Home
Legal

Security

Last updated: August 2026

Our Approach

We take the security of your account and data seriously and apply reasonable technical and organizational measures to protect it across the Service.

Encryption in Transit

All traffic between your browser and our servers is encrypted using HTTPS/TLS.

Account Security

  • Passwords are never stored in plaintext in your browser's local storage.
  • Use a strong, unique password — our sign-up form includes a live password-strength indicator to help with this.
  • New account registrations require administrator approval before they can sign in.

Access Controls

The Admin Panel, which can view and manage user accounts, is protected by a separate administrator login and is not indexed by search engines. Administrative API requests are authenticated with a secret issued only after a successful admin login.

Secure Data Handling

User-submitted content (such as account names) is escaped before being rendered in the Admin Panel and across the app to prevent script-injection attacks, and API responses are only rendered as plain text where they could otherwise contain untrusted content.

Responsible Disclosure

If you believe you've found a security vulnerability in ProspectInsight, please report it to us privately rather than disclosing it publicly, and give us a reasonable amount of time to investigate and address it before any public disclosure.

Report a Vulnerability

Email security@prospectinsight.app with details of the issue and steps to reproduce it. We aim to acknowledge reports promptly.