PRIME Logo

Security at PRIME

Your trust and data security are our top priorities. Learn about our comprehensive security measures.

Last updated: March 8, 2024

Security Overview

At PRIME, security is not just a feature—it's the foundation of everything we do. We employ industry-leading security practices, regular audits, and continuous monitoring to protect your data and ensure the integrity of our platform. Our security program is designed to meet and exceed industry standards including SOC 2, GDPR, and HIPAA compliance where applicable.

Our Security Pillars

Data Protection

End-to-end encryption for data at rest and in transit, with advanced key management systems.

Access Control

Role-based access control, multi-factor authentication, and principle of least privilege.

24/7 Monitoring

Continuous security monitoring, automated threat detection, and rapid incident response.

Infrastructure

Secure cloud infrastructure with redundancy, automated backups, and disaster recovery.

Compliance

Regular audits, certifications, and adherence to industry standards and regulations.

Team Security

Comprehensive security training, background checks, and secure development practices.

Technical Security Measures

Encryption & Data Protection

TLS 1.3 Encryption: All data in transit is encrypted using the latest TLS standards
AES-256 Encryption: Data at rest is encrypted using AES-256 bit encryption
Key Management: Hardware security modules (HSMs) for cryptographic key management
Perfect Forward Secrecy: Ensures past communications remain secure even if keys are compromised

Authentication & Access Control

Multi-Factor Authentication (MFA): Required for all administrative access
Passkey Support: Modern passwordless authentication with WebAuthn
Role-Based Access Control (RBAC): Granular permissions based on user roles
Session Management: Automatic session timeouts and secure session handling

Infrastructure & Network Security

Cloud Security: Hosted on secure cloud infrastructure with multiple availability zones
Web Application Firewall (WAF): Advanced threat protection and DDoS mitigation
Intrusion Detection: Real-time monitoring and automated response to threats
Regular Penetration Testing: Third-party security assessments conducted quarterly

Security Certifications & Compliance

SOC 2 Type II

Security, availability, and confidentiality controls

GDPR Compliant

European data protection regulation compliance

ISO 27001

Information security management systems

PCI DSS

Payment card industry security standards

HIPAA Ready

Healthcare data protection compliance

CSA STAR

Cloud security alliance security framework

Incident Response & Breach Notification

Our Process

1
Detection & Assessment: Automated monitoring and manual oversight
2
Containment: Isolate affected systems and prevent further damage
3
Recovery: Restore systems and validate data integrity
4
Notification: Inform affected users within required timeframes

Notification Timeline

GDPR

Within 72 hours of becoming aware of the breach

CCPA

Without unreasonable delay, but no later than 45 days

General

As soon as possible after discovery and assessment

Security Best Practices for Users

Account Security

  • Enable multi-factor authentication (MFA)
  • Use strong, unique passwords
  • Regularly update your password
  • Monitor account activity

Device Security

  • Keep software and devices updated
  • Use antivirus software
  • Be cautious with public Wi-Fi
  • Enable device encryption

Security Contact & Reporting

Report a Security Concern

If you discover a security vulnerability or suspect unauthorized access to your account, please contact our security team immediately.

Security Hotline:

1-800-PRIME-SEC (24/7)

Email:

security@primetransit.com

PGP Key:

Available for secure communications

Bug Bounty Program

We run a responsible disclosure program. If you find a security vulnerability, we appreciate your help in keeping our platform secure.

Rewards

  • • Critical vulnerabilities: $5,000 - $10,000
  • • High severity: $2,000 - $5,000
  • • Medium severity: $500 - $2,000
  • • Low severity: Recognition & swag

Security Updates & Transparency

We believe in transparency regarding our security practices and incidents. We regularly publish security updates, threat intelligence, and post-incident reports to keep our community informed.