Skip to content
Skip to content
Prime Fixel logo
Trust

Security & Trust overview

How Prime Fixel protects customer data across our website, engagements, and admin operations.

About this page. This page is maintained by Prime Fixel to answer common security and privacy questions about our website and engagements. It describes controls we have enabled today and is not a third-party certification or audit report. Security is a shared responsibility between Prime Fixel, our platform providers, and our customers.
Platform

Web platform & hosting

HTTPS everywhere with HSTS

All traffic is served over TLS. HTTP Strict Transport Security is enabled with a two-year max-age, includeSubDomains, and preload eligibility.

Hardened response headers

Every response carries a Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and a restrictive Permissions-Policy that disables camera, microphone, and geolocation by default.

Row-level security on customer data

Customer records (inquiries, quotes, admin content) live in a managed Postgres database with row-level security policies. Public write endpoints (contact, quote) accept inserts only and never expose reads to anonymous visitors.

Safe rendering & sanitized links

User-supplied URLs stored in admin content are sanitized against javascript: and other unsafe schemes before render. Markdown output is escape-encoded; no arbitrary HTML from untrusted sources is inlined.

Access

Admin access & identity

Multi-factor authentication for admins

Admins are required to enroll a TOTP authenticator and complete a step-up challenge before reaching privileged surfaces. Recovery codes are shown once at enrollment.

Least-privilege role model

Roles live in a dedicated user_roles table, never on profile records. Server functions verify the caller's role with a SECURITY DEFINER check before performing any privileged action.

Breached-password protection

New and rotated passwords are checked against the Have I Been Pwned k-anonymity API. Passwords found in known breaches are rejected during sign-up and password change.

Audit logging on admin actions

Privileged actions (role grants, inquiry status changes, MFA enrollment) are recorded with actor, timestamp, and target for after-the-fact review.

Data

Data collection & retention

We collect only the information needed to respond to an inquiry or deliver a service you have requested — typically your name, business email, phone number, and a short description of your requirement. See our Privacy Policy for the full list of data categories, lawful bases, and retention windows.

Cookie usage, analytics, and consent choices are described in our Cookie Policy. Non-essential cookies load only after you accept them.

Contractual commitments — including service scope, service levels, and termination — are covered in our Terms & Conditions and Service Level Agreement.

Shared responsibility

What we do vs. what customers own

Prime Fixel responsibilities

  • • Operating this website and its admin surfaces securely.
  • • Applying the platform controls listed above.
  • • Responding to security or privacy reports promptly.
  • • Notifying affected customers of confirmed incidents.

Customer responsibilities

  • • Keeping account credentials confidential.
  • • Reviewing scoped access before granting our team system permissions.
  • • Sharing sensitive information only through channels agreed in your engagement.
  • • Reporting suspected misuse of your account to the contact below.

Report a security concern

If you believe you have found a vulnerability, a data-handling issue, or a suspicious account activity, please contact us. We investigate every credible report and will confirm receipt within one business day.

Have a compliance or security questionnaire?

Send it over and our team will respond with the completed document.