How we handle
your data and access.
We work inside regulated environments for a living — banks, insurers, healthcare systems, and SaaS businesses with their own enterprise buyers to answer to. This page is the short version of the security questionnaire we fill out every week.
Practical controls before badge language.
Security-aware delivery
Client systems are handled with documented access rules, secure delivery practices, and clear ownership for security-sensitive decisions.
Access governance
We keep access scoped to the engagement, use MFA where systems support it, and document production access paths before delivery starts.
GDPR-aligned delivery
We support data-processing review for EU / UK clients and document residency, retention, access, and sub-processor expectations during engagement setup.
HIPAA-aware engagements
For healthcare clients, we minimize PHI exposure, document access paths, and align tooling choices with the privacy and audit needs of the workflow.
The controls behind the delivery model.
People
- Background checks for all staff touching client systems
- Annual security awareness and role-based training
- Named security owner for each client engagement
- Documented onboarding and offboarding procedures
Access
- SSO with MFA required across all corporate systems
- Just-in-time access to client production systems
- Zero standing privileged access; break-glass audited
- Client-specific VPN and segmented workstations when required
Platforms
- Endpoint detection and response on every workstation
- Centralized logging with tamper-evident storage
- Encryption at rest and in transit for all data we hold
- Vulnerability management with documented response expectations
Delivery
- Security review built into delivery planning
- Dependency and release checks where the engagement requires them
- Pre-production vulnerability review before go-live
- Incident response runbooks with named owners
Found something?
If you've identified a security issue on this website or in any Prometheas-operated system, email security@prometheastech.com — ideally with PGP (fingerprint on request).
We acknowledge within two business days, investigate, and commit to fixing genuine issues under a coordinated-disclosure timeline. We don't pursue legal action against good-faith researchers.
