete their data at any time, per connection or for the entire workspace.

Questions security teams ask

How is my data encrypted?

Everything is encrypted in transit with TLS, between your browser, Proxi, and the third-party APIs we connect to. Database storage is encrypted at rest with AES-256. OAuth tokens and API keys are stored encrypted on a per-connection basis.

Can another customer see my data?

No. All data is logically isolated per customer workspace. There is no cross-tenant access at the query layer, and database operations enforce tenant-level scoping on every request.

Do you sell my data or train models on it?

No to both. We do not sell personal data, and we do not use customer data for advertising or profiling. We do not train machine learning models on customer data without explicit written consent, and we do not access customer data except as necessary to provide the service or as directed by you.

How do I delete my data?

You can delete your data at any time, per connection or for the entire workspace, and you can email us to request full deletion. Raw data is retained for the duration of your active account. On termination, customer data is deleted as soon as reasonably practicable, though it may persist in encrypted backups for a limited period before being overwritten through normal backup rotation.

What happens if there is a breach?

We notify affected customers within 72 hours of becoming aware of an incident. The notification covers the nature of the incident, the categories and approximate number of affected records, likely consequences, and the measures taken or proposed to mitigate impact. We cooperate with customers on investigation and remediation.

Who are your sub-processors?

Supabase (database hosting, storage, authentication), Railway (application and worker hosting), Amazon Web Services (log and audit-record archive storage), Anthropic and OpenAI (AI processing), and Resend (transactional email). All process data in the United States. We notify customers at least 30 days before engaging a new sub-processor. The full table lives on our security page.

How do I get your DPA?

Email security@getproxi.ai and we will send it. The DPA is available to all customers and defines our obligations as a data processor, including security commitments, sub-processor transparency, 72 hour breach notification, deletion procedures, and audit rights.

Questions?

For security, privacy, or compliance questions, or to request our DPA or other documentation, contact us at security@getproxi.ai.