Security & Responsible Disclosure

Last updated Jul 27, 2026

Draft for legal review. This document is a template and has not been reviewed by counsel. Do not treat it as final legal advice until it has been reviewed and finalized.

Progma, Inc. ("Progma") takes the security of the Service and the data entrusted to us seriously. This page summarizes our security practices and explains how to report a vulnerability responsibly.

Placeholder — confirm with engineering and counsel: any formal certifications and the precise scope of testing permitted.

Our security practices

We maintain technical and organizational measures designed to protect the Service, which may include:

  • role-based access control and least-privilege authorization;
  • logical isolation between institution tenants;
  • encryption of data in transit;
  • secure storage of credentials;
  • optional two-factor authentication using time-based one-time passwords (TOTP) for accounts that sign in with a password, and mandatory two-factor authentication for Progma platform administrators;
  • audit logging of sensitive actions for accountability, with out-of-band notice to the account holder when a security-relevant change is made to their account;
  • constrained, resource-limited code execution via a third-party execution backend; and
  • operational logging and monitoring.

No system is perfectly secure, and security is a shared responsibility. Institutions and users should protect their credentials and follow good security hygiene.

Reporting a vulnerability

If you believe you have found a security vulnerability, please report it to us privately so we can investigate and remediate it before details are made public.

  • Email: security@progma.app
  • What to include: a clear description, the steps to reproduce, the potential impact, and any relevant proof-of-concept. Please avoid including unnecessary personal data.

Responsible-disclosure guidelines

When researching, please:

  • act in good faith and avoid privacy violations, data destruction, or service disruption;
  • only interact with accounts you own or have explicit permission to test;
  • not access, modify, or exfiltrate data that does not belong to you;
  • not run denial-of-service attacks, spam, or social-engineering against staff or users; and
  • give us a reasonable opportunity to remediate before any public disclosure.

Safe harbor

We support responsible security research and want you to feel comfortable reporting to us. If you make a good-faith effort to comply with the responsible-disclosure guidelines above during your research, we will consider that research to be authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue promptly. If a third party brings legal action against you for research you conducted in accordance with these guidelines, we will make it known that your actions were authorized.

This safe harbor applies only to legal claims under our control, and does not bind independent third parties. If your research affects a third-party service or infrastructure (for example, our hosting or execution providers), that safe harbor does not extend to them, and you remain responsible for complying with their terms. If you are unsure whether a specific action is authorized, contact us at security@progma.app before proceeding.

Our response

We aim to acknowledge valid reports, keep you reasonably informed of remediation progress, and credit reporters where appropriate and desired. We do not operate a bug-bounty program and do not offer monetary rewards for vulnerability reports.

Contact

Security reports: security@progma.app. General questions: support@progma.app.