The short version
- Every company’s data is separated inside the database, not just in application code.
- Encrypted in transit and at rest. Hosted on Amazon Web Services in the United States.
- Two-step sign-in for you; mandatory for our staff. Every change is logged.
- Found a vulnerability? Write to security@pmt1.com.
This summary is for convenience. The full text below is what applies.
1. Separation between companies
PMT1 is a multi-company service, so the most important control is the wall between companies. Every row of customer data is tagged with its company, and PostgreSQL row-level security policies enforce that tag on every read and write. The application connects with a database role that cannot bypass those policies. If our own code ever forgot a filter, the database would still refuse to return another company’s data. We test this wall automatically on every release.
Inside a company, people see only the projects they have been added to, and what they can do there depends on their role.
2. Encryption
- In transit: all traffic uses TLS (HTTPS). Older, insecure protocol versions are disabled, and browsers are told to use HTTPS only.
- At rest: the database, file storage and backups are encrypted with AES-256 using keys managed by AWS.
- Passwords are never stored. We keep only a salted hash made with scrypt, a deliberately slow algorithm. Session and reset tokens are stored only as hashes.
3. Signing in
- Two-step sign-in (TOTP) with any authenticator app, for every user who turns it on.
- Repeated failed sign-ins lock the account for a period and are rate-limited by address.
- Resetting a password signs out every device.
- Email addresses are verified, and invited users choose their own passwords — administrators never see them.
- Sign-in cookies cannot be read by scripts, are sent only over HTTPS, and are restricted to our own site.
4. Application security
- A strict Content Security Policy blocks inline and third-party scripts; our pages load code only from our own domain.
- Cross-site request forgery protections on every state-changing request; clickjacking protection on every page.
- All input is validated on the server, and all database access uses parameterised queries.
- Uploaded files are stored privately, served only to signed-in users with access to that project, and never executed or rendered as active content.
- Rate limits protect sign-in, sign-up, password reset, forms and the assistant.
- We keep third-party code to a minimum, which keeps our software supply chain small.
5. Activity log
Every create, change, signature and deletion is recorded with who did it and when — including changes made by the AI assistant, which are marked as such. Owners and administrators can review the log in Settings.
6. Hosting and network
PMT1 runs on Amazon Web Services in the United States, in a private network that is not directly reachable from the internet. Traffic reaches it only through Cloudflare, which provides protection against denial-of-service attacks and malicious traffic. The database and file storage are not publicly accessible. AWS data centers are independently audited against SOC 1, SOC 2, SOC 3 and ISO 27001, among others.
7. Backups and recovery
The database is backed up automatically every day with point-in-time recovery, and backups are encrypted. File storage keeps prior versions of files so that accidental overwrites and deletions can be reversed. Projects you delete can be restored for 30 days. We test restoring from backup.
8. Our access to your data
Our staff do not look at customer data in the ordinary course. Access for support or operations is limited to the people who need it, requires two-step sign-in, and is logged. When support needs to see what you see, that session is time-limited and recorded in the activity log.
9. Payments
Card payments are handled entirely by Stripe, a PCI DSS Level 1 certified provider, on Stripe’s own pages. Card numbers never reach our servers.
10. AI assistant
The assistant runs on our servers with the permissions of the person using it and cannot reach another company’s data. Our API credentials for the AI provider never reach your browser. Content sent to the provider is not used for training. Details are in our AI Terms.
11. If something goes wrong
We monitor for errors and unusual activity. If we confirm a security incident that affected your data, we will notify the workspace owner without undue delay — and in any case within 72 hours of confirming it — with what happened, what was affected, and what we are doing about it.
12. Certifications
PMT1 is a young product and has not yet completed an independent security audit such as SOC 2. We would rather say so plainly than imply otherwise. We are happy to complete your security questionnaire — write to security@pmt1.com.
13. Reporting a vulnerability
If you believe you have found a security vulnerability in PMT1, please email security@pmt1.com with enough detail for us to reproduce it. We will acknowledge your report within 3 business days and keep you informed.
We will not pursue legal action against people who, in good faith: test only against accounts and workspaces they own; avoid accessing, changing or deleting other people’s data; do not degrade the service (no denial-of-service or volume-based testing, no social engineering, no physical attacks); and give us reasonable time to fix the issue before disclosing it. We do not currently run a paid bug-bounty program.
14. What you can do
- Turn on two-step sign-in, and ask your team to.
- Give people the lowest role that lets them do their job.
- Remove people from the team the day they leave.
- Never share a sign-in.
Questions about this page: security@pmt1.com