Commitments
Organize and publish clear security and privacy commitments on your Compliance Portal, with practical guidance for writing accurate public claims.
Commitments explain your security and privacy practices in concise, visitor-friendly language. They appear publicly on the Compliance Portal and help customers understand your approach before they review detailed policies or reports.
Commitments are public claims, not evidence of implementation. Use documents and audit reports when visitors need supporting material.
How commitments are organized
Section titled “How commitments are organized”A commitment belongs to a commitment group. Groups create the sections visitors see on the portal.
For example, a Data protection group could contain commitments about encryption, data retention, and backups. Other useful group themes include:
- Infrastructure security
- Identity and access management
- Incident response
- Privacy and data handling
- Business continuity
- Responsible disclosure
Each group requires a title and description. Each commitment contains:
- Icon — a visual cue that supports the subject.
- Eyebrow — an optional short label displayed above the title.
- Title — the main claim visitors scan.
- Description — the context needed to understand the claim.
Create a commitment group
Section titled “Create a commitment group”- Open the portal’s Commitments tab.
- Select Add group.
- Enter a specific title that describes the shared theme.
- Explain in the description what the group covers.
- Save the group.
Keep groups distinct. A small number of well-defined sections is easier to scan than many overlapping sections.
Add a commitment
Section titled “Add a commitment”- Find the group where the commitment belongs.
- Select Add commitment.
- Choose an icon.
- Optionally enter an eyebrow as a short category or qualifier.
- Enter the title and description.
- Save the commitment.
- Open the public portal and review the result in context.
The title should communicate the practice without depending on the description. Use the description to add meaningful scope, ownership, or limitations.
For example:
- Eyebrow: Encryption
- Title: Customer data is encrypted in transit
- Description: Connections to Probo services use modern TLS configurations to protect customer data while it moves across networks.
Only use an example like this when it accurately reflects your implemented controls.
Write defensible commitments
Section titled “Write defensible commitments”Prefer language that is specific enough to be useful and narrow enough to remain true.
Be factual. Describe an implemented practice, not an aspiration. Replace “We are committed to industry-leading security” with the control or process you actually operate.
Define the scope. Avoid broad claims such as “All data is always encrypted” unless every system, environment, and data flow satisfies the statement.
Avoid guarantees. Terms such as “never,” “completely secure,” and “zero risk” create claims that security controls cannot support.
Keep evidence separate. A commitment can summarize a practice, while a restricted policy or audit report provides substantiation.
Write for customers. Expand uncommon acronyms and avoid internal system names, implementation notes, and control identifiers unless they help visitors.
Arrange the public layout
Section titled “Arrange the public layout”Drag commitment groups into the order in which visitors should read them. Within each group, reorder commitments so the most important or frequently requested information appears first.
A useful default order is:
- Data protection and privacy
- Access and infrastructure security
- Monitoring and incident response
- Resilience and business continuity
The right order depends on your product, risk profile, and customer due-diligence questions.
Update or remove commitments
Section titled “Update or remove commitments”Edit a group when its theme or introduction changes. Edit an individual commitment when the underlying practice, scope, or wording changes.
Because commitments are public, changes are visible to portal visitors. Review the public page after editing, reordering, or removing content to confirm that the remaining claims still read coherently.
Establish a review process
Section titled “Establish a review process”Assign an owner to each commitment or group and review the content:
- When a related control, system, vendor, or policy changes
- After an incident reveals that a statement is incomplete or inaccurate
- Before a major customer or regulatory review
- On a recurring schedule appropriate to your compliance program
During review, confirm that each statement is current, supported by evidence, approved for public disclosure, and consistent with published policies and reports.