Security principles
Prodogon follows least privilege, defense in depth, secure defaults, auditability, change control, and clear operational ownership.
Prodogon is designed for teams that need a credible security posture from day one. This page summarizes our intended security practices and disclosure path.
Prodogon follows least privilege, defense in depth, secure defaults, auditability, change control, and clear operational ownership.
Access to production systems should use strong authentication, limited privileges, role-based permissions, and periodic access review.
Customer data should be encrypted in transit and at rest. Secrets should be stored in managed secret stores and never committed to source control.
Security-relevant activity should be logged, monitored, retained appropriately, and reviewed during incident response and post-incident learning.
Report suspected vulnerabilities to security@prodogon.com with enough detail to reproduce the issue. We ask researchers to avoid privacy violations, destructive testing, and service disruption.
Prodogon helps customers prepare evidence for compliance frameworks. Any Prodogon certification or audit status should be confirmed through current official documentation before being represented publicly.