Skip to main content
Platform Review
PricingSign in
← ProSights assessment

ProSights procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for ProSights
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown“ ProSights Labs Inc. maintains a SOC 2 Type I and Type II report covering security, availability, and confidentiality controls. A copy of the most recent report is available to enterprise customers under NDA.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow“ We may transfer PI to jurisdictions with different data protection laws. Where required, we use appropriate safeguards (e.g., EU Standard Contractual Clauses and UK Addendum) and conduct transfer risk assessments. Our primary hosting region is the United States.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow“ Authority. The Chief Technology Officer (CTO) is authorized by the Board to implement and enforce privacy and security programs. Management reporting. The team issues quarterly reports to executive leadership covering audit results, incidents, risk assessments, and remediation status. Monitoring & audits. We conduct annual penetration tests, routine vulnerability scanning, centralized logging/SIEM, and track findings to closure. Requests & referrals. All requests for personal information (from individuals, law enforcement, media, or others) are referred to trained personnel via support@prosights.co; employees and contractors complete annual security & privacy training. Suspicious attempts. Employees must report attempted social engineering or unauthorized PI requests to support@prosights.co immediately; events are logged for three months. Identity & access governance. Role-based access, MFA, least privilege, quarterly access reviews, segregation of duties, and centralized logging.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Physical security (hosting providers). Facilities employ 24×7 professional security, CCTV, badge access, and visitor logging. Asset & media controls. Devices are inventoried and encrypted; media is sanitized consistent with NIST 800-88 upon decommissioning. Identity & access. SSO + MFA, least privilege, quarterly access reviews, privileged session logging, and emergency break-glass procedures with approval and post-use review. Identity and access practices align to NIST 800-53 control families. Network & application security. Segmentation, WAF, rate limiting, secure configuration baselines, dependency monitoring, and security headers. Monitoring & response targets (non-contractual). Centralized logging/SIEM, alerting, and vulnerability management with target response objectives: P1 (critical) initial response ≤ 1 hour; containment ≤ 4 hours. P2 (high) initial response ≤ 4 hours. P3 (moderate/low) initial response next business day. Resilience. RTO 4 hours for critical services (AI systems included). RPO 1 hour via frequent backups and resilient storage.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersmedium“ We retain your personal information for as long as necessary to fulfill the purposes outlined in this privacy notice, unless a longer retention period is required or permitted by law. When we no longer need to retain your personal information, we will securely delete or anonymize it.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ We will maintain certain data that you transmit to the Services for the purpose of managing the performance of the Services, as well as data relating to your use of the Services. Although we perform regular routine backups of data, you are solely responsible for all data that you transmit or that relates to any activity you have undertaken using the Services. You agree that we shall have no liability to you for any loss or corruption of any such data, and you hereby waive any right of action against us arising from any such loss or corruption of such data.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersmedium“ We retain PI only as long as necessary for the purposes described, to satisfy legal, accounting, or reporting requirements, and for security/fraud prevention. When PI is no longer needed, it is deleted or de-identified. If immediate deletion is not possible (e.g., backups), PI is segregated and access-restricted until deletion. Retention criteria. We determine retention periods based on factors such as the amount, nature, and sensitivity of the data; potential risk from unauthorized use or disclosure; the purposes for which we process it and whether those purposes can be achieved through other means; applicable legal, regulatory, tax, accounting, or reporting requirements; and our security, fraud-prevention, resilience (RTO/RPO), and business continuity needs.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ We disclose PI to: Service providers and subprocessors under written agreements that restrict use to providing services to us and require appropriate security; Successors/assignees in connection with mergers, acquisitions, financings, or similar transactions; Authorities or other parties where required to comply with law, enforce terms, or protect rights/safety; and Others as directed or authorized by you. De-identified/aggregated/derived data may be used and disclosed as described in Section 3. We maintain measures to prevent re-identification and prohibit it contractually. We do not sell personal information or share it for cross-context behavioral advertising.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow“ California "Shine the Light." We do not disclose personal information for third-party direct marketing.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Identity, hosting, analytics, security, customer support, compute/inference, and payments providers may supply limited information needed to operate, secure, and support the Services. We do not purchase personal information from data brokers.”Captured 2026-09-25Open source →Finding permalink →
Tier differencesAll applicable tiersmedium“ This privacy notice for Prosights Labs, Inc. (doing business as "Prosights," "we," "us," or "our") describes how we collect, use, disclose, retain, protect, and dispose of personal information related to our websites, applications, and services (collectively, the "Services"). Enterprise scope: This notice does not apply to Enterprise Customer Data processed under a separate enterprise agreement and data processing addendum. We maintain a security and privacy program aligned with industry standards, including SOC 2 controls. We completed a SOC 2 Type II report on May 20, 2025. Contact: support@prosights.co ”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.