Personal Business Look closer How we work How we score Questions Security and trust Talk to us Sign in Book your audit
Protector Class Trust Centre

Security. Privacy.
Documented.

Our security architecture, compliance posture, data handling practices, and privacy commitments, transparently published in one place. No request required.

Current Compliance Status
FTC Compliant Active
CCPA / CPRA Compliant Active
AES-256 Encryption Active
Data Stays in North America Active
Zero Personal Information Post-Assessment Active
SOC 2 Type II Planned
Why Now

Cybercriminals move at AI speed. Trust posture should scale to match.

Cybercriminals use AI to enumerate targets, personalize phishing, and index breach data within hours of a leak. Protector Class's trust posture is designed for that pace: encryption at rest, a confidentiality agreement in both directions, a consent check before any scan of a named person, and a logged retention policy. Continuous coverage without ever storing what shouldn't be stored.

Compliance & Certifications

What We Are Certified For.

Our compliance posture aligns to PIPEDA, SEC Reg S-P, GLBA, FINRA, FTC Safeguards Rule, NIST CSF 2.0, and additional jurisdictional frameworks applicable to individual and business clients worldwide. Encryption standards and data residency requirements maintained across every engagement.

Active
FTC Act

Federal Trade Commission Act, the primary US federal law governing data security and privacy practices. All Protector Class data processing is fully compliant with FTC guidelines and enforcement standards.

Active
CCPA / CPRA

California Consumer Privacy Act and California Privacy Rights Act compliance for all US-resident users. Includes full right-to-deletion, opt-out of data sale, and disclosure rights.

Active
AES-256 Encryption

All data at rest is encrypted using AES-256. All data in transit is secured using TLS 1.3. Encryption keys are managed using industry-standard key management systems with no shared keys.

Active
North American Data Residency

All data processing, storage, and compute occurs within Canada and the United States. No data is transferred to, processed in, or accessible from outside North America.

Active
Zero Personal Information Retention

Personal identifiable information provided during a scan is not retained after report delivery. No user profiles. No persistent databases of scan subjects. We find your exposure, we do not become part of it.

Planned
SOC 2 Type II

We are not SOC 2 certified and no audit is underway. It is on the roadmap rather than in progress, and we would rather say so than imply otherwise. What is in place today is documented above and below: encryption at rest and in transit, role-based access, and a defined retention policy.

Security Architecture

How We Protect the Platform.

The technical and operational controls that govern how Protector Class systems are built, operated, and monitored.

01
Authentication
Multi-Factor Authentication & Access Controls

All internal system access requires multi-factor authentication. Role-based access controls restrict data access to the minimum required for each function. No standing administrative privileges, privileged access is just-in-time and fully logged.

02
Infrastructure
Isolated Production Environment

Production infrastructure is isolated from development and staging environments. All configuration changes are code-reviewed and deployed through automated pipelines. Unauthorized changes to production are automatically detected and escalated.

03
Encryption
End-to-End Encryption at Rest and in Transit

AES-256 encryption at rest for all stored data. TLS 1.3 for all data in transit. Encryption keys are held separately from encrypted data and are not stored in the application repository. No plaintext storage of sensitive identifiers.

04
Monitoring
Continuous Logging & Anomaly Detection

Application errors and exceptions are captured by a third-party monitoring service and alert us directly. Repeated failed logins are rate limited and the originating address is blocked automatically.

05
Development
Secure Development Lifecycle

All code changes undergo peer review before deployment. A pre-commit check blocks template and stylesheet defects that have previously reached production. Security reviews are required for all feature changes that touch data handling.

06
Testing
Independent Review

We have not commissioned an external penetration test of our own production environment, and no engagement is underway. What is in place is documented above: an isolated production environment, encryption at rest and in transit, role-based access, and a defined retention policy. Vulnerability reports about our own systems are welcome at security@protectorclass.com and are acknowledged within one business day.

Data Handling

What We Do With Your Data.

A precise statement of what data is collected, how long it is retained, and what happens to it after your scan or assessment is complete.

Scan Subject Data

Email addresses and domain inputs used to run a scan are retained, with the originating IP address, so we can measure demand and prevent abuse. They are purged on the schedule set out in our Privacy Policy. We do not sell them, and individual scanners who do not purchase are never sent marketing email.

Report Contents

Delivered reports are accessible via the dashboard for the duration of an active subscription. On cancellation, report data is deleted within 30 days. You may request immediate deletion at any time.

Account & Contact Information

Name, email, and payment information required to operate your account. Payment data is processed by Stripe and never stored on Protector Class systems. Account data is deleted on cancellation within 30 days.

Usage & Analytics

Anonymised usage data is collected to improve the platform. No user-identifiable information is included in analytics. Data is never sold or shared with third parties for advertising purposes.

Disclosure & Resources

Reporting & Documentation.

How to report a vulnerability, request compliance documentation, or exercise your privacy rights.

Responsible Disclosure
Report a security vulnerability in Protector Class infrastructure or products

If you have identified a potential security vulnerability in any Protector Class system, please contact our security team directly. We commit to acknowledging your report within 24 hours and providing a remediation timeline within 5 business days. We do not pursue legal action against good-faith researchers.

security@protectorclass.com
Compliance Documentation
Request our data processing agreement or written answers to a security questionnaire

Clients may request our data processing agreement, our retention and deletion policy, or written answers to a security questionnaire. We do not hold a third-party audit report and do not claim one. Documentation is shared under a confidentiality agreement. Contact us to initiate a request.

Request Documentation
Privacy Rights Requests
Exercise your PIPEDA or CCPA rights, deletion, access, or opt-out

You may request access to, correction of, or deletion of any personal information Protector Class holds about you. Requests are processed within 30 days. To opt out of communications, email us or reply STOP to any SMS.

privacy@protectorclass.com
Security Standards
Full technical security documentation and policy statements

Our public Security Standards page documents the full set of controls, policies, and procedures that govern the Protector Class platform, written for technical and compliance audiences.

Read Security Standards
Changelog

Recent Trust & Security Updates.

Material changes to our security posture, compliance status, or privacy practices, documented as they occur.

Sep 2026
No Mailbox Access, Anywhere in the Product

Protector Class offers no service that requires access to a customer’s mailbox. Every assessment and every monitoring check runs from outside, with nothing installed and no access to your systems or inbox.

Completed
Aug 2026
Security Headers Enforced on Every Response

HTTPS is enforced with HSTS at a one-year max-age. Content-Security-Policy and Permissions-Policy headers are sent on every page, and technology-identifying server headers are stripped.

Completed