Security Overview
Updated September 11, 2026.
- Encryption — TLS for every connection. Network access tokens, provider app secrets and payment-related keys are encrypted at rest with a key held outside the database.
- Access — role-based permissions inside each workspace; workspaces are isolated at the data layer. ITPS staff access to customer workspaces is logged in the workspace's audit trail and visible to you.
- Authentication — password hashing with a modern algorithm, rate-limited sign-in, email verification, single-use reset links, optional TOTP two-factor with recovery codes.
- Payments — handled by Stripe; card numbers never reach our servers.
- Networks — we hold only the permissions needed to publish and read comments/analytics on your behalf and honour revocations and deletion requests from the networks automatically.
- Retention — API diagnostic logs 30 days, sign-in records 90 days; posts, media and analytics for the life of the workspace and 30 days after deletion.
- Backups — daily database backups by the hosting provider, retained 30 days.
- Reporting — found a vulnerability? Email security@it-ps.net. We acknowledge within two business days.
© 2026 IT PRO SERVICES LLC · Questions: legal@it-ps.net