Legal

Security

Last updated: March 26, 2026 · BoringDollars, Inc. — a Delaware corporation

Responsible disclosure: Found a vulnerability? Email security@prago.io. We acknowledge within 24 hours and treat all good-faith reports with full cooperation — no legal action against researchers.

1. Our Commitment

Prago holds OAuth access to your advertising accounts and analytics data. That is a high-trust position. Our security practices are designed around that responsibility — not as an afterthought, but as a core design constraint.

This page describes what we do to protect your data and what you can expect from us. It is intentionally written at a principles level rather than listing specific tools or configurations — security through transparency of commitment, not transparency of implementation.

Questions? security@prago.io

2. Infrastructure

2.1 Hosting

Prago runs on enterprise-grade cloud infrastructure in the United States, operated by a major cloud provider with ISO 27001, SOC 2 Type II, and FedRAMP certifications. All infrastructure is provisioned with the principle of least privilege and is not publicly exposed beyond what is strictly required to serve the application.

2.2 Encryption

2.3 Network Controls

3. Application Security

3.1 Authentication

3.2 Access Control

3.3 Secure Coding Practices

4. Data Handling

4.1 Tenant Isolation

Each account's data is strictly isolated at the data layer. Queries are designed to enforce this at the database level, not just the application level — one account cannot inadvertently or maliciously access another account's data.

4.2 OAuth Token Lifecycle

4.3 AI Inference

4.4 Backups and Retention

5. Operational Security

5.1 People and Processes

5.2 Monitoring

5.3 Incident Response

We maintain a documented incident response process. In a confirmed security incident:

6. Compliance

Enterprise customers may request security questionnaire responses and (once available) our SOC 2 report under NDA: security@prago.io

7. Responsible Disclosure

Security researchers who follow responsible disclosure are protected from legal action by us. To report a vulnerability:

We recognize researchers publicly in our security acknowledgments and assess case-by-case goodwill rewards for significant findings.

8. Contact

Security Team — BoringDollars, Inc.

Vulnerability reports: security@prago.io

For encrypted communication, email us to request our public key.

131 Continental Dr Suite 305, Newark, DE 19713, United States