Security

Security and trust

Proxon is built to help organizations understand and govern AI usage without creating a new blind spot. Security, access control, data minimization, auditability, and customer review readiness are core product requirements.

Encryption in transitTenant isolationLeast privilegeAudit trailsSecurity review support

Security overview

Proxon helps companies monitor AI tools, agents, prompts, workflows, costs, policies, and outcomes. Because that visibility can include sensitive operational metadata, our security model is designed around least privilege, tenant isolation, strong authentication, encryption, auditable access, and clear administrative controls.

Designed for enterprise visibility

Proxon centralizes AI usage records so teams can govern adoption, cost, and compliance from one system of record.

Built for controlled deployment

Collection options can be configured to match customer requirements, including integrations, proxy-based telemetry, browser-based collection, and desktop observer approaches where appropriate.

Prepared for security review

We support customer reviews with clear answers about architecture, data handling, access controls, subprocessors, retention, and incident response.

AI governance by design

Policies, approvals, alerts, evidence, and audit trails help security and compliance teams manage AI risk as usage changes.

Assurance and compliance readiness

Security reviews should not require guesswork. Proxon maintains customer-facing security materials and responds to vendor risk reviews with practical detail about controls, data flows, subprocessors, and deployment choices.

AvailableSecurity review responses

Architecture, data protection, access control, privacy, and operational security questionnaires.

AvailableDPA and legal review

Contractual privacy and data-processing materials for enterprise procurement workflows.

AvailableSubprocessor information

Reviewable vendor information covering the third-party services used to operate Proxon.

In progressSOC 2 readiness

Control mapping and evidence practices are being prepared for formal assurance review.

AI-specific security controls

  • Inventory and classification help teams understand which AI applications, agents, MCP servers, and workflows are active across the organization.
  • Policy workflows support approvals, exceptions, owner assignment, and evidence collection for governed AI usage.
  • Configurable alerts help surface shadow AI, cost anomalies, policy violations, sensitive data patterns, and risky tool behavior.
  • Collection modes are designed to be deployed intentionally, with scope, retention, and capture behavior aligned to customer requirements.
  • Customer administrators can use Proxon records to support AI risk, compliance, procurement, and board reporting workflows.

Data protection

  • Data is encrypted in transit using TLS.
  • Production data stores use encryption at rest where supported by infrastructure providers.
  • Customer data is logically separated by tenant.
  • We collect and retain only the data needed to provide the Service and support customer-configured retention policies.
  • Administrative tooling is designed to show sensitive records only to authorized roles.
  • We do not sell customer data, and we do not use customer data to train third-party models unless a customer explicitly configures or authorizes that use.

Access control

  • Customer administrators control who can access Proxon workspaces.
  • Role-based access control is used to limit access to sensitive views and actions.
  • Internal access to production systems is limited to authorized personnel with a business need.
  • Access is reviewed periodically and removed when no longer required.
  • Administrative access patterns are designed around least privilege, strong authentication, and accountable activity.

Infrastructure security

Proxon relies on reputable cloud and infrastructure providers for hosting, storage, analytics, communications, and security operations. We design systems to separate environments, limit production access, and support secure deployment workflows.

  • Production and non-production environments are separated.
  • Deployment and operational workflows are designed to reduce manual access to production data.
  • Infrastructure changes are handled through controlled engineering workflows.
  • Customer deployment patterns can be reviewed during onboarding for security and privacy fit.

Monitoring and auditability

  • Security-relevant administrative activity is designed to be logged.
  • Product audit trails help customers understand who changed policies, inventory records, alerts, and approvals.
  • Operational monitoring is used to detect reliability and security issues.
  • Customers can use Proxon evidence, alerts, and audit records to support internal governance workflows.

Incident response

Proxon maintains an incident response process for assessing, containing, investigating, and communicating security events. When an incident affects customer data or service availability, we work to notify affected customers in accordance with contractual, legal, and operational requirements.

  • Designated responders coordinate triage, severity assessment, remediation, and customer communication.
  • Evidence and timelines are retained to support post-incident review.
  • Findings from incidents and near misses are used to improve controls and operational practices.

Vendors and subprocessors

We use third-party service providers to operate the Service, such as cloud hosting, analytics, communication, and security vendors. Third parties are expected to protect data through contractual, technical, and organizational safeguards appropriate to the services they provide.

Security review materials

Customers and prospects can request security review materials, including architecture notes, data-flow answers, subprocessor details, privacy documentation, and completed security questionnaires when available.

Review packet

Security questionnaire answers, control summaries, data handling notes, and deployment information.

Customer-specific review

For sensitive deployments, we can review collection scope, retention expectations, access roles, and integration boundaries with your security team.

Responsible disclosure

If you believe you have discovered a security issue affecting Proxon, please contact us promptly. Include enough detail for us to reproduce and assess the issue. Do not access, modify, delete, or exfiltrate customer data while investigating.

Security contact

For security questions, vendor reviews, or responsible disclosure, contact security@vortexsoftware.com.