Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Probo Cloud Infrastructure Security

High-level security, encryption, tenant isolation, and resilience controls for Probo Cloud

View as Markdown

This page provides a high-level overview of security controls for Probo Cloud. Detailed architecture, operational procedures, and audit evidence are shared through the Compliance Portal or during a security review.

Probo Cloud is available in separate EU and US regions. Your organization’s data is stored in the region selected during onboarding.

Customer organizations are logically isolated through tenant-scoped authorization and data access controls. Regional infrastructure is shared across Cloud customers and is not dedicated hardware for each organization.

  • Network boundaries restrict direct access to application workloads and data services.
  • Encryption protects data in transit and at rest. Sensitive application fields receive additional application-level encryption.
  • Secret management keeps service credentials separate from application data and limits access according to operational roles.
  • Access control applies least-privilege permissions to infrastructure and production operations.
  • Monitoring supports detection and response for service and infrastructure events.

Probo Cloud uses encrypted daily backups and point-in-time recovery (PITR) with a five-minute recovery point objective. Backup retention, restoration procedures, and availability commitments are defined in applicable agreements and security documentation.

  • Organization owners and administrators control membership, roles, and integrations.
  • Stored integration credentials are not displayed back to users.
  • Security concerns can be reported to security@probo.com.

These controls apply to Probo Cloud. In a self-hosted deployment, your organization is responsible for infrastructure security, encryption, secrets, backups, monitoring, and production access.

For subprocessors, certifications, control details, and audit artifacts, see the Compliance Portal. The Privacy Policy describes data processing and retention.