Trust

Security, data handling & compliance posture

PromoPack is built for regulated workflows. We are transparent about what we do today and what we are building for enterprise procurement.

Data protection

  • Encryption in transit (HTTPS/TLS) for all application traffic.
  • Encryption at rest for stored data, consistent with our cloud provider defaults.
  • Access controls and authentication so only your account can reach your projects.

Audit logging

We maintain audit logging appropriate to operating the service. Product features such as claim history, document versions, and pack generation support your internal MLR and documentation processes—they supplement, not replace, your company's formal records and sign-off.

AI & human review

AI assists with extraction and linking suggestions. It can be wrong. Low-confidence links are flagged for review; your medical, legal, and regulatory teams remain accountable for final content. PromoPack does not guarantee regulatory compliance.

Roadmap: SOC 2 & enterprise readiness

We are actively working toward SOC 2 Type II and expanded enterprise certifications. Exact timelines depend on customer demand and program scope—contact us for the current roadmap, data processing terms, and security questionnaire.

Contact for security pack & DPA →

Enterprise capabilities

Advanced needs—SSO/SAML, custom retention, regional data residency, named SLAs, and formal sign-off roles—are available on Enterprise plans or via professional services. We will align contractual terms with your legal and procurement requirements.

View pricing & Enterprise →