Security and data handling
Supplier prices are commercially sensitive. This page describes how Proceny handles your files and data today — only what is built and tested, and what is not in place yet.
Updated 29 September 2026 · Proceny
Where your files are processed
- Files are read by Proceny's own code. They are not sent to AI services, and no AI provider is called. Scanned pages are read by OCR software that is part of Proceny, not by an outside service.
- The free price list comparison runs in your browser. Files you compare there are not uploaded.
- Private files and organisation data are reached only through the application, which checks your organisation membership on every request. The application is served over HTTPS only.
Your organisation's data stays separate
- Every record belongs to one organisation, and the database itself refuses links between records of different organisations.
- Every request is checked against your membership on the server. Requests for another organisation's files, imports, comparisons or exports are answered as if they did not exist; this is tested over HTTP with separate accounts.
- Roles: owner, admin and member. Templates, review thresholds, billing and invitations are for admins; only the owner changes roles or deletes the organisation.
Files you upload
- The file type is recognised from the content, not the file name. Files are limited to 50 MB and PDFs to 1,000 pages.
- Spreadsheet formulas are never calculated and macros never run; only the stored values are read. Encrypted workbooks and damaged PDFs are refused with a message.
- Each file is read in an isolated worker with time and memory limits, so a broken or hostile file is stopped instead of exhausting the server.
- Files are kept outside any folder the web server publishes, and are downloaded only through a route that checks your membership.
Nothing changes without a person
- Proceny does not connect to or write into your ERP. It produces an export file; you import it. Exports contain approved rows only.
- Values read from a scan are never used without a person approving them, and values in doubt are shown next to the page they came from.
- Exported CSV and XLSX files neutralise cells that start like a formula (
=,+,-,@), so a supplier's text cannot run in your spreadsheet.
Accounts and sessions
- Passwords are stored as scrypt hashes. Session cookies are HTTP-only and sent over HTTPS only; sign-in, sign-up and password endpoints are rate limited.
- Password-reset links work once and for one hour, and a reset signs out every session. Team invitations work once, for one e-mail address, for seven days.
Logs and activity
- Application logs never contain file contents or price rows; passwords, tokens and e-mail addresses are removed.
- Admins see an activity history of imports, reviews, exports and settings. It records who did what, not the contents of your files.
- Product usage is counted in our own database without cookies or third-party scripts, and never includes names, file names, prices or e-mail addresses.
Keeping and deleting data
- Your data is kept while your organisation exists.
- The owner can delete the organisation. It disappears for every member at once, and its records and files are then erased. Copies in backups are removed when those backups expire.
- People can delete their own account in Settings once they no longer own an organisation.
What is not in place yet
- No SOC 2, ISO 27001 or similar certification, and no third-party penetration test so far.
- Uploaded files are not scanned for malware. They are never executed or opened by desktop software on our side.
- The privacy policy and terms are drafts until the company details are final.
Reporting a security problem
Write to [email protected] with what you found and how to reproduce it. Please do not include other people's data.