Prompter.

Security & data

Where your company’s data lives, and who can reach it.

Your members’ contact details, your cast’s headshots and your auditionees’ files sit on this platform. This page says where they are kept, how one company is kept apart from another, and what is not finished yet.

What Prompter runs on.

Nothing sits on a private server. Prompter runs on named providers, and the table below is the whole list — the same list published in our privacy policy, with the same regions.

ProviderWhat it doesWhere
SupabaseDatabase, file storage, authenticationTokyo, Japan
VercelApplication hostingUnited States, global edge
CloudflareDomain name service, and off-site backup of uploaded filesUnited States, global
StripeSubscription billing and ticketingUnited States, global
ResendTransactional emailUnited States
ZohoPrompter's own emailAustralia
AnthropicThe Bard AI assistantUnited States

Supabase is SOC 2 Type 2 compliant and ISO 27001 certified, and publishes that all customer data is encrypted at rest with AES-256 and in transit over TLS. Published by the provider and last checked on 11 September 2026 source.

Separation

How one company is kept apart from another.

It is enforced in two places, and they do different jobs.

In the database. Row-level security is enabled on every one of the 81 tables, with 185 policies across them. That is what stops anyone reaching the data directly — the public key that ships inside every browser returns no rows at all from any table holding company data.

In the application. Each request checks the organisation and the production before it reads or writes. This is the layer that carries most of the traffic, so it is the layer a mistake would live in, and it is the one tested hardest. We would rather tell you that than let the database answer stand in for both.

Holding a role in an organisation does not grant access inside a production — that is assigned per show. Cast and crew hold a production role only and never reach the organisation area. Nobody can change their own role.

How it is built.

Every change to the database is a numbered, reviewable migration — there are 206 of them, each one written down with its reasoning. An automated test suite runs before anything ships, and an automated security advisor runs against the database on a schedule rather than when somebody remembers.

Payments never touch Prompter. Card details are entered on a page served by Stripe, and there is no card field anywhere in the product and no card number in the database. For ticketing, each company is the merchant through its own Stripe account, so money moves from the buyer to the company directly.

When Prompter support opens an account to resolve a problem, that session is recorded with a reason, is read-only, and expires after an hour. The record is included in your own data export, so you can check it without asking us.

Stated rather than implied

What is not finished yet.

Prompter is young, and a list of strengths with nothing beside it tells you very little. These are the things we would want to know about, if we were you.

  • Sensitive actions re-check your password, not your second factor

    Two-step sign-in protects the sign-in itself, and an organisation can require it of its owners and admins. Deleting an organisation, closing an account, or a support session still asks for your password again rather than a code from your authenticator. Raising those to the second factor is the remaining piece of this work.

Prompter has also not had an independent penetration test, and holds no SOC 2 or ISO 27001 certification of its own. The security testing done so far is our own work. We would rather say that plainly than let the certifications of the platform underneath stand in for Prompter’s.

If you need more than this.

There is a fuller document — eleven security, privacy and commercial questions answered in detail, including our current limitations, written for a company doing a proper vendor review. Ask and we will send it.

privacy@get-prompter.app — for the full documentation, or any question this page does not answer.

Found a vulnerability? Email support@get-prompter.app with SECURITY in the subject line. You will be told whether it is being acted on, and when it is fixed. There is no bug bounty, and saying so is fairer than leaving it to be assumed.

See also our privacy policy and terms.