Security Policy
Last Updated: August 14, 2026
At ProvenTen ("ProvenTen," "we," "us," or "our"), security, data privacy, and European data sovereignty are embedded into the architecture of our enterprise reference management platform. Operating from Finland, we ensure that your customer proof points, advocate data, and internal sales intelligence are safeguarded by strict technical controls, modern encryption, and European data residency.
This Security Policy describes the Technical and Organizational Measures (TOMs) implemented by ProvenTen to protect customer data against unauthorized access, disclosure, loss, or alteration.
1. Infrastructure & EU Data Sovereignty
- 100% EU Data Residency: All primary customer data, application assets, relational databases, and automated system backups are hosted strictly within the European Union. Core platform data is never transferred cross-border outside the EU/EEA.
- Tier-4 Data Center Facilities: Our primary cloud infrastructure and managed database clusters are hosted in ISO 27001- and SOC 2-certified, Tier-4 data centers located in Helsinki, Finland and Frankfurt, Germany.
- Physical Security: Infrastructure facilities feature 24/7/365 physical security monitoring, biometric access controls, video surveillance, climate management, and redundant power and network feeds.
- GDPR Compliance: ProvenTen strictly complies with the EU General Data Protection Regulation (GDPR), incorporating privacy-by-design and privacy-by-default standards across all platform workflows.
2. Cryptographic & Encryption Standards
Data handled by ProvenTen is protected across all lifecycle stages using strong cryptographic protocols:
- Data in Transit: All communications between end-user browsers, API clients, CRM sync extensions (Salesforce, HubSpot, Dynamics 365, Pipedrive), and application endpoints are encrypted using TLS 1.3 (with TLS 1.2 supported as a fallback). HTTP Strict Transport Security (HSTS) is strictly enforced.
- Data at Rest: All customer databases, file assets, and system backups are encrypted at rest using AES-256 encryption. Cryptographic keys are managed securely with automated key rotation routines.
3. Identity, Authentication & Access Control
- Role-Based Access Control (RBAC): Granular permission controls inside the platform allow account administrators to define exact access levels for sales reps, revenue leaders, and advocate contacts.
- Single Sign-On (SSO): Enterprise accounts support SAML 2.0 and OpenID Connect (OIDC) Single Sign-On (Okta, Azure AD, Google Workspace).
- Multi-Factor Authentication (MFA): MFA is mandatory for all ProvenTen engineering, operational, and administrative personnel accessing internal or production environments.
- Least Privilege Access: Access to production infrastructure is restricted to authorized operational staff strictly on a need-to-know basis and is governed by strict identity management controls.
4. Application & Network Security
- Continuous Vulnerability Scanning: We run automated dependency scanning, static application security testing (SAST), and dynamic security audits continuously within our CI/CD deployment pipeline.
- Penetration Testing: ProvenTen undergoes regular third-party security assessments and penetration tests conducted by independent cybersecurity specialists.
- Perimeter Security & WAF: Web Application Firewalls (WAF) and automated DDoS mitigation guard our network perimeter against OWASP Top 10 web vulnerabilities and volumetric attacks.
5. System Availability, Backups & Disaster Recovery
- High Availability: Our platform architecture is deployed in multi-zone configurations with redundant network routing and automated service failover to ensure uninterrupted operation.
- Encrypted Daily Backups: Automated, encrypted database backups are taken daily and stored across geographically separated EU facilities (Helsinki and Frankfurt).
Disaster Recovery Metrics: Our Business Continuity and Disaster Recovery plans are regularly evaluated against:
- Recovery Point Objective (RPO): < 1 hour
- Recovery Time Objective (RTO): < 4 hours
6. Incident Management & Breach Notification
ProvenTen maintains a formal Incident Response Plan to swiftly detect, contain, investigate, and remediate potential security incidents:
- 24/7 Monitoring: Automated intrusion detection systems (IDS) and centralized security logging monitor our system components around the clock.
- GDPR Notification Commitment: In the event of a confirmed personal data breach impacting Customer Data, ProvenTen will notify affected customers and relevant supervisory authorities without undue delay and within 72 hours of confirmation, in compliance with GDPR Articles 33 and 34.
7. Employee Security & Endpoint Governance
- Security Awareness: All ProvenTen employees undergo mandatory security and data privacy training upon onboarding and annually thereafter.
- Confidentiality: Every team member and contractor is bound by legally enforceable non-disclosure and confidentiality obligations.
- Central Endpoint Management: Personnel hardware devices are centrally managed, fully encrypted, and protected by real-time anti-malware and endpoint detection software.
8. Third-Party Vendor Management
ProvenTen evaluates the security posture and data privacy practices of every third-party service provider prior to onboarding. All sub-processors handling Customer Data must execute a GDPR-compliant Data Processing Agreement (DPA) and enforce appropriate technical and organizational safeguards.
To view the live list of our authorized service providers, please visit our dedicated Sub-processors page.
9. Vulnerability Disclosure Policy
We appreciate reports from security researchers and community members. If you identify a potential security issue in ProvenTen:
- Email the details to security@proventen.com.
- Provide reproducible steps along with any relevant proof-of-concept material or screenshots.
- Please avoid disrupting live service operations or accessing data that does not belong to your test account.
We commit to acknowledging receipt within 2 business days and working transparently to validate and fix verified findings.
10. Contact Information
For security questions, compliance documentation requests, or security questionnaire submissions, please contact our security team:
ProvenTenAttn: Information Security
Axelia II
Agricolankatu 4
20520 Turku
Finland
Email: security@proventen.com