Security & trust FAQ
Answers to common enterprise security-review questions.
Answers to the questions that recur in enterprise vendor reviews. Where an answer depends on a business attestation we do not yet publish, it says so plainly — we do not claim a certification, insurance limit, or capability we cannot evidence.
Version 2026-08-02 (effective: not yet in effect).
Data handling
Do you store prompts or completions?
No. Durable storage is metadata-only (token counts, cost, status, timestamps). See the data-retention exhibit.
Do you train on customer data?
No. Customer Content is never used to train, fine-tune, or evaluate any model.
Where is data processed?
Inference and all retained metadata are in the United States. Any per-model processing region is stated on that model's card.
How long is metadata retained?
pending sign-off The billing ledger is append-only; retention duration and deletion terms are set in the DPA.
Security controls
Is data encrypted in transit?
Yes. TLS is terminated at the edge with HSTS on all customer hosts.
How are secrets and API keys handled?
API key secrets are shown once and stored only in hashed form; a process-wide scrubber redacts credential-shaped values before any log record is built.
Do you support SSO / SAML / SCIM for the console?
pending sign-off Enterprise SSO availability is confirmed by the business.
Do you enforce MFA for privileged access?
pending sign-off Administrative-access MFA posture is confirmed by the business.
Compliance & attestations
Do you have SOC 2 / ISO 27001?
pending sign-off Current attestation status is provided by the business.
Are you HIPAA-eligible / will you sign a BAA?
No. ProsGrow Serving does not sign BAAs and is not HIPAA-eligible; do not send PHI.
Will you sign a DPA?
A DPA is published at /legal/dpa (draft, pending counsel).
Do you carry cyber / E&O insurance?
pending sign-off Insurance coverage and limits are provided by the business.
Resilience & operations
What is your uptime SLA?
pending sign-off The committed SLA %, window, and credits are being finalized.
What are your RTO / RPO for disaster recovery?
pending sign-off Recovery objectives are confirmed by the business.
How do you notify customers of incidents?
pending sign-off Incident communication procedures and notification channels are being finalized.
Do you have a vulnerability-disclosure program?
Yes — see the disclosure policy and /.well-known/security.txt.
Detailed responses to a full security questionnaire are provided to enterprise prospects under NDA via support@prosgrow.ai. Report a vulnerability via the disclosure policy.