How Prodigy EMS protects your training records, employee data, and certifications. Built for the privacy and reliability EMS organizations require.
Last updated: May 7, 2026
Hosted on Amazon Web Services in the United States. Data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard AES-256.
Single sign-on (SSO/SAML), multi-factor authentication, and role-based permissions for administrative access. We perform periodic reviews of access to production systems.
Automated vulnerability scanning across application code, dependencies, and runtime via Aikido, Dependabot, and CrowdStrike. All code changes go through review and protected branches. We engage external security testing as part of our SOC 2 program.
Continuous automated monitoring with on-call response. We maintain a documented incident response plan and notify affected customers in line with our contractual and regulatory commitments.
We review critical third-party vendors and require security and privacy commitments from providers that handle customer data.
Data classification, retention, and deletion procedures aligned with our SOC 2 program. Encrypted backups with documented restore procedures.
Confidentiality agreements and code of conduct for all employees, plus ongoing security awareness training as part of our SOC 2 program.
We honor data subject access, correction, and deletion requests. See our Privacy Policy for full details on how we handle personal information.
Found a security issue? We appreciate responsible disclosure. Please email our security team — we will acknowledge reports promptly and coordinate a fix.
security@prodigyems.com