We take the security of your account and data seriously and apply reasonable technical and organizational measures to protect it across the Service.
All traffic between your browser and our servers is encrypted using HTTPS/TLS.
The Admin Panel, which can view and manage user accounts, is protected by a separate administrator login and is not indexed by search engines. Administrative API requests are authenticated with a secret issued only after a successful admin login.
User-submitted content (such as account names) is escaped before being rendered in the Admin Panel and across the app to prevent script-injection attacks, and API responses are only rendered as plain text where they could otherwise contain untrusted content.
If you believe you've found a security vulnerability in ProspectInsight, please report it to us privately rather than disclosing it publicly, and give us a reasonable amount of time to investigate and address it before any public disclosure.
Email security@prospectinsight.app with details of the issue and steps to reproduce it. We aim to acknowledge reports promptly.