Legal
Security
How the platform is secured, what we hold ourselves to, and how to report a vulnerability.
Last updated 1 August 2026
1. Where we are
Prinvia is an early-stage company running a pilot. We do not yet hold a SOC 2 report, and we will not claim one before we do. What we can describe today is the posture below, and we are happy to answer a security questionnaire in detail.
2. Encryption
- Data in transit is encrypted with TLS 1.2 or above; older versions are refused.
- Data at rest is encrypted with AES-256.
- Card data is tokenised and never stored on Prinvia terminals or in application databases.
3. Access control
Access to production follows least privilege and is reviewed quarterly. Elevated access is time-boxed and requires a stated reason, and every grant is written to the audit log. Multi-factor authentication is mandatory for all staff. SSO and SCIM are available to customers on Enterprise.
4. Audit logging
Every privileged action is written to an append-only log recording the actor, the device, the previous value, and a timestamp. Logs are retained for 12 months by default, configurable to 7 years, and are exportable in JSON or CSV at any time.
5. Data residency
Customer data is stored in US regions by default. EU residency is available on request and is set per organisation. Residency does not change without written instruction from the customer.
6. Resilience
Backups run continuously with point-in-time recovery for 35 days. Restore procedures are tested quarterly. Terminals operate offline through a network outage and reconcile automatically when connectivity returns.
7. Vulnerability disclosure
Report suspected vulnerabilities to hello@prinvia.com. We acknowledge within one business day and aim to provide a remediation timeline within five. We do not pursue legal action against researchers who act in good faith, avoid privacy violations, and give us reasonable time to fix an issue before disclosing it.
8. Incident response
Security incidents are triaged within one hour of detection. Affected customers are notified without undue delay and in any event within 72 hours of confirmation, with a written post-incident report to follow.
9. Subprocessors
A current list of subprocessors is maintained and provided to customers on request. We give 30 days notice before adding a subprocessor that processes customer data.
This is a demonstration website. The text below is placeholder copy written to show document structure and is not a legal agreement, not legal advice, and not binding on anyone.