Security & trust

Compliance data deserves compliance-grade controls

Protocore holds risk registers, audit findings and policy records — the exact material a firm cannot afford to leak. Security is designed into the data layer, not bolted on at the front end.

Strong authentication

Password-first sign-in with enforced multi-factor authentication, plus Microsoft Entra ID single sign-on for enterprise tenants.

Workspace isolation

Each client or legal entity is a separate workspace. Access is granted per workspace and enforced in the database, not just in the interface.

Row-level access control

Every table is protected by row-level security policies tied to workspace membership and role, so a query cannot reach data outside its scope.

Audit trails

Security events and record changes are logged with actor, timestamp and context, giving you a reviewable history of who did what.

Encryption and hosting

Data is encrypted in transit and at rest on managed EU infrastructure, with automated backups and least-privilege service credentials.

Least-privilege roles

Consultant, client admin, contributor, internal auditor and read-only roles limit what each user can see and change, including invitation limits per contract.

Intelligent assistance and data handling

Suggested risks, controls and actions are generated from your workspace records and from curated reference material. They are proposals: a human reviews and approves before anything is written to a register, and every approval is recorded.

Workspace content is not used to train third-party models. Where a request needs an external model, only the material required to answer it is sent, and enterprise deployments can restrict which knowledge sources are available.

Reporting a vulnerability

If you believe you have found a security issue, contact us before disclosing it publicly. We will acknowledge your report and keep you updated on the fix.