Security

Enterprise-grade security built into every layer of the platform — included in every tier, with no security paywalls.

Probuck Workspace delivers enterprise-grade security as standard. Every subscription tier includes full access to all security features — from encryption and MFA to IP whitelisting, audit logs, and role-based access control.

Data Protection

Encryption Everywhere

All data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher (TLS 1.3 negotiated where supported). Organisation API keys are further protected with server-side pgcrypto.

Tenant Isolation

Multi-tenant architecture with strict org-scoped Row-Level Security ensures complete data isolation between organisations.

Backup & Recovery

7-day soft-delete recovery window for documents, plus bulk export of documents and workflows for portable, off-platform backups.

Access Control

Mandatory Multi-Factor Authentication

Strong password policy with server-side rate limiting and throttling. TOTP-based MFA is mandatory for every user, with built-in brute-force defences.

Role-Based Access Control

Granular permissions at the organisation, feature, and workflow level. Within an organisation, document access is uniformly open to members; cross-organisation access is structurally blocked by row-level security.

Password Custodianship

Passwords are bcrypt-hashed by our authentication provider in a reserved schema and are not accessible to probuck.ai staff, operators, or platform administrators — by design.

IP Whitelisting

Restrict access to your organisation's data from approved IP ranges only, with continuous activity-based enforcement.

Visibility & Auditability

Comprehensive Audit Logs

Full visibility into authentication events, document actions, workflow executions, and permission changes — retained for 365 days.

Retrieval Diagnostics

Every chatbot and workflow answer ships with a full diagnostics trail showing the exact retrieval path, sources, and token usage behind it.

Platform Hardening

DDoS Protection

The platform is fronted by Cloudflare's enterprise-grade DDoS mitigation, defending against network-layer and application-layer attacks.

Codebase Security

Multi-layered security checks across the full stack — dependency vulnerability scanning, static code analysis for injection risks and hardcoded secrets, database schema linting for RLS gaps, and type-safe static analysis.

Your data, your AI provider

probuck.ai is BYOK by design — your AI provider key, your data governance. Choose the tier that matches your compliance needs. We recommend paid-tier Google AI, Gemini Enterprise (formerly Vertex AI), or OpenRouter for production workloads to ensure your data is never used for model training.

FeatureGemini API — FreeGemini API — PaidGemini EnterpriseRecommendedOpenRouter
Data used for training?YesNoNoNo
SLA / SupportNoneLimitedEnterprise SupportOpenRouter SLA
Rate LimitsLowHigh (Pay-per-token)Very High (Quotas)High (Credit-based)
Data RetentionUp to 30 daysNot retainedNot retainedNot retained
Data Residency ControlNoNoYes (choose region)No
ComplianceNoneLimitedSOC 2, HIPAA, ISO 27001, FedRAMPSOC 2 (OpenRouter)
Setup EffortNoneAdd Credit CardGCP Project SetupAPI key only

Please refer to your providers terms of service for the latest details on data handling per tier.

Security Program Overview

Download our security overview below, or get in touch via the contact form for further information — including our data-handling addendum and enterprise requirements.