Security you can build an agency on
Every account, connector, and client record is protected the same way, no matter your plan.
Architecture
ProPilotX runs on a multi-tenant architecture with strict workspace-level data isolation. Every query is scoped to the authenticated agency's workspace, and cross-tenant data access is prevented at the application layer, not just by convention.
Encryption
Data is encrypted at rest using AES-256 and in transit using TLS 1.3. Vault secrets receive an additional layer of application-level encryption, so credentials are never stored or transmitted in plain text.
Audit Logs
Every meaningful action in ProPilotX — logins, vault access, connector changes, permission updates — is recorded with actor, timestamp, and context, giving your agency a full accountability trail.
Role-Based Access Control
Access is governed by granular, role-based permissions across clients, teams, and connectors. Agencies can scope what designers, developers, and account managers can see and do, per client if needed.
Connector Security
Connector credentials (like WordPress application passwords or API keys) are stored in the encrypted vault and scoped per connection. Credentials can be rotated or revoked instantly without affecting other connections.
Privacy
We collect only the data required to operate the platform and never sell customer data. See our Privacy Policy for full details on what we collect, why, and how you can request deletion.
Have a security question?
Our team is happy to walk through our security practices in detail.