Skip to content

Security & trust

What we do to protect your clients' work

Client work means holding other organisations' confidential material. This page sets out the controls we operate, where your data sits, and what we have not yet done. The last part matters as much as the first.

We do not hold a completed third-party certification

No SOC 2 report, no ISO 27001 certificate. We are working towards a formal audit, and until it exists we will not imply otherwise on a trust page or in a sales conversation. Our controls are designed around the practices those frameworks describe, they are documented below, and Enterprise customers receive a completed security questionnaire covering each control area with its current status. If a certification is a hard requirement for your procurement process, tell us early and we will say plainly whether we can meet your timeline.

Controls

Nine control areas, stated specifically

Vague reassurance is not useful during a security review, so each area lists the actual measures rather than a description of our attitude.

Encryption

Your project data is encrypted on the wire and on disk, including backups.

  • TLS 1.2 or higher enforced for all connections, with HTTP requests redirected to HTTPS
  • HTTP Strict Transport Security enabled across all domains
  • Data encrypted at rest using AES-256 at the storage layer
  • Backup snapshots encrypted with keys separate from the primary datastore
  • Encryption keys managed by the cloud provider key management service, rotated on a defined schedule

Authentication

Account access is protected by modern authentication with optional enterprise controls.

  • Passwords hashed with a memory-hard algorithm and never stored or logged in plain text
  • Two-factor authentication available on every plan and enforceable workspace-wide
  • SAML 2.0 single sign-on and SCIM provisioning on Enterprise
  • Session invalidation on password change, and administrator-initiated session revocation
  • Rate limiting and progressive lockout on authentication endpoints

Authorisation and access

Permissions are enforced per item, so shared views cannot leak internal work.

  • Role-based access control with standard roles on all plans and custom roles on Enterprise
  • Every task, comment and file carries an internal or shared visibility state, defaulting to internal
  • Client collaborators are scoped to the projects they are invited to and cannot see financial data
  • Authorisation checked server-side on every request rather than enforced in the interface
  • Scoped API tokens with least-privilege permissions and independent revocation

Tenancy and isolation

Workspace data is separated at the query layer and validated by automated tests.

  • Every data access path is scoped by workspace identifier at the persistence layer
  • Automated cross-tenant access tests run on every deployment
  • Production, staging and development environments are fully separate with no shared data
  • Production data is never copied into development environments

Infrastructure

We run on established cloud providers and keep the attack surface small.

  • Managed cloud infrastructure with physical security and environmental controls handled by the provider
  • Private networking between application and database tiers, with no public database exposure
  • Infrastructure defined as code and peer reviewed before it is applied
  • Dependency and container scanning in continuous integration, with severity-based patch timelines
  • Administrative access requires multi-factor authentication and is limited to named personnel

Backups and resilience

Regular tested backups in a separate region, with a defined recovery position.

  • Automated encrypted database backups with point-in-time recovery
  • Backup copies replicated to a geographically separate region
  • Restore procedures exercised on a scheduled basis rather than assumed to work
  • Target recovery point of one hour and target recovery time of four hours for a regional failure

Logging and audit

Security-relevant events are recorded, retained and available to you.

  • Audit log of authentication, permission changes, sharing changes and approvals
  • Audit retention of 90 days on Starter, one year on Pro, and configurable with export on Enterprise
  • Application and infrastructure logs centralised with restricted access
  • Approval and change request decisions retained for the life of the project record

Incident response

A written procedure, a defined notification commitment, and no quiet incidents.

  • Documented incident response procedure with defined severity levels and named owners
  • Affected customers notified without undue delay and within 72 hours of confirming a personal data breach
  • Post-incident review for significant incidents, with the resulting corrective actions tracked
  • Status communication to account owners during service-affecting events

Secure development

Security is part of the change process rather than a periodic review.

  • Peer review required on every change before it reaches production
  • Automated static analysis and dependency vulnerability checks in continuous integration
  • Secrets held in a managed secret store, never in source control
  • Personnel background appropriate to role, with security training and least-privilege access provisioning
  • Access revoked promptly when someone changes role or leaves

Data residency

Where your project data lives

Workspaces are hosted in the region you choose at creation. If you have a residency obligation, raise it before you commit rather than after.

  • Primary hosting region is selected per workspace at creation, from the United States, Singapore or Hong Kong SAR.
  • Encrypted backups are replicated to a second region for resilience. That region is always within the same broad geography as the primary where our provider supports it.
  • Support and engineering personnel may access production data only where necessary to resolve an issue you have raised, under logged and time-limited access.
  • International transfers rely on the mechanisms set out in our data processing addendum, including standard contractual clauses where applicable.

Every third party that processes data on our behalf is named on our sub-processor list, along with what it is used for and which regions it operates in.

Regulatory posture

Where we stand on each framework

Supported means we meet the obligations and can evidence how. Not yet held means exactly that.

Third-party certification

Not yet held

We do not currently hold a completed SOC 2 or ISO 27001 report, and we will not imply that we do. Our controls are designed around the practices those frameworks describe, and we are working towards a formal audit. Enterprise customers receive a completed security questionnaire covering each control area with its current status.

GDPR and UK GDPR

Supported

We act as a processor for the project data you put into Projexio. A data processing addendum is available on every plan, covering processing purposes, sub-processors, international transfer safeguards, security measures and breach notification. We support data subject access, correction, deletion and portability requests.

Hong Kong PDPO

Supported

Our handling of personal data follows the six data protection principles of the Personal Data (Privacy) Ordinance, including purpose limitation, accuracy, retention limits, security and access rights. Our privacy notice states what we collect, why, and how to exercise your rights.

Singapore PDPA

Supported

We meet the consent, purpose limitation, notification, access, correction, protection and retention obligations of the Personal Data Protection Act, and we will notify you of a data breach in line with the mandatory notification requirements.

US state privacy laws

Supported

We honour access, deletion, correction and opt-out rights under the California Consumer Privacy Act as amended, and equivalent rights under other state privacy statutes. We do not sell personal information and we do not share it for cross-context behavioural advertising.

Accessibility

In progress

We target WCAG 2.1 Level AA. Keyboard navigation, focus visibility, semantic structure and colour contrast are reviewed as part of interface work. We are not claiming full conformance, and we will fix reported barriers as a priority.

Responsible disclosure

If you have found a vulnerability, we want to hear about it. Email support@projexio.org with enough detail to reproduce the issue.

What we commit to

  • Acknowledge your report within two business days
  • Keep you updated while we investigate
  • Credit you if you would like to be credited
  • Take no action against good-faith research

What we ask of you

  • Do not access, modify or exfiltrate other people's data
  • Do not degrade the service for other customers
  • Give us reasonable time to fix it before publishing
  • Avoid social engineering and physical attacks

Questions

Security and data questions

Need to run this past your security team?

Send us the questionnaire. We will complete it, flag anything we cannot yet meet, and put you in touch with someone who can answer follow-up questions properly.

Suspected vulnerabilities are treated as urgent regardless of plan.