Security
ProCirrus operates a secure, highly available private-cloud platform designed for professional firms with business-critical, security-sensitive, and regulated workloads. Our security program follows a defense-in-depth model that combines physical security, resilient infrastructure, identity and access controls, network segmentation, endpoint and application protection, centralized monitoring, encryption, vulnerability management, data protection, and independently audited compliance controls.
Security at Every Layer
Security is built throughout the ProCirrus environment rather than concentrated at a single perimeter. Multiple physical, technical, administrative, and operational controls work together so that if one control is bypassed or fails, additional controls remain available to restrict, detect, contain, or recover from an event.
This layered architecture includes perimeter and internal network controls, zero-trust segmentation, endpoint detection and response, application control, multifactor authentication, least-privilege access, centralized security monitoring, encrypted communications, encryption at rest, vulnerability management, patch management, secure backups, and continuous infrastructure monitoring.
U.S.-Based, Resilient Infrastructure
Client systems and data are maintained within ProCirrus-managed environments in the United States, with geographically redundant U.S. data centers providing resilience against facility, infrastructure, network, and regional disruptions.
Our data centers incorporate multiple layers of physical and environmental protection, including 24x7 onsite security, controlled and monitored access, biometric authentication, video surveillance, secured perimeter controls, redundant utility and UPS power, backup generators, redundant cooling systems, diverse network connectivity, fire protection, and independently audited facility controls.
Within the data centers, ProCirrus uses clustered compute, enterprise storage, redundant switching, multiple network paths, and workload segmentation to reduce dependence on individual physical components and support continued operation during hardware failure or planned maintenance.
Zero-Trust Network and Access Security
ProCirrus applies least-privilege principles to both users and systems. Access is centrally managed, administrative privileges are restricted, and multifactor authentication is required for client users and ProCirrus administrative personnel where supported.
Inside the data center, zero-trust microsegmentation and distributed security controls restrict communications between workloads to approved systems, applications, ports, and services. This limits unnecessary server-to-server communication and helps contain lateral movement if a system or credential is compromised.
Endpoint, Application, and Threat Protection
ProCirrus combines advanced endpoint detection and response with application allowlisting and application-level restrictions. These controls are designed to identify malicious behavior while also preventing unauthorized applications, scripts, installers, and executable code from running in the first place.
Email, network, endpoint, identity, and application security are managed as parts of a coordinated security environment rather than as independent products.
Continuous Security Monitoring
Security events from across the environment are centrally collected, analyzed, correlated, and monitored. ProCirrus uses centralized security monitoring to identify suspicious activity, generate alerts, support investigations, evaluate security configurations, and provide historical event visibility.
Infrastructure health, capacity, backups, replication, network availability, system configurations, and security services are also continuously monitored, with alerts routed to the appropriate technical teams for investigation and response.
Vulnerability and Patch Management
Security requires continuous maintenance. ProCirrus performs recurring vulnerability assessments and maintains formal patch-management processes for supported operating systems, applications, infrastructure components, security platforms, and network systems.
Identified vulnerabilities are evaluated based on factors such as severity, exploitability, exposure, potential business impact, available remediation, and compensating controls. Priority is given to conditions presenting the greatest risk to client systems and data.
Encryption and Data Protection
Client data stored within the ProCirrus environment is protected with AES-256 encryption at rest, while external communications use modern encrypted transport protocols and strong industry-standard cryptography.
ProCirrus also maintains a layered data-protection strategy with frequent production recovery snapshots, robust daily, weekly, and longer-term backup retention, encrypted replication, and geographically redundant U.S. data centers. Backup and recovery strategies can be tailored when firms have specific business-continuity, retention, or regulatory requirements.
Independent Audits and Compliance
ProCirrus undergoes annual independent SOC 1 and SOC 2 Type II examinations covering applicable controls within the ProCirrus operating environment. These examinations evaluate both the design and operating effectiveness of controls over an extended review period.
ProCirrus also maintains an audited HIPAA compliance program incorporating administrative and technical safeguards, security policies and procedures, workforce security training, access controls, security-event monitoring, and risk-management activities. Personnel with applicable responsibilities receive HIPAA security and privacy training annually.
Additional audit and compliance information is available to clients and qualified organizations upon request.
Security Starts with People
Technology controls are only one part of an effective security program. ProCirrus support and operational personnel are U.S.-based, undergo background screening, and are subject to confidentiality obligations that specifically acknowledge responsibilities under the Economic Espionage Act.
Personnel with relevant responsibilities also receive annual HIPAA security and privacy training, helping ensure that the people operating and supporting the environment understand both the technical and procedural responsibilities associated with sensitive client information.
An Integrated Security Environment
ProCirrus does not rely on any single technology or control to protect client systems and data. Security is integrated across the infrastructure, network, identity, endpoint, application, monitoring, backup, personnel, and compliance layers. The objective is straightforward: prevent what can be prevented, restrict what should not be permitted, detect abnormal activity quickly, contain potential threats, and maintain the ability to recover when necessary.
Questions regarding ProCirrus security or requests for additional security and compliance documentation may be directed to: info@procirrus.com.