1. Local-first architecture
Many Prapl tools are built so your files, server credentials, database contents and backups stay on your own machines and storage, under your own keys. We design our software so that this data never leaves your control and we cannot see it. This is the single most important security property of our products: the data we never receive is data that cannot be breached at our end.
2. Encryption
We use encryption in transit (TLS) for connections to our website and services. Where our tools store credentials or create backups, they support encryption so your sensitive material is protected at rest under keys you control.
3. Access control
Access to the limited systems that hold account and billing data is restricted on a least-privilege basis, protected by strong authentication, and logged. Only personnel who need access for support or operations have it.
4. Infrastructure
Our website and cloud services run on reputable providers with strong physical and network security. We keep systems patched and monitor for anomalies.
5. Payments
Payments are handled by established third-party payment processors. We do not store full payment card numbers on our systems.
6. Secure development practices
We follow secure development practices, review changes before release, and keep dependencies up to date. We aim to respond quickly to security issues affecting our products.
7. Shared responsibility
Security is a partnership. You are responsible for keeping your devices, accounts and encryption keys secure, using strong unique passwords, keeping the Software updated, and maintaining independent backups of important data before running data-affecting operations.
8. Reporting a vulnerability
If you believe you've found a security vulnerability in a Prapl product or on our website, please report it responsibly to [email protected]. Include enough detail to reproduce the issue, and give us a reasonable time to investigate and fix it before public disclosure. We appreciate coordinated disclosure and will keep you updated.
9. Contact us
Security questions or reports: [email protected].