Security
Built for banks, and honest about what is not built yet
Your awards programme is commercially sensitive. This page states plainly what protects it today, and what we have deliberately not built yet.
What protects your data today
Your organisation’s data is separated at the database, not in the interface
Every request for your data carries your identity, and the rule that restricts it to your organisation is applied when the data is fetched — not by hiding things on the screen. It applies the same way whether the request comes from the application, the API or a background job. One organisation seeing another’s data is the most serious failure this product could have, and it is the one thing we have never deferred.
We never see your card details
Payment is handled entirely by Stripe. Card details are entered on Stripe’s own pages and never reach our servers. Billing events we receive from Stripe are cryptographically verified before we act on them.
One sign-in system, with sessions handled properly
Authentication is handled by a single system for everyone, staff and subscribers alike — no second login provider to keep in step. Passwords are hashed, never stored. Sessions use HTTP-only cookies, so page scripts cannot read them, and every connection is served over HTTPS.
Your documents are not on a public link
Files you upload are stored privately and served only through a route that checks who is asking. There is no public bucket address that would work if someone found it. Uploads are limited by size and file type, and the file’s actual contents are checked rather than trusted from its name.
Permissions are enforced on the server
What role you hold, which organisation you belong to and what your subscription allows are all decided on the server, from your session. They are never taken from the browser, so they cannot be changed by editing a request.
Hosted in the UK and EU
The application runs on Vercel and the database and file storage are hosted by Supabase in the London region.
What we have not built yet
PRi Awards Manager is a young product, and we would rather tell you this than let you assume it.
Single sign-on and multi-factor authentication
Not yet available. Sign-in is by email and password. If SSO is a requirement for your institution, tell us — it is the most likely thing to be built next, and knowing who needs it decides when.
Detailed audit logging
We do not yet keep a per-user record of every action taken inside an account. Billing history is retained, and content changes are versioned.
Independent penetration testing
Not yet commissioned. It is planned before the platform is sold at scale.
Security questions are welcome
If your information security team needs detail beyond this page, ask. We would rather answer a hard question now than have you assume an answer.