PrecePrece
Security

Security and privacy

A practical overview of how Prece approaches security, privacy, and reliability.

Prece is built to support day-to-day operations with clear access boundaries, reliable audit trails, and sensible defaults. This page describes common safeguards we use and the controls we recommend customers enable as part of their rollout.

Access controls

  • Role-based access to keep each team member in the right workflow.
  • Principle of least privilege in UI and backend authorization checks.
  • Audit-friendly workflows where key actions are recorded and reviewable.

Authentication

  • Secure session handling with protected routes.
  • Account recovery flows designed to reduce takeover risk.

Data protection

  • Encryption in transit for web traffic.
  • Encryption at rest in our storage providers.
  • Scoped data access so users only see data they have permission to access.

Backups and recovery

We maintain automated daily backups with point-in-time recovery capability. Infrastructure is designed with redundancy and failover to minimize downtime risk. Recovery processes are tested regularly.

Logging and monitoring

We use application logs to help detect issues, investigate incidents, and improve reliability. Access to logs is restricted and operationally controlled.

Responsible use

Security is shared. Strong permissions, careful staff onboarding, and good password hygiene significantly reduce risk. If you have special requirements (SSO, retention policies, custom logging), we're happy to discuss them.

Compliance readiness

  • COPPA considerations built into how we handle children's data and parental consent.
  • State licensing requirements inform our compliance workflows and audit trail design.
  • SOC 2 readiness: we are actively working toward SOC 2 Type II certification.
  • Data residency: data is stored and processed in the United States.