Trust Centre

Security you can verify

Progressive Robot builds automation, AI and infrastructure for other businesses — so we hold our own platform to the standard we sell. This page explains, in plain language, how progressiverobot.com is secured, how we handle your data, and exactly where we are on the road to SOC 2. Every claim here describes a control that is live today, and most can be checked from your own browser.

  • TLS 1.3
  • HSTS preload
  • OWASP CRS WAF
  • HTTP/3
  • Audit logged
  • GDPR-aligned
At a glance

Our security posture

Six things worth knowing about how this platform is run. The detail — and the honest caveats — follow below.

  • Encrypted everywhere

    All traffic is encrypted with TLS 1.3, and HSTS with a two-year max-age, includeSubDomains and preload means browsers refuse to connect insecurely.

  • Web application firewall

    Requests are filtered by ModSecurity running the OWASP Core Rule Set before they ever reach the application.

  • Hardened platform

    Current WordPress release, XML-RPC disabled entirely, a non-default administrative endpoint and hardened response headers.

  • Audit-logged administration

    Administrator and content actions are recorded in a security audit log, so changes are attributable after the fact.

  • Version-controlled changes

    The entire production codebase is tracked in Git. Every change is attributable, reviewable and reversible.

  • Privacy by default

    GDPR-aligned consent management governs cookies and tracking, and we collect only the data we need to respond to you.

The detail

How the platform is secured

The controls below are the ones running on this site today. Where a control is easy to verify externally — headers, TLS, protocol support — we encourage you to check for yourself.

Infrastructure & network

Encryption and filtering at the edge, before requests reach the application.

  • TLS 1.3 encryption in transit, with HTTP Strict Transport Security set to a two-year max-age, includeSubDomains and preload.
  • Web application firewall: ModSecurity with the OWASP Core Rule Set inspects requests at the web-server tier.
  • Modern protocols: HTTP/2 and HTTP/3 (QUIC) are served, reducing exposure to legacy-protocol attacks.
  • Hardened response headers including Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy.

Application & platform

A deliberately reduced attack surface on top of an up-to-date core.

  • Current software: the site runs the current WordPress release, and core and plugin patches are applied promptly.
  • Reduced attack surface: XML-RPC is disabled entirely and the administrative login lives at a non-default endpoint.
  • Role-based access: administrative access follows least privilege using WordPress role-based permissions.
  • Audit trail: administrator and content actions are recorded in a security audit log.

Change management

Production changes are deliberate, attributable and reversible.

  • Everything in version control: the full production codebase is tracked in Git with attributable history.
  • Small, single-purpose changes: site behaviour is built as focused, independently removable modules rather than sweeping rewrites.
  • Pre-change snapshots: risky operations are preceded by targeted backups of the data they touch.

Data protection & privacy

Aligned with UK and EU GDPR. See our Privacy Policy for the full picture.

  • Consent management: cookies and tracking are governed by a GDPR consent platform — nothing non-essential runs without your consent.
  • Data minimisation: we collect only what is needed to respond to your enquiry or deliver the service you asked for.
  • Encrypted submission: anything you send us through this site travels over an encrypted connection.

Responsible AI & transparency

We are an AI company — our crawler policy is explicit, not accidental.

  • Machine-readable AI policy: llms.txt, ai.txt and ai.json are published at the site root.
  • Explicit signals: X-AI-Training and Content-Signal response headers declare that our public content is open to AI search and AI training, with attribution required.
  • Transparency over blocking: we would rather state our terms clearly to AI systems than pretend they do not exist.

Vulnerability disclosure

Found something? We want to know about it.

  • Report it: email [email protected] with a description of the issue and steps to reproduce it.
  • Good faith is welcome: we will acknowledge reports promptly and ask only that you give us reasonable time to remediate before public disclosure.
Compliance

Our road to SOC 2

Our security programme is modelled on the AICPA Trust Services Criteria — the framework behind SOC 2 — starting with the Security (Common) Criteria. Here is where we are, stated honestly.

  1. Harden the platform

    Firewall, TLS, hardened headers, reduced attack surface, audit logging — the live controls documented on this page.

  2. Document policies & controlsNow

    Written security policies mapped to the Trust Services Criteria, from access control to incident response.

  3. Collect evidence continuously

    Change history, audit logs, access reviews and monitoring retained as audit-ready evidence.

  4. Independent attestation

    A SOC 2 examination by a licensed CPA firm — Type I, then Type II — scheduled as customer demand requires.

The plain-English version: Progressive Robot is not SOC 2 certified today, and we will not pretend otherwise. What we have is a working security programme whose controls are live rather than aspirational. If your procurement process requires the formal report, tell us — customer demand is exactly what schedules the audit. Details of our controls are available on request.

FAQ

Common questions

Is Progressive Robot SOC 2 certified?

Not yet. We run a SOC 2-aligned security programme: our controls are modelled on the AICPA Trust Services Criteria and we operate a continuous readiness process. A formal independent attestation is planned as customer demand requires it. Details of our controls are available on request.

How is data protected in transit?

All traffic to progressiverobot.com is encrypted with TLS 1.3 and protected by HTTP Strict Transport Security (HSTS) with a two-year max-age, includeSubDomains and preload, so browsers refuse to connect insecurely.

How do I report a security vulnerability?

Email [email protected] with a description of the issue and steps to reproduce it. We welcome good-faith reports, will acknowledge them promptly, and ask that you give us reasonable time to remediate before public disclosure.

What is your policy on AI crawlers and AI training?

We publish an explicit machine-readable AI policy: llms.txt, ai.txt and ai.json at the site root, plus X-AI-Training and Content-Signal response headers. Our public content is open to AI search and training with attribution required.

Questions about our security?

Whether you are running vendor due diligence, filling in a security questionnaire, or just want a straight answer about how we would look after your systems — talk to us. You can also read about the security services we provide to clients.

CHAT