Security & Compliance
Compliance & Standards
Not all of these are the same kind of claim, so each one says what it is. The SOC 2 Type II report is the independent audit; the rest are a statute we satisfy, a readiness posture with a BAA available on request, and an encryption standard we implement. Read the SOC 2 announcement.
Security Features
Encryption at Rest
All data is encrypted at rest using AES-256.
Encryption in Transit
All data transmitted between your systems and Propper is protected with TLS 1.2 or higher.
Access Controls
Role-based access control (RBAC) ensures users only access what they need. SSO integration with major providers.
Audit Logging
Comprehensive audit trails track every action taken on documents for compliance and forensics.
US Hosting
Your data is stored in the United States, with multi-zone redundancy.
RBAC DB Controls
Role-based database access controls ensure data isolation and least-privilege access at the database level.
Data Handling Practices
We believe in transparency about how your data is handled. Here are our commitments to you:
- Data is never sold or shared with third parties
- Customer data is logically separated in multi-tenant architecture
- Automatic data backup with point-in-time recovery
- Configurable retention policies and data deletion
- Right to erasure supported
- Data portability with standard export formats
Frequently Asked Questions

Ready to Transform Your Document Workflow?
See where your document process is creating unnecessary cost and how Propper helps eliminate it.
