Security
This page describes controls in the application and points to confirm for your environment. Hosting conditions and service commitments should be reviewed as part of your agreement.
Last updated · September 12, 2026
Application access
Authentication uses Supabase Auth. Server controls take account of the user, their role and their dealership scope. Administrative operations use separate server access.
SSO availability, password policies and MFA requirements depend on identity service configuration. Activation must be checked for the relevant deployment.
Email connections
Microsoft and Google OAuth tokens are encrypted at application level with AES-256-GCM before storage. A server environment variable supplies the encryption key. Connecting an external account requires provider configuration and the requested permissions.
Browser protection
Application configuration defines headers including Content-Security-Policy, X-Frame-Options, Referrer-Policy and Permissions-Policy. An HSTS header is configured for production.
The HTTPS certificate, the TLS protocols actually offered and any entry in the HSTS preload list depend on the domain and hosting; this page does not attest to them.
Hosting and backups
Processing regions, host-provided encryption, backup retention and recovery options depend on the configured services and plans. Review these settings with the Prosio team before agreeing on guarantees for your environment.
Operations and verification
Availability, monitoring, log retention and incident response commitments must be established in the applicable service documents. This page does not claim a Prosio certification, an annual external audit or a completed independent penetration test.
Questions and reports
For a security question or report, contact contact@prosio.be. Describe the useful context without including passwords, tokens or customers’ personal data.