Progressive Robot builds automation, AI and infrastructure for other businesses — so we hold our own platform to the standard we sell. This page explains, in plain language, how progressiverobot.com is secured, how we handle your data, and exactly where we are on the road to SOC 2. Every claim here describes a control that is live today, and most can be checked from your own browser.
Six things worth knowing about how this platform is run. The detail — and the honest caveats — follow below.
All traffic is encrypted with TLS 1.3, and HSTS with a two-year max-age, includeSubDomains and preload means browsers refuse to connect insecurely.
Requests are filtered by ModSecurity running the OWASP Core Rule Set before they ever reach the application.
Current WordPress release, XML-RPC disabled entirely, a non-default administrative endpoint and hardened response headers.
Administrator and content actions are recorded in a security audit log, so changes are attributable after the fact.
The entire production codebase is tracked in Git. Every change is attributable, reviewable and reversible.
GDPR-aligned consent management governs cookies and tracking, and we collect only the data we need to respond to you.
The controls below are the ones running on this site today. Where a control is easy to verify externally — headers, TLS, protocol support — we encourage you to check for yourself.
Encryption and filtering at the edge, before requests reach the application.
A deliberately reduced attack surface on top of an up-to-date core.
Production changes are deliberate, attributable and reversible.
Aligned with UK and EU GDPR. See our Privacy Policy for the full picture.
We are an AI company — our crawler policy is explicit, not accidental.
Found something? We want to know about it.
Our security programme is modelled on the AICPA Trust Services Criteria — the framework behind SOC 2 — starting with the Security (Common) Criteria. Here is where we are, stated honestly.
Firewall, TLS, hardened headers, reduced attack surface, audit logging — the live controls documented on this page.
Written security policies mapped to the Trust Services Criteria, from access control to incident response.
Change history, audit logs, access reviews and monitoring retained as audit-ready evidence.
A SOC 2 examination by a licensed CPA firm — Type I, then Type II — scheduled as customer demand requires.
The plain-English version: Progressive Robot is not SOC 2 certified today, and we will not pretend otherwise. What we have is a working security programme whose controls are live rather than aspirational. If your procurement process requires the formal report, tell us — customer demand is exactly what schedules the audit. Details of our controls are available on request.
Not yet. We run a SOC 2-aligned security programme: our controls are modelled on the AICPA Trust Services Criteria and we operate a continuous readiness process. A formal independent attestation is planned as customer demand requires it. Details of our controls are available on request.
All traffic to progressiverobot.com is encrypted with TLS 1.3 and protected by HTTP Strict Transport Security (HSTS) with a two-year max-age, includeSubDomains and preload, so browsers refuse to connect insecurely.
Email [email protected] with a description of the issue and steps to reproduce it. We welcome good-faith reports, will acknowledge them promptly, and ask that you give us reasonable time to remediate before public disclosure.
We publish an explicit machine-readable AI policy: llms.txt, ai.txt and ai.json at the site root, plus X-AI-Training and Content-Signal response headers. Our public content is open to AI search and training with attribution required.
Whether you are running vendor due diligence, filling in a security questionnaire, or just want a straight answer about how we would look after your systems — talk to us. You can also read about the security services we provide to clients.