Skip to content

Security

Built for banks, and honest about what is not built yet

Your awards programme is commercially sensitive. This page states plainly what protects it today, and what we have deliberately not built yet.

What protects your data today

Your organisation’s data is separated at the database, not in the interface

Every request for your data carries your identity, and the rule that restricts it to your organisation is applied when the data is fetched — not by hiding things on the screen. It applies the same way whether the request comes from the application, the API or a background job. One organisation seeing another’s data is the most serious failure this product could have, and it is the one thing we have never deferred.

We never see your card details

Payment is handled entirely by Stripe. Card details are entered on Stripe’s own pages and never reach our servers. Billing events we receive from Stripe are cryptographically verified before we act on them.

One sign-in system, with sessions handled properly

Authentication is handled by a single system for everyone, staff and subscribers alike — no second login provider to keep in step. Passwords are hashed, never stored. Sessions use HTTP-only cookies, so page scripts cannot read them, and every connection is served over HTTPS.

Your documents are not on a public link

Files you upload are stored privately and served only through a route that checks who is asking. There is no public bucket address that would work if someone found it. Uploads are limited by size and file type, and the file’s actual contents are checked rather than trusted from its name.

Permissions are enforced on the server

What role you hold, which organisation you belong to and what your subscription allows are all decided on the server, from your session. They are never taken from the browser, so they cannot be changed by editing a request.

Hosted in the UK and EU

The application runs on Vercel and the database and file storage are hosted by Supabase in the London region.

What we have not built yet

PRi Awards Manager is a young product, and we would rather tell you this than let you assume it.

Single sign-on and multi-factor authentication

Not yet available. Sign-in is by email and password. If SSO is a requirement for your institution, tell us — it is the most likely thing to be built next, and knowing who needs it decides when.

Detailed audit logging

We do not yet keep a per-user record of every action taken inside an account. Billing history is retained, and content changes are versioned.

Independent penetration testing

Not yet commissioned. It is planned before the platform is sold at scale.

Security questions are welcome

If your information security team needs detail beyond this page, ask. We would rather answer a hard question now than have you assume an answer.