Security Policy
At PR VENTURES LTD, security is fundamental to everything we do. This Security Policy outlines our commitment to protecting your data and the measures we implement to ensure the security of our services.
1. Our Security Commitment
We are committed to maintaining the highest standards of security to protect your data and ensure the integrity of our services. Our security program is designed to:
- Protect the confidentiality, integrity, and availability of customer data
- Prevent unauthorized access to our systems and networks
- Detect and respond to security incidents promptly
- Continuously improve our security posture
- Comply with applicable laws, regulations, and industry standards
2. Data Protection
Encryption
- Data in Transit: All data transmitted between your devices and our servers is encrypted using TLS 1.2 or higher.
- Data at Rest: Customer data stored in our systems is encrypted using AES-256 encryption.
- Key Management: Encryption keys are managed using industry-standard practices and are rotated regularly.
Access Control
- Role-based access control (RBAC) limits access to data based on job function
- Multi-factor authentication (MFA) required for all system access
- Regular access reviews and prompt deprovisioning of access when no longer needed
- Privileged access management for administrative functions
3. Infrastructure Security
Network Security
- Firewalls and intrusion detection/prevention systems
- Network segmentation to isolate critical systems
- DDoS protection and mitigation
- Regular vulnerability scanning and penetration testing
Physical Security
- Data centers with 24/7 security personnel and surveillance
- Biometric access controls and visitor management
- Environmental controls (fire suppression, climate control, power redundancy)
- SOC 2 Type II certified data center facilities
4. Application Security
- Secure software development lifecycle (SDLC) practices
- Regular code reviews and security testing
- Static and dynamic application security testing (SAST/DAST)
- Third-party security audits and penetration testing
- Prompt patching of security vulnerabilities
5. Compliance and Certifications
We maintain compliance with industry standards and regulations, including:
- SOC 2 Type II: Annual audits verify our security controls
- ISO 27001: Information security management system certification
- GDPR: Compliance with European data protection requirements
- CCPA: Compliance with California consumer privacy requirements
- HIPAA: Available for healthcare customers (with BAA)
6. Incident Response
We maintain a comprehensive incident response program that includes:
- 24/7 security monitoring and alerting
- Defined incident response procedures and escalation paths
- Regular incident response drills and tabletop exercises
- Post-incident reviews and lessons learned
- Customer notification procedures in accordance with applicable laws
7. Business Continuity
- Geographic redundancy across multiple data centers
- Regular data backups with tested recovery procedures
- Defined recovery time objectives (RTO) and recovery point objectives (RPO)
- Annual business continuity and disaster recovery testing
8. Employee Security
- Background checks for all employees
- Security awareness training upon hire and annually
- Confidentiality agreements and acceptable use policies
- Clear desk and clear screen policies
9. Vendor Security
We carefully evaluate and monitor our third-party vendors to ensure they meet our security standards:
- Security assessments prior to vendor engagement
- Contractual security requirements and data protection agreements
- Ongoing monitoring of vendor security posture
- Regular review of vendor access and permissions
10. Responsible Disclosure
We value the security research community and encourage responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:
Email: security@theprventures.com
We commit to:
- Acknowledging receipt of your report within 48 hours
- Providing regular updates on our investigation
- Not pursuing legal action against researchers acting in good faith
- Working with you to understand and resolve the issue
11. Contact Us
For security-related inquiries, please contact us at:
PR VENTURES LTD
Security Team
Email: security@theprventures.com
PR VENTURES LTD
London, United Kingdom · Last updated June 1, 2026