Last updated: January 2025
All data transmitted through the ProcureX platform is encrypted in transit using TLS 1.3 and at rest using AES-256. We do not store sensitive credentials — passwords are hashed using bcrypt with a minimum work factor of 12.
Access to the platform requires authenticated sessions issued via signed JWT tokens with short-lived expiry. Session tokens are rotated on each login and invalidated on logout.
ProcureX infrastructure is hosted in certified EU data centres (ISO 27001). Access to production systems is restricted to authorised personnel via VPN with hardware-based MFA. All infrastructure changes are logged and audited.
We operate a responsible disclosure programme. If you discover a security vulnerability, please contact security@procurex.io. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.