Protée OS (pro-tay)
Trust & Security

Security & Trust

Enterprise-grade infrastructure. Built for the events industry.

Protée OS runs on cloud infrastructure of the same class that powers global fintech, healthcare and e-commerce platforms. Your event data, your clients' details and your agency's operations sit on a foundation designed for security, uptime and scale from day one.

Compliance you can point to

We don't ask agencies to take our word for it. Our infrastructure providers maintain independently audited compliance programs — third-party attestations on an ongoing audit cycle, not self-declared badges.

To be straight about what that covers: these certifications are held by our infrastructure providers. Protée OS hasn't completed its own audit yet. We'd rather say that plainly than let a logo imply otherwise. We're happy to name our providers and share their current attestations with your IT or procurement team on request.

SOC 2 Type II

Held by our infrastructure providers. Independently audited controls for security, availability and confidentiality.

ISO 27001

Held by our infrastructure providers. The international standard for information security management.

Australian Privacy Principles

Personal data — guests, crew and client contacts — is handled in line with Australia’s Privacy Act, including the mandatory Notifiable Data Breaches scheme. GDPR obligations apply where an event involves EU residents.

How your data is protected

Protection at every layer — how data moves, how it rests, who can reach it, and how the platform defends itself.

Encryption everywhere

Data is encrypted in transit (TLS on every connection) and at rest, so information is protected whether it’s moving between systems or sitting in storage.

Role-based access

Every user — agency owner, crew member, vendor, guest — sees only what their role permits. Within an event, only the owner can edit. That’s a data-integrity decision as much as a security one: one editor is what keeps it that way.

Scoped by account

Your agency’s events, contacts and documents are scoped to your account. A vendor sees their brief and their zone. They don’t see your budget, your client, or your other vendors.

Network protection

Every request passes through automatic DDoS mitigation and a platform-wide firewall, with SSL certificates generated and rotated automatically — no manual configuration, no gaps.

Secure authentication

App access uses magic-link sign-in — no password to guess, reuse, or leak, and every link is single-use and time-limited. Where passwords are stored, they’re hashed and salted using industry-standard cryptography. Administrative access to our infrastructure is protected by two-factor authentication, restricted to named administrators, with no third-party logins.

Continuous monitoring

Vulnerability scanning and patch management run continuously against emerging threats.

Built for uptime

The platform runs on globally distributed edge infrastructure with automatic failover. It stays fast and available whether you're running one event or a hundred, from Sydney to Auckland to Melbourne.

Where your data lives

Event records, documents and contacts are stored in Sydney. The platform is delivered through a global edge network and some transactional services route internationally, so cached assets and notifications may pass through servers outside Australia — your event records don't.

Your data, your control

  • Automated backups run daily and are retained on a rolling three-day cycle, stored in the same region as your primary data.
  • Detailed activity and access logging for accountability.
  • Your data is yours. When you ask us to delete it, it’s removed from the live system immediately and clears from backups within three days.
  • Export what you’ve built at any time.

What we don't do

We don’t process payments.

There is no payment gateway in Protée OS. No card numbers, no funds held. Where vendors provide payment details, those are stored encrypted and never displayed in full. Treasury tracks what you’ve committed and what’s outstanding — the money itself never moves through us.

We don’t sell or share your data.

Your events, your client list and your vendor relationships are yours. They aren’t packaged into a dataset and they aren’t visible to other accounts.

We don’t train models on your event data.

AI is used for a few specific jobs: extracting a palette and elements from an image you upload, parsing documents, comparing a returned quote against the brief you sent, and finding publicly available contact details. It runs on the item in front of you. We may use anonymised, aggregated data to improve the platform, as set out in our terms.

A small access surface

Protée OS is built and maintained by full-time staff. No contractors, outsourced support team, no third parties with a login.

Why this matters for your agency

Event agencies handle sensitive information every day — client contracts, guest lists with dietary and accessibility details, crew licences, supplier documents, budgets. Some of it belongs to your clients, and some of it belongs to their guests.

Protée OS was built on infrastructure that meets the same bar banks and healthcare providers rely on, so you can run your business without worrying about the plumbing underneath it.

Reporting a security issue

If you find a vulnerability, tell us and we'll act on it. Email support@proteeos.com and you'll get an acknowledgement within one business day.

No legal action will be taken against anyone reporting a genuine issue in good faith.

Have a specific security or compliance question?

If your IT or procurement team needs more detail, we'll walk them through the architecture. You'll get a direct answer from the people who built the system, not a form.