Security overview
Proxon helps companies monitor AI tools, agents, prompts, workflows, costs, policies, and outcomes. Because that visibility can include sensitive operational metadata, our security model is designed around least privilege, tenant isolation, strong authentication, encryption, auditable access, and clear administrative controls.
Designed for enterprise visibility
Proxon centralizes AI usage records so teams can govern adoption, cost, and compliance from one system of record.
Built for controlled deployment
Collection options can be configured to match customer requirements, including integrations, proxy-based telemetry, browser-based collection, and desktop observer approaches where appropriate.
Prepared for security review
We support customer reviews with clear answers about architecture, data handling, access controls, subprocessors, retention, and incident response.
AI governance by design
Policies, approvals, alerts, evidence, and audit trails help security and compliance teams manage AI risk as usage changes.
Assurance and compliance readiness
Security reviews should not require guesswork. Proxon maintains customer-facing security materials and responds to vendor risk reviews with practical detail about controls, data flows, subprocessors, and deployment choices.
Architecture, data protection, access control, privacy, and operational security questionnaires.
Contractual privacy and data-processing materials for enterprise procurement workflows.
Reviewable vendor information covering the third-party services used to operate Proxon.
Control mapping and evidence practices are being prepared for formal assurance review.
AI-specific security controls
- Inventory and classification help teams understand which AI applications, agents, MCP servers, and workflows are active across the organization.
- Policy workflows support approvals, exceptions, owner assignment, and evidence collection for governed AI usage.
- Configurable alerts help surface shadow AI, cost anomalies, policy violations, sensitive data patterns, and risky tool behavior.
- Collection modes are designed to be deployed intentionally, with scope, retention, and capture behavior aligned to customer requirements.
- Customer administrators can use Proxon records to support AI risk, compliance, procurement, and board reporting workflows.
Data protection
- Data is encrypted in transit using TLS.
- Production data stores use encryption at rest where supported by infrastructure providers.
- Customer data is logically separated by tenant.
- We collect and retain only the data needed to provide the Service and support customer-configured retention policies.
- Administrative tooling is designed to show sensitive records only to authorized roles.
- We do not sell customer data, and we do not use customer data to train third-party models unless a customer explicitly configures or authorizes that use.
Access control
- Customer administrators control who can access Proxon workspaces.
- Role-based access control is used to limit access to sensitive views and actions.
- Internal access to production systems is limited to authorized personnel with a business need.
- Access is reviewed periodically and removed when no longer required.
- Administrative access patterns are designed around least privilege, strong authentication, and accountable activity.
Infrastructure security
Proxon relies on reputable cloud and infrastructure providers for hosting, storage, analytics, communications, and security operations. We design systems to separate environments, limit production access, and support secure deployment workflows.
- Production and non-production environments are separated.
- Deployment and operational workflows are designed to reduce manual access to production data.
- Infrastructure changes are handled through controlled engineering workflows.
- Customer deployment patterns can be reviewed during onboarding for security and privacy fit.
Monitoring and auditability
- Security-relevant administrative activity is designed to be logged.
- Product audit trails help customers understand who changed policies, inventory records, alerts, and approvals.
- Operational monitoring is used to detect reliability and security issues.
- Customers can use Proxon evidence, alerts, and audit records to support internal governance workflows.
Incident response
Proxon maintains an incident response process for assessing, containing, investigating, and communicating security events. When an incident affects customer data or service availability, we work to notify affected customers in accordance with contractual, legal, and operational requirements.
- Designated responders coordinate triage, severity assessment, remediation, and customer communication.
- Evidence and timelines are retained to support post-incident review.
- Findings from incidents and near misses are used to improve controls and operational practices.
Vendors and subprocessors
We use third-party service providers to operate the Service, such as cloud hosting, analytics, communication, and security vendors. Third parties are expected to protect data through contractual, technical, and organizational safeguards appropriate to the services they provide.
Security review materials
Customers and prospects can request security review materials, including architecture notes, data-flow answers, subprocessor details, privacy documentation, and completed security questionnaires when available.
Review packet
Security questionnaire answers, control summaries, data handling notes, and deployment information.
Customer-specific review
For sensitive deployments, we can review collection scope, retention expectations, access roles, and integration boundaries with your security team.
Responsible disclosure
If you believe you have discovered a security issue affecting Proxon, please contact us promptly. Include enough detail for us to reproduce and assess the issue. Do not access, modify, delete, or exfiltrate customer data while investigating.
Security contact
For security questions, vendor reviews, or responsible disclosure, contact security@vortexsoftware.com.