One Unified Platform for spend management and proactive control

Expense Manager

AP Manager

Security & Controls

Last Updated: May 15, 2026

TL;DR:

ProSpend is hosted on AWS in Australia’s Sydney region, with encryption in transit and at rest, restricted network access, logical separation of customer data and least-privilege access controls. Internal access is managed through RBAC, MFA for privileged access, regular access reviews, and logged and monitored production access. ProSpend follows secure development, monitoring, incident response, vulnerability scanning, periodic third-party vendor reviews based on risk, and periodic independent security assessments. Customer data is used only to deliver the ProSpend service, and ProSpend does not store sensitive cardholder data.

Overview

ProSpend is designed with security and privacy at its core. We implement industry-standard controls across our platform to protect customer data, maintain system integrity, and support our customers’ governance and compliance requirements.

Security Framework

Our security program is aligned to recognised industry standards and best practices.

  • SOC 2 (aligned)
  • ISO/IEC 27001 principles
  • Australian Privacy Principles (APPs)

We continuously review and improve our controls to ensure they remain effective as our platform evolves.

Cloud Infrastructure

ProSpend is hosted on Amazon Web Services (AWS), leveraging its secure, globally distributed infrastructure.

  • Data is hosted in Australia (AWS Sydney region)
  • Network access is restricted using private networking and security controls
  • Infrastructure is configured according to industry best practices
  • Regular patching and updates are applied to underlying systems

Data Protection & Privacy

We apply strict controls to protect customer data throughout its lifecycle:

  • Encryption in transit using TLS 1.2+
  • Encryption at rest using industry-standard encryption
  • Logical separation of customer data between tenants
  • Access to sensitive data is restricted based on least privilege principles

Customer data is only used for the purpose of delivering the ProSpend service.

Payments & Financial Data Handling

ProSpend facilitates payments through trusted third-party providers, including Wise.

  • Virtual cards are issued and managed by these providers
  • ProSpend does not store sensitive cardholder data
  • Payment processing and card data handling occur within the provider’s secure environment

This approach reduces ProSpend’s exposure to sensitive financial data while leveraging the security controls of established payment providers.

Access Control

Access to systems and data is tightly controlled:

  • Role-Based Access Control (RBAC) across internal systems
  • Multi-Factor Authentication (MFA) enforced for privileged access
  • Access is granted on a least-privilege basis
  • Regular access reviews are conducted

All access to production systems is logged and monitored.

Application Security

We follow secure development practices throughout the software lifecycle:

  • Code changes undergo peer review before deployment
  • Dependencies are monitored for known vulnerabilities
  • Environments are separated across development, staging, and production
  • Security considerations are incorporated into design and implementation

Monitoring & Incident Response

We maintain continuous monitoring and defined response processes:

  • Centralised logging of system and application activity
  • Monitoring and alerting for anomalous behaviour
  • Documented incident response procedures
  • Timely investigation and remediation of security events

Third-Party Management

We carefully manage third-party providers that support our platform:

  • Providers are selected based on their security posture
  • Access to data is limited and controlled
  • Vendors are reviewed periodically based on risk

Assurance & Testing

We regularly assess and improve our security posture:

  • Ongoing vulnerability scanning
  • Periodic independent security assessments
  • Continuous improvement of controls and processes

Security Contact

For security-related enquiries or to report vulnerabilities:

Email: secops@prospend.com

 Frequently asked questions 

How does ProSpend protect customer data?

We use a layered approach to security across infrastructure, application controls, access management and operational processes. That includes secure cloud hosting, network controls, monitoring, encryption, restricted administrative access and a documented response process for incidents.

 

Prospend data is stored exclusively within the AWS Sydney Region (ap-southeast-2). To ensure maximum reliability, your information is redundantly spread across multiple physically distinct data centers within Sydney. This architecture for storage is designed for 99.999999999% durability.

Where is customer data hosted?

 ProSpend's platform infrastructure is cloud hosted on Amazon Web Services (AWS). If any clients need more detail on hosting location, architecture or data flow, our team can provide a high-level overview during the security review process. 

Is data encrypted?

 Yes. Data is protected in transit using modern transport encryption, and data at rest is encrypted within our managed environment and backups.Backups of the database are encrypted on rest and have a 35 day retention period. 

How does ProSpend help reduce fraud and unauthorised activity?

 ProSpend combines platform controls with operational safeguards. Depending on the module, this includes configurable approval workflows, approval limits, supplier verification controls, duplicate detection, bank-detail checking, exception routing and audit trails. These controls are designed to reduce the risk of unauthorised or incorrectly approved spend. 

What access controls do you use?

 We apply least-privilege principles so team members only receive the access required for their role. Access to sensitive internal systems is restricted and protected using identity controls such as single sign-on, multi-factor authentication and network restrictions where appropriate. Administrative actions are limited to authorised personnel. 

How do you manage employee and third-party access?

 Security responsibilities form part of onboarding and ongoing staff awareness training. Third-party providers are engaged only where necessary to deliver the service, and access is controlled based on business need, contractual confidentiality obligations and the principle of minimum necessary access. 

Do you perform penetration testing or security reviews?

 Yes. ProSpend conducts periodic security testing, including penetration testing. Findings are assessed, prioritised and remediated through our internal processes. For qualified prospects, we can share a high-level summary of recent testing under appropriate confidentiality terms. 

What happens if there is a security incident?

 We maintain a documented incident response process with defined ownership, triage, internal escalation, communication and post-incident review steps. Our team monitors production systems and supports rapid investigation and remediation if an issue is detected. 

Do you have backup and recovery measures in place?

 Yes. We maintain encrypted backups and documented recovery procedures designed to support business continuity. Detailed recovery objectives and architecture specifics can be discussed as part of customer due diligence, where required. 

Are you ISO 27001 or SOC 2 certified?

ProSpend is not currently certified to ISO 27001 or SOC 2. We are continuing to mature our security program and working toward formal certification. In the meantime, we maintain practical security controls and operating disciplines to protect customer data and support customer due diligence. We will continue to provide updates on our security roadmap to prospects and customers.

Do you align with any recognised security frameworks?

 Our security practices are informed by established security and risk-management principles, and we maintain controls designed to support secure handling of customer information. Where relevant, we also use established compliance and cloud-security guidance to inform how our environment is operated and reviewed. 

How does ProSpend handle privacy and third-party service providers?

We handle personal information in line with our Privacy Policy and applicable privacy obligations. Where third-party service providers are used to help us deliver the service, we limit disclosures to what is necessary, select providers carefully and require appropriate confidentiality and security protections.



Where can I find your legal terms and privacy policy?

 You can review our Terms of Use and Privacy Policy on our website. Commercial terms, including liability and any negotiated protections, are governed by the relevant customer agreement and applicable terms. 

Can we request more detailed security information?

Yes. Customers with formal procurement, IT or risk review processes can request additional information from our technical teams. Depending on the stage of review, this may include a security overview, architecture summary, privacy and legal documents, and a high-level penetration test summary.



Does ProSpend support audit trails?

 Yes, ProSpend supports audit trails to track and log user activity within the system. This can be accessed by Admins. 

Does ProSpend support user roles?

 Yes, ProSpend supports user roles. These are fixed, system-defined roles rather than custom configurable roles. 

What password policies does ProSpend enforce?

 ProSpend enforces a minimum password length and prevents reuse of the same password. 

Is sensitive data encrypted at rest?

 Yes, sensitive data is indeed encrypted at rest, this includes and not limited to Oauth tokens, Passwords, account card codes. 

Need to complete a supplier security review?

Our team can provide additional due diligence materials for qualified prospects, including high-level security documentation and answers to common customer questionnaires.