What PROSENTRIQ actually does with your data, what it can prove to an auditor, and how to reach us if something's wrong.
The same evidence report a running deployment can generate today — JSON, Markdown, or a signed-checksum PDF — maps directly to these controls.
| Framework | Control | What PROSENTRIQ provides as evidence |
|---|---|---|
| SOC 2 | CC7.2 | Continuous monitoring for anomalies indicative of malicious activity, with a timestamped event log and automated-response record. |
| PCI DSS v4.0 | Req. 10.2.1 / 11.5 | Audit logging on all monitored components, plus active intrusion-detection with documented, current rule updates. |
| HIPAA Security Rule | 45 CFR 164.312(b) | Audit controls that record and examine activity on systems handling electronic protected health information. |
Reports include a SHA-256 checksum sidecar so an auditor can verify a copy hasn't been altered after generation. See compliance/reports/generate_report.py for the exact query logic behind every figure in a report.
Found a security issue in PROSENTRIQ itself — the agent, the Detection API, or this site? We want to know before anyone else does.
Email [email protected] with as much detail as you can. We ask that you:
We aim to acknowledge reports within 2 business days.
Detailed in the architecture documentation, summarized here because it's a security property, not a feature:
/var/log/prosentriq/enforcement_audit.log, separate from the Detection API's own records.