— Trust Center
Bank-grade encryption. PCI-DSS-compliant payments via Stripe. SOC 2 Type II in progress. Here’s everything we do to protect your business and your clients’ data — with receipts.
256-bit SSL / TLS 1.3
All traffic encrypted end-to-end via HSTS + automatic HTTPS redirect.
VerifyPCI-DSS Compliant
Card data never touches ProChair servers. Payments handled by Stripe (PCI DSS Level 1 Service Provider).
VerifySOC 2 Type II
Annual audit of security, availability, confidentiality controls by a Big-Four-affiliated CPA firm.
GDPR Ready
Data subject access, right to erasure, data portability. DPA available for EU business customers.
VerifyCCPA Compliant
Do-not-sell opt-out honored. Data sale disclosure. Covered business & consumer rights.
VerifyVulnerability Disclosure
Responsible disclosure program. Safe harbor for good-faith security research.
Verify— Data handling
— Sub-processors
A sub-processor is a third-party service we use to run ProChair. Everyone below is contractually bound to our Data Processing Agreement.
| Service | Purpose |
|---|---|
| Stripe | Payment processing, payouts, KYC |
| Supabase | Primary database + authentication |
| Vercel | Application hosting + edge delivery |
| Twilio / Tylynx | Transactional SMS for booking reminders |
| Resend / Brevo | Transactional email |
| Anthropic, OpenAI | AI features (receptionist, content studio) |
| Google Maps / Places | Location + business discovery |
| Mapbox | Map rendering |
This list is the source of truth. Subscribe to the changelog for updates (we give 30 days notice on new sub-processors).
— Report a vulnerability
We run a responsible disclosure program with safe harbor for good-faith security research. Send details (repro steps, impact, suggested fix) to the email below. First-response SLA: 24 hours. We don’t offer cash bounties yet but we publicly credit reporters in our hall of fame.
security@prochair.appPGP key: 0xA3F8 1E2C
— What we commit to
Enterprise customers can request a security questionnaire (SIG, CAIQ), DPA, and a call with our security lead.