Skip to content
Book a Demo

Security

Built for fiduciary environments where accuracy, security, and explainability are non-negotiable.

Voting decisions are examined by fund boards, clients, and regulators—often long after they were made. The controls behind them are designed to be examined too.

Governance

Proxify's Security and Privacy teams establish policies and controls, monitor compliance with those controls, and prove our security and compliance to third-party auditors.

  1. 01

    Access is granted only to individuals with a clear business justification, and permissions are scoped to the minimum required to perform their role.

  2. 02

    Security controls are designed as overlapping layers, so no single safeguard is relied on as the sole line of defense.

  3. 03

    Controls are enforced uniformly across the organization, rather than applied selectively or inconsistently.

  4. 04

    Controls are implemented with ongoing improvements that improve effectiveness and reduce operational friction over time.

Enterprise security
Endpoint protection
All corporate devices are provisioned with mobile device management and anti-malware tools.
  • Endpoint security is monitored continuously, 24/7/365.
  • MDM enforces secure configurations, including disk encryption, screen lock policies, and timely software updates.
Identity and access management
Proxify protects remote access to internal systems through AWS's VPN solution.
  • Malware-filtering DNS services safeguard employees and their devices during internet access.
Security training
Comprehensive security training is delivered to all employees at onboarding and annually thereafter.
  • All new hires complete a required live onboarding session covering core security principles.
  • All new engineers attend an additional mandatory session on secure coding practices.
  • The security team distributes regular threat briefings on updates requiring heightened awareness or action.
Secure remote access
Proxify relies on AWS for identity and access management and enforces phishing-resistant authentication methods, using Cognito wherever feasible.
  • Employee access to applications is role-based and automatically revoked upon termination.
  • Any additional access requires approval in accordance with each application's defined policies.
Data protection

Data privacy is a first-class priority—Proxify strives to be a trustworthy steward of all sensitive data.

Data at rest
All customer data repositories, including S3 buckets, are encrypted at rest.
  • Highly sensitive tables and collections additionally employ row-level encryption, encrypting data before it is written to the database.
  • Neither physical access nor database-level access alone is sufficient to view the most sensitive data.
Data in transit
TLS 1.2 or higher is enforced for all data transmitted across potentially untrusted networks.
  • HSTS provides additional protection for data in transit.
  • TLS certificates and server keys are managed by AWS and implemented through Application Load Balancers.
Secret management
Encryption keys are centrally managed using AWS Key Management Service.
  • Key material is protected within Hardware Security Modules—no individuals, including Amazon or Proxify personnel, can directly access the keys.
  • All encryption and decryption operations are performed through KMS APIs using keys secured in these modules.
Vulnerability scanning

Proxify requires vulnerability scanning at key stages of its Secure Development Lifecycle.

Network scanning
Periodic network vulnerability scanning.
Software supply chain
Dependency scanning to detect and block malicious packages from entering the software supply chain.
Application testing
Dynamic application security testing against running services.
Attack surface
Continuous external attack surface management to identify newly exposed external assets.
Vendor security

Proxify uses a risk-based approach to vendor security. Factors that influence the inherent risk rating of a vendor include:

Production environment integration
The extent to which the vendor integrates with Proxify's production environment.
Potential brand damage
The reputational impact of an incident involving the vendor.
Customer and corporate data access
The scope of customer and corporate data the vendor can access.

Responsible disclosure

Looking to report a security concern?

Report a concern

See how Proxify works across your portfolio.

Book a personalized demo with our team.