Primary hosting
Australia Database, authentication, storage, application compute and private job infrastructure.Security Centre
Trust should be
inspectable.
PROE handles full communication histories, client details and connected CRM records. This centre explains the controls, contracts and operating practices used to protect them.
Transport
TLS Customer, provider and service traffic uses encrypted modern transport.Selected secrets
AES-256-GCM Selected credentials and secret fields receive additional application-layer protection.Cross-customer AI use
Never Customer Data is not used to train or improve models, datasets or features serving another customer.Contracts and transparency
Start with the documents.
Public terms for everyday review, backed by a detailed customer security pack when your due-diligence process needs more.
Data Processing Addendum
Contractual processing, security, subprocessor, incident, export and deletion terms.
View document PrivacyPrivacy Policy
How PROE collects, uses, discloses and protects personal information.
View document TermsTerms of Service
The commercial and acceptable-use terms governing the PROE service.
View document FAQSecurity FAQ
Direct answers on hosting, encryption, AI, access, incidents and retention.
View documentSecurity FAQ
Direct answers.
Questions procurement, privacy and security teams commonly ask about PROE.
Where is Customer Data hosted?
PROE’s primary database, authentication, file storage, application compute and private job infrastructure are hosted in Australia. Selected providers process limited data overseas where needed to deliver connected services, AI inference, analytics and mobile notifications. Those locations are disclosed in the DPA.
How is data encrypted?
PROE uses HTTPS/TLS in transit and managed platform encryption at rest for stored Customer Data, including message content. Selected credentials and secret fields receive additional AES-256-GCM application-layer encryption. PROE does not represent that application-layer encryption applies to every Customer Data field. Runtime secrets are kept in managed secret stores and are not deliberately written to logs.
Who owns Customer Data, and is it used to improve services for other customers?
As between PROE and the Customer, all rights in Customer Data remain with the Customer and PROE acquires no ownership interest. PROE does not sell Customer Data or use Customer Data — including messages, attachments, prompts, outputs, embeddings or other customer-specific derivatives — to train, evaluate or improve any model, dataset, algorithm or feature serving another customer. AI providers process relevant data only to provide inference for that Customer and do not train or improve their models from PROE API inputs or outputs.
How long may an AI provider retain submitted data?
Commercial AI API providers may retain submitted inputs and outputs for safety and abuse monitoring for up to 30 days unless a zero-data-retention arrangement or shorter period applies. That retention does not permit training or model improvement. OpenAI requests explicitly disable application-state storage where supported.
Who can access production Customer Data?
Production access is limited to named personnel whose role requires it. Access follows least privilege and is subject to logging and review, administrative accounts use MFA where supported, and Customer-content access is limited to authorised support, security, recovery, operational or legal needs. PROE does not currently offer Customer-enforced end-user MFA; customer sessions are protected through Supabase Auth and organisation-scoped authorisation.
How are AI actions controlled?
PROE can classify, prioritise, associate, summarise and prepare drafts automatically. Outbound email and WhatsApp messages require a deliberate human send action. PROE does not autonomously accept or reject offers, allocate housing or enter contracts. Configured matched-contact CRM activity notes may be automatic; contact creation or material enrichment requires human approval.
What happens after termination?
A Customer may request a machine-readable export. Customer Data is deleted from active systems within 30 days after termination or a valid deletion instruction unless law requires retention. Deleted records may remain temporarily in protected rolling backups until they age out under provider lifecycle controls.
How will PROE respond to a security incident?
PROE follows a documented incident-response plan. An affected Customer will be notified without undue delay and no later than 72 hours after PROE determines that an incident has affected, or is reasonably likely to affect, that Customer’s data or systems. Security reports go directly to alex@proe.ai.
Which subprocessors does PROE use?
Current material providers are listed in Schedule 3 of the public DPA. The detailed security pack also includes a Subprocessor Register describing purpose, data categories, processing location, contract position and AI-training terms.
Can we review the full security pack?
Yes. The pack includes the architecture data-flow diagram, Information Security Policy, incident-response plan, encryption standard, secure-development standard, password policy, data-classification matrix and detailed Subprocessor Register. Request it from CTO Alex Morton at alex@proe.ai.
Need the evidence?
Request the full security pack.
It includes PROE's data-flow diagram, security policies, incident-response plan, encryption standard, data-classification matrix and detailed Subprocessor Register.
This Security Centre is a public summary. Signed agreements and the DPA govern where their terms differ.
Book demo