PRIME Logo

Security at PRIME

Your trust and data security are our top priorities. Learn about our comprehensive security measures.

Last updated: March 8, 2024

Security Overview

At PRIME, security is not just a featureβ€”it's the foundation of everything we do. We employ industry-standard security practices and continuous monitoring to protect your data and ensure the integrity of our platform. Our security program is built around encryption, access controls, audit logging, and GDPR-aligned data practices.

Our Security Pillars

Data Protection

End-to-end encryption for data at rest and in transit, with advanced key management systems.

Access Control

Role-based access control, multi-factor authentication, and principle of least privilege.

Continuous Monitoring

Automated security monitoring, threat detection, and alerting on our production infrastructure.

Infrastructure

Secure cloud infrastructure with redundancy, automated backups, and disaster recovery.

Compliance

Documented security practices aligned with industry standards and data protection regulations.

Team Security

Comprehensive security training, background checks, and secure development practices.

Technical Security Measures

Encryption & Data Protection

TLS 1.3 Encryption: All data in transit is encrypted using the latest TLS standards
AES-256 Encryption: Data at rest is encrypted using AES-256 bit encryption
Key Management: Hardware security modules (HSMs) for cryptographic key management
Perfect Forward Secrecy: Ensures past communications remain secure even if keys are compromised

Authentication & Access Control

Multi-Factor Authentication (MFA): Required for all administrative access
Passkey Support: Modern passwordless authentication with WebAuthn
Role-Based Access Control (RBAC): Granular permissions based on user roles
Session Management: Automatic session timeouts and secure session handling

Infrastructure & Network Security

Cloud Security: Hosted on secure cloud infrastructure with multiple availability zones
Web Application Firewall (WAF): Advanced threat protection and DDoS mitigation
Intrusion Detection: Real-time monitoring and automated response to threats
Regular Penetration Testing: Third-party security assessments conducted quarterly

Compliance & Data Protection

Encryption

Data encrypted in transit (TLS) and at rest

GDPR-Aligned

Data practices aligned with European privacy requirements

Payments via Stripe

Card data handled by a PCI DSS Level 1 processor

Audit Logging

Security-relevant events recorded for review

Access Controls

Role-based permissions across fleet, driver, and admin surfaces

Responsible Disclosure

Report vulnerabilities to our security team for prompt review

Incident Response & Breach Notification

Our Process

1
Detection & Assessment: Automated monitoring and manual oversight
2
Containment: Isolate affected systems and prevent further damage
3
Recovery: Restore systems and validate data integrity
4
Notification: Inform affected users within required timeframes

Notification Timeline

GDPR

Within 72 hours of becoming aware of the breach

CCPA

Without unreasonable delay, but no later than 45 days

General

As soon as possible after discovery and assessment

Security Best Practices for Users

Account Security

  • Enable multi-factor authentication (MFA)
  • Use strong, unique passwords
  • Regularly update your password
  • Monitor account activity

Device Security

  • Keep software and devices updated
  • Use antivirus software
  • Be cautious with public Wi-Fi
  • Enable device encryption

Security Contact & Reporting

Report a Security Concern

If you discover a security vulnerability or suspect unauthorized access to your account, please contact our security team immediately.

Email:

security@primetransit.com

Response:

We acknowledge and investigate every report.

Safe harbor:

We will not pursue action against good-faith research that does not access other users' data, degrade service, or publicly disclose before we can remediate.

Status:

Live platform status at primetransit.com/api-status

Vulnerability Disclosure Program

We run a responsible disclosure program. If you find a security vulnerability, we appreciate your help in keeping our platform secure.

Recognition

  • β€’ Public acknowledgment on this page (with your permission)
  • β€’ Prime Points platform credit for qualifying reports
  • β€’ Direct thanks from our security team

We do not offer cash rewards at this stage.

Security Updates & Transparency

We believe in transparency regarding our security practices and incidents. We publish security updates and post-incident reports whenever there is something to share, to keep our community informed.