Skip to main content
Protegon
Compliance · governanceDocument

Compliance, security, and governance

This page outlines the compliance and security principles applied to our SaaS/cloud platform, at a level of detail suitable for customers, partners, and auditors. It also clarifies our authorized scanning policy: you must only scan targets you own or have written permission to test.

0. Authorized scanning policy (scope)

Protegon is built for repeatable audits of your own internet-exposed assets.

It is not permission to test third-party systems. Unauthorized scanning may be illegal and is prohibited by our Terms and policy.

  • Only scan targets you control, or where you have explicit written authorization.
  • Stay within agreed scope (hostnames, environments, and time windows).

1. Data hosting

Our platform runs on Amazon Web Services (AWS), chosen for resilience and its ability to operate critical services at scale.

The architecture is designed for high availability, with redundancy for essential components and recovery mechanisms after incidents.

Production data is hosted in regions located in the European Union to support data sovereignty and GDPR-aligned requirements.

2. Security and encryption

Traffic between users, APIs, and internal services is protected in transit using TLS 1.2/1.3.

Data at rest is encrypted using industry-standard algorithms (AES-256) to reduce risk from unauthorized physical or logical access.

Cryptographic key management is centralized in AWS KMS with strict access policies and usage auditing.

3. Access management

Permissions follow least privilege: each identity only receives the rights required for its role.

Sensitive access is strengthened with strong authentication (MFA), including for administrative accounts.

Identity and authorization are governed with AWS IAM, with separation of technical and operational roles.

  • Logging of administrative actions and privileged access.
  • Audit capabilities to review changes and security-relevant events.

4. Certifications and compliance

We rely on the AWS compliance framework, including ISO 27001, ISO 27017, ISO 27018, and SOC 1, SOC 2, and SOC 3 reports.

These frameworks demonstrate sound practices for cloud operations governance, security, and data protection.

Our approach also incorporates GDPR principles, including data minimization, transparency, and securing processing activities.

5. Backup and business continuity

Critical data is backed up automatically, with retention policies aligned to the expected service level.

A disaster recovery plan defines how essential functions are restored within controlled timeframes.

Periodic tests validate restoration and recovery procedures.

6. Monitoring and incident management

The platform is monitored continuously with real-time tooling for availability, performance, and application errors.

Anomaly detection helps identify unusual behavior quickly and trigger the right investigations.

Incidents follow a formal process covering triage, resolution, communication, and lessons learned.

7. Additional good practices

We maintain strict separation of environments (development, test, production) to limit error propagation or inappropriate access.

Application and system components are updated regularly to address known vulnerabilities.

  • Security audits and penetration testing commensurate with risk.
  • Ongoing awareness for teams on cyber and compliance topics.

Summary

By combining a leading cloud infrastructure, structured security controls, and rigorous operational governance, we maintain a high level of trust for data protection and service continuity.

Compliance | Protegon