As a financial-services partner, Pro Collections handles some of the most sensitive data your customers trust you with. Our security and compliance program is engineered to protect every account we touch — physically, technically, and procedurally.
Our hosting partner operates under an independently audited control framework spanning international privacy, security, and payment standards.
Security is a layered discipline. Here's what protecting your data looks like inside Pro Collections.
Our collection software is hosted in a fully redundant Tier 3 cloud environment with continuous monitoring, encrypted transport and storage, and best-in-class access controls.
Nightly backups, real-time monitoring (Zabbix), endpoint protection (ESET), and periodic network & penetration tests.
Database- and column-level encryption, redaction, MFA, automatic audit logging, and role-based account access.
OWASP-aligned development practices with Veracode and other scanning systems used to remediate vulnerabilities.
Authentication, authorization, TLS/SSL at the channel layer, and protected service keys.
IP blacklisting after three failed login attempts, distributed monitoring, and real-time anomaly detection.
Data is encrypted at rest and in transit; SSL/TLS for all transport, with tokenization for payment data.
A mature program isn't only technical — it depends on the policies, audits, and continuity planning that sit behind it. Pro Collections maintains a documented framework covering every stage of the data-processing cycle.
Built into our operating system, Compliance Watch generates system-level reports that help prevent policy violations and circumvention of work plans. It enforces provincial and federal law adherence, time-zone restrictions, call-attempt caps by province, cell-phone regulations, place-of-employment contact restrictions, and restricted call dates.
We're happy to walk procurement, legal, and InfoSec teams through our full program.