What we hold, and what we deliberately do not.
Prospen is early. This page says exactly where it stands, and claims nothing it has not done.
Hosting and transport
The application and this site run on Vercel. Every request is served over HTTPS with TLS, and HTTP requests are redirected. Vercel operates the underlying infrastructure and its own security controls.
Data minimisation
We store the account email, the profile you confirm, and the runs and partner lists your account produced. That is what the product needs. We do not collect card details on the free plan and we do not build a profile of you beyond your own account.
No stored credentials for your other tools
Prospen has no integrations that require your credentials today, and stores none. When integrations ship they will use the provider’s official authorisation flow, with scopes shown before you approve, and you will be able to revoke access from your own side.
A human approves before contact
Nothing is sent to a partner on your behalf without your explicit approval. When outreach ships, sending rules, suppression and stop-on-reply are part of it, not an afterthought.
What we do not claim
No SOC 2, no ISO 27001, no penetration-test report. We have not done them yet. If a certification matters to your procurement, tell us where you need to get to and we will tell you honestly whether we are there.
Reporting a vulnerability
Email hello@tasken.aiwith the subject “Security”. Tell us what you found and how to reproduce it. We will acknowledge within one business day, keep you updated, and will not pursue anyone who reports in good faith and does not access other people’s data.
Questions
Contact us and ask. A vague answer here would be worse than no page at all.