Security and Privacy at Proforma

Governance

Proforma's Legal and Technology Teams establish policies and controls, monitor compliance with those controls, and prove our security and compliance to third-party auditors.

Our policies are based on the following foundational principles:

  1. Access should be limited to only those with a legitimate business need and granted based on the principle of least privilege.
  2. Security controls should be implemented and layered according to the principle of defense-in-depth.
  3. Security controls should be applied consistently across all areas of the enterprise.
  4. The implementation of controls should be iterative, continuously maturing across the dimensions of improved effectiveness, increased auditability, and decreased friction.

Proforma maintains a SOC 2 Type II attestation. This is available to our customers upon request.

Data Protection

Product Security

Enterprise security

Once the inherent risk rating has been determined, the security of the vendor is evaluated in order to determine a residual risk rating and an approval decision for the vendor.

Data Privacy - At Proforma, data privacy is a first-class priority—we strive to be trustworthy stewards of all sensitive data.