Security And Compliance
This policy summarizes the administrative, technical, and operational safeguards Prizm Services LLC uses to protect customer, invoice, payment, and bank-connection data.
Governance
Prizm Services assigns responsibility for information security to the Prizm Services Security Team. Security questions, privacy requests, and incident notices can be sent to info@prizmservices.com.
Access Control
Production systems use unique administrator accounts, role-based access, least-privilege permissions, and periodic access review. Access is removed when it is no longer required.
Technical Safeguards
- HTTPS/TLS is required for web and API traffic.
- Administrative sessions use HttpOnly cookies and security headers are applied by the Node server and Apache configuration.
- Bank account login is handled by Plaid Link. Prizm Services does not receive or store online banking passwords.
- Payment and invoice events are stored in audit logs for review.
- Sensitive secrets must be stored in Hostinger environment variables, not in public JavaScript or HTML files.
Monitoring And Vulnerability Management
Prizm Services reviews application logs and admin audit logs for invoice, order, payment, and bank-link activity. Production systems should be patched regularly, dependencies reviewed before deployment, and vulnerability scans scheduled for hosting assets and administrator workstations.
Incident Response
If a suspected security issue occurs, Prizm Services will investigate, contain access where needed, preserve relevant logs, notify affected parties when required by law, and document remediation steps.