Compliance data deserves compliance-grade controls
Protocore holds risk registers, audit findings and policy records — the exact material a firm cannot afford to leak. Security is designed into the data layer, not bolted on at the front end.
Strong authentication
Password-first sign-in with enforced multi-factor authentication, plus Microsoft Entra ID single sign-on for enterprise tenants.
Workspace isolation
Each client or legal entity is a separate workspace. Access is granted per workspace and enforced in the database, not just in the interface.
Row-level access control
Every table is protected by row-level security policies tied to workspace membership and role, so a query cannot reach data outside its scope.
Audit trails
Security events and record changes are logged with actor, timestamp and context, giving you a reviewable history of who did what.
Encryption and hosting
Data is encrypted in transit and at rest on managed EU infrastructure, with automated backups and least-privilege service credentials.
Least-privilege roles
Consultant, client admin, contributor, internal auditor and read-only roles limit what each user can see and change, including invitation limits per contract.
Intelligent assistance and data handling
Suggested risks, controls and actions are generated from your workspace records and from curated reference material. They are proposals: a human reviews and approves before anything is written to a register, and every approval is recorded.
Workspace content is not used to train third-party models. Where a request needs an external model, only the material required to answer it is sent, and enterprise deployments can restrict which knowledge sources are available.
Reporting a vulnerability
If you believe you have found a security issue, contact us before disclosing it publicly. We will acknowledge your report and keep you updated on the fix.