Security
Last updated September 1, 2026
Security is foundational to a compliance product. This page summarizes the controls we operate. If you have questions or need to report an issue, email security@prelienpro.com.
Infrastructure
- The Services run on Laravel Cloud, backed by AWS data centers in the United States.
- Compute, database, and cache tiers are isolated within a private network; the database is not publicly reachable.
- Infrastructure is provisioned through code and rebuilt from known-good images.
- Automated encrypted backups of the primary database are taken daily and retained on a rolling schedule, with point-in-time recovery available.
Encryption
- In transit: all traffic to the API and dashboard is served over TLS 1.2+. HTTP is redirected to HTTPS and HSTS is enabled.
- At rest: databases, backups, and object storage are encrypted with AES-256.
- Application secrets are stored in the platform secret manager, not in source control.
Authentication & access control
- API access uses per-key Bearer tokens (Laravel Sanctum). Keys are shown once, stored only as hashes, and can be revoked individually.
- Keys are scoped to an environment (sandbox or production) and to a single organization context.
- The multi-organization model links records through participant roles (sender, receiver, reviewer) rather than duplicating data, so access is enforced per relationship.
- Internal administrative access follows least privilege, requires individual accounts with multi-factor authentication, and is logged.
Application security
- All write endpoints use Form Request validation; responses are serialized through API Resources to avoid leaking internal fields.
- Public identifiers are UUIDs, not sequential integers.
- Per-tier rate limiting protects against abuse and runaway clients.
- Dependencies are monitored for known vulnerabilities and patched on a regular cadence.
- Changes go through code review and an automated test suite before deploy.
Auditing & monitoring
- An immutable audit trail records who changed what, and when, across core compliance objects.
- Application errors and performance are monitored with alerting; security-relevant events are reviewed.
- Webhook deliveries follow a retry-with-backoff schedule and a failure queue so integrators can detect problems.
Data handling
- Sandbox data is isolated from production and can be reset at any time.
- Payment card data is handled entirely by our PCI-compliant processor (Stripe); we never store full card numbers.
- Data retention follows the recordkeeping obligations that apply to construction payment compliance. See the Privacy Policy.
Responsible disclosure
We welcome reports from security researchers. Please email security@prelienpro.com with steps to reproduce. We ask that you:
- Give us a reasonable time to investigate and remediate before public disclosure;
- Avoid privacy violations, data destruction, and service degradation;
- Only test against your own account or the sandbox, never other customers’ data.
We will acknowledge your report, keep you updated on remediation, and credit you if you wish.
Contact
Prelien Pro — Security
security@prelienpro.com
Questions about this document? Email
legal@prelienpro.com
or contact us.