Last Updated: March 18, 2026
This page describes the security practices PR Bot implements to protect your data. It is provided for informational purposes and does not form part of any agreement between you and StartupBros LLC d/b/a PR Bot. Contractual security obligations, where applicable, are governed by our Data Processing Addendum.
PR Bot is operated by StartupBros LLC ("we," "us," "our"). Security is foundational to how we build and operate our platform. We implement commercially reasonable administrative, technical, and physical safeguards designed to protect your data against unauthorized access, destruction, loss, alteration, or misuse. These measures are proportionate to the nature and sensitivity of the data we process and the risks presented by our processing activities.
Our security practices are informed by the CIS Critical Security Controls v8, the NIST Cybersecurity Framework, and SOC 2 Trust Services Criteria. We continuously evaluate and refine our controls as threats evolve and our platform grows.
PR Bot runs on infrastructure provided by industry-leading cloud platforms. Physical security for all data centers is inherited from our infrastructure providers:
| Provider | Role | Certifications |
|---|---|---|
| Supabase (AWS) | Database, authentication, file storage | SOC 2 Type II, HIPAA |
| Vercel | Application hosting, global CDN | SOC 2 Type II, ISO 27001 |
| Stripe | Payment processing, subscriptions | PCI DSS Level 1, SOC 2 Type II |
These providers maintain enterprise-grade data center security including biometric access controls, 24/7 monitoring, environmental controls, and multi-zone redundancy. We do not operate our own data centers.
All data transmitted between your browser and our servers, between our services, and between our servers and third-party providers is encrypted using TLS 1.2 or higher (TLS 1.3 where supported). We enforce HTTPS on all connections and apply HTTP Strict Transport Security (HSTS) headers to prevent downgrade attacks.
All customer data stored in our database is encrypted at rest using AES-256 encryption, provided by our database infrastructure (Supabase / AWS). This includes:
Sensitive values such as access tokens and API keys are additionally encrypted at the application level before storage.
PR Bot operates a multi-tenant architecture with strict logical separation between customer accounts:
Because PR Bot uses third-party AI models to generate media outreach content, enterprise customers need to understand exactly how their data moves through these systems. Here is how it works:
We use commercial API agreements with our AI providers that contractually prohibit the use of your data for model training or improvement:
| AI Provider | API Tier | Training Opt-Out | DPA in Place |
|---|---|---|---|
| OpenAI | Business / Enterprise API | Confirmed — API data not used for training | ✓ Active |
| Anthropic | Commercial API | Confirmed — API inputs/outputs excluded from training | ✓ Active |
| Google AI | Gemini API (paid tier) | Confirmed — Paid API data excluded from training | ✓ Active |
We implement controls designed to protect against adversarial inputs to our AI processing pipeline:
Each customer's AI processing requests are independent and isolated. We do not batch data across customer accounts, and one customer's profile information is never included in another customer's AI context window. For more information about how we use AI, see our AI Transparency & Policy.
We maintain a documented incident response plan that is reviewed and updated periodically. In the event of a security incident affecting customer data:
All breach notifications will describe the nature of the breach, the data categories affected, the likely consequences, and the measures taken to address it. For complete details, see Data Processing Information.
| Framework | Status | Details |
|---|---|---|
| GDPR | Compliant | Data Processing Addendum available; Standard Contractual Clauses implemented for international transfers; lawful bases documented in our Privacy Policy |
| CCPA / CPRA | Compliant | California privacy rights honored; no sale of personal information; service provider obligations fulfilled |
| SOC 2 Type II | Infrastructure Providers Certified | Supabase, Vercel, and Stripe each maintain independently audited SOC 2 Type II reports. Our internal security practices are aligned with SOC 2 Trust Services Criteria. |
| PCI DSS | Delegated to Stripe | All payment processing is handled by Stripe (PCI DSS Level 1 Service Provider). We never store, process, or transmit cardholder data on our own servers. |
| EU AI Act | Compliant | AI-generated content disclosures per Article 50; AI transparency policy published; provider-level obligations monitored. See our AI Transparency & Policy |
| CIS Controls v8 | Aligned | Security practices aligned with Implementation Group 1 controls, recognized as the reasonable security baseline by the California Attorney General |
We understand the importance of security diligence in enterprise procurement. We can provide:
Contact security@prbot.ai to initiate a security review.
We retain customer data only as long as necessary to provide our services and comply with legal obligations. Key retention periods:
You may delete your data at any time through your account settings or by contacting privacy@prbot.ai. For complete data retention details, see our Privacy Policy and Data Processing Information.
We value the security research community and welcome responsible reports of potential security vulnerabilities in our services.
If you believe you have discovered a security vulnerability, please report it to security@prbot.ai. Include:
We will not pursue legal action against security researchers who:
This safe harbor is consistent with the U.S. Department of Justice's policy on charging violations of the Computer Fraud and Abuse Act (CFAA) with respect to good-faith security research.
In scope: prbot.ai and its subdomains; PR Bot application functionality.
Out of scope: Social engineering attacks against our employees; denial-of-service attacks; physical security testing; third-party services and applications (report these to the respective provider).
For security-related inquiries:
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher with HSTS headers enforced. All customer data stored in our database is encrypted at rest using AES-256 encryption provided by Supabase on AWS. Sensitive values such as access tokens and API keys receive additional application-level encryption before storage.
Yes. PR Bot enforces strict logical separation between customer accounts using row-level security (RLS) policies at the database level. Each customer’s AI processing requests are independent and isolated — one customer’s data is never included in another customer’s AI context window. API authorization checks verify account membership on every request.
We maintain a documented incident response plan. In the event of a breach, we detect and contain the incident, assess impact, notify affected customers and regulatory authorities within required timelines (72 hours for GDPR, 30 days for Florida FIPA), remediate the root cause, and conduct a post-incident review. All notifications describe the breach nature, data affected, and measures taken.
Email security@prbot.ai with a description of the vulnerability, steps to reproduce, and any proof-of-concept. We acknowledge receipt within 3 business days, provide an initial assessment within 10 business days, and offer safe harbor for good-faith security researchers consistent with the U.S. Department of Justice’s CFAA policy.
Our infrastructure providers (Supabase, Vercel, Stripe) maintain independently audited SOC 2 Type II reports. We are GDPR and CCPA/CPRA compliant, PCI DSS compliant via Stripe, and EU AI Act compliant. Our internal practices align with CIS Critical Security Controls v8 Implementation Group 1 and the NIST Cybersecurity Framework.
Account and profile data is retained while your account is active and deleted within 30 days of account deletion. AI-generated content follows the same schedule. Payment records are retained for 7 years as required by tax law. Server logs are retained for up to 90 days. Backup copies are deleted within 90 days of primary data deletion.
| Date | Summary of Changes |
|---|---|
| March 18, 2026 | Initial publication |
This Security Policy complements our broader legal documentation. For binding security commitments, please refer to our Data Processing Addendum.
Related Documents:
Questions about this document? Contact us at security@prbot.ai
Ready to build your media presence?
Most customers get their first backlink within 7 days. 30-day money-back guarantee on every plan.
See Plans