How PracticPro protects customer data across our infrastructure, applications, and staff.
This page summarizes the technical and organizational security measures PracticPro uses to protect customer data. It is intended to be readable by privacy and security professionals as well as the business owners who are our customers. For the full contractual commitments, see our Data Processing Addendum.
PracticPro is hosted on DigitalOcean in the United States. Production compute, databases, file storage, and encrypted backups all live within DigitalOcean's infrastructure. DigitalOcean maintains industry-standard physical security controls and is independently audited (SOC 2, ISO 27001).
All public traffic to PracticPro is routed through Cloudflare for TLS termination, DDoS protection, and content delivery. We enforce HTTPS-only access with HSTS preload.
All connections to and from PracticPro use TLS 1.2 or higher. We do not accept unencrypted connections. Internal service-to-service traffic is also encrypted.
Customer data stored in our production databases, file storage, and backups is encrypted at rest using industry-standard algorithms (AES-256). Encryption keys are managed by our infrastructure provider and rotated according to provider best practice.
Customer users authenticate with username and password and may enable multi-factor authentication. Within a customer account, access to records is governed by role-based permissions configurable by the account administrator.
Access to customer data by PracticPro personnel is restricted to those with a documented business need (for example, to provide support requested by the customer or to investigate a security incident). Such access is logged.
Direct access to production servers and databases is limited to a small set of authorized engineers, secured with strong authentication and audit logging.
Every third party that touches customer data is engaged under a written agreement that imposes data-protection obligations no less protective than those we owe our customers. The current list of sub-processors is published at practicpro.com/trust/sub-processors. We provide at least 30 days advance notice before adding a new sub-processor.
We maintain documented incident response procedures covering triage, containment, communication, remediation, and post-incident review.
In the event of a Personal Data Breach affecting a customer's data, we will notify the affected customer without undue delay, and in any event no later than 72 hours after becoming aware. Details of what the notice will contain are set out in Section 8 of our DPA.
To report a suspected security issue, see our Vulnerability Disclosure page.
Customer data is processed in the United States. Where customer data of EEA, UK, or Swiss residents is transferred to the United States, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent Swiss mechanisms apply, as incorporated into our DPA.
Processor obligations met via our DPA, including 72-hour breach notification, sub-processor controls, and SCC-based international transfers.
Service Provider obligations met via our DPA and Privacy Policy.
Independent third-party attestation of our security controls.
Information security management system certification.
PracticPro does not currently support HIPAA-covered use cases and does not sign Business Associate Agreements. The Services should not be used to store Protected Health Information.
Security is a shared responsibility. PracticPro secures the platform; customers are responsible for:
To report a suspected security issue, email security@practicpro.com and see our Vulnerability Disclosure page. For privacy or data-protection questions, email privacy@practicpro.com.