PropIQ Information Security Policy
Effective Date: July 9, 2026 | Last Updated: July 9, 2026 | Version 1.0
1. Purpose
This Information Security Policy (“Policy”) establishes the framework by which Rocketfuel AI, Inc., a Delaware corporation doing business as PropIQ, with its principal place of business in Cincinnati, Ohio (“PropIQ,” “we,” “our”), protects the confidentiality, integrity, and availability of its information systems and the data entrusted to it, including customer account information, payment information, and the property and consumer data that powers our platform. This Policy is informed by recognized industry frameworks and practices, including the NIST Cybersecurity Framework and CIS Critical Security Controls. The controls described in this Policy are implemented in a manner commensurate with PropIQ’s size, complexity, and risk profile, and are expected to mature and evolve as the company grows.
2. Scope
This Policy applies to all PropIQ employees, contractors, and third parties who access PropIQ systems or data (“personnel”), and to all information assets owned or managed by PropIQ, including production infrastructure, corporate systems, endpoints, applications, and data in any form or location.
3. Roles and Responsibilities
- Security Owner: PropIQ leadership designates a security owner responsible for maintaining this Policy, overseeing the security program, coordinating risk assessments, and leading incident response.
- Management: Managers are responsible for ensuring personnel under their supervision understand and comply with this Policy and complete required training.
- All personnel: All personnel are responsible for handling data in accordance with this Policy, protecting their credentials, and promptly reporting suspected security incidents.
4. Data Classification and Handling
PropIQ classifies information into the following categories, each with corresponding handling requirements:
- Restricted: information whose unauthorized disclosure could cause significant harm, including customer account credentials, payment-related information, and personal information of consumers and customers. Restricted data must be encrypted in transit and at rest, and access is limited to personnel with a documented business need.
- Confidential: internal business information not intended for public release, such as internal documents, source code, and operational data. Confidential data may be shared internally on a need-to-know basis and externally only under appropriate agreements.
- Public: information approved for public release, such as marketing materials and published policies.
Personnel must store company data only in approved systems and locations. Restricted and Confidential data must not be stored on personal devices or unapproved services, transmitted over unencrypted channels, or shared with unauthorized parties.
5. Access Control
- Least privilege: Access to systems and data is granted based on the principle of least privilege — personnel receive only the access necessary to perform their job functions.
- Unique accounts: Each user is assigned unique credentials. Shared accounts are prohibited except where technically required, in which case access is documented and controlled.
- Authorization and review: Access to production systems, administrative consoles, and Restricted data requires authorization and is reviewed periodically, with access adjusted upon role change.
- Offboarding: Upon termination of employment or engagement, all system access is revoked promptly, and company assets and data are recovered.
6. Authentication and Credential Management
- Multi-factor authentication: Multi-factor authentication (MFA) is enabled where supported for access to production infrastructure, administrative systems, email, and other critical business applications.
- Password standards: Passwords must be unique, meet reasonable complexity and length standards, and should not be reused across systems. Use of a password manager is encouraged for all personnel.
- Secrets management: API keys, tokens, and service credentials are stored in approved locations, rotated as appropriate, kept out of source code where practicable, and revoked promptly if compromise is suspected.
7. Encryption
- In transit: Data transmitted over public networks is encrypted using current industry-standard protocols (such as TLS).
- At rest: Restricted data, including customer personal information and production databases, is protected using industry-standard encryption at rest provided by our cloud infrastructure.
- Key management: Encryption keys are managed through the key management capabilities of our cloud infrastructure providers, with access restricted.
8. Infrastructure and Network Security
PropIQ hosts its Services with leading cloud infrastructure providers that maintain independently audited security programs (e.g., SOC 2 and ISO 27001 certified data centers). PropIQ’s controls include:
- segmentation between production and non-production environments where practicable;
- firewalls and security groups configured to restrict traffic to required ports and protocols;
- application of security patches on a risk-prioritized basis;
- logging and monitoring of production systems to help identify anomalous or unauthorized activity;
- periodic vulnerability review of production systems, with remediation prioritized by risk severity.
9. Secure Software Development
- Change management: Application code changes are managed through version control and reviewed or tested as appropriate prior to deployment to production.
- Secure coding: Development follows secure coding practices that address common vulnerability classes (e.g., OWASP Top 10), including input validation and secure session management.
- Dependency management: Third-party libraries and dependencies are updated on a risk-prioritized basis as vulnerabilities become known.
- Data in non-production: Use of production data in development or test environments is limited, and protections are applied where such use is necessary.
10. Endpoint Security
Devices used to access PropIQ systems should have disk encryption enabled, screen lock with authentication, and current operating system and security updates. Personnel must not disable security controls and must report lost or stolen devices promptly to support@trypropiq.ai.
11. Vendor and Third-Party Risk Management
Before engaging vendors that will store, process, or access PropIQ data, PropIQ considers the vendor’s security posture, giving preference to established vendors with independent attestations (such as SOC 2 or ISO 27001). Vendors with access to Restricted data are bound by contractual confidentiality and data protection obligations. Vendor access is limited to what is necessary for the service provided. Data providers are evaluated for lawful sourcing of the data they supply.
12. Personnel Security and Training
- Confidentiality: Personnel are subject to confidentiality obligations as a condition of employment or engagement.
- Security training: Personnel receive security awareness guidance upon onboarding and periodically thereafter, covering topics including phishing, credential hygiene, data handling, and incident reporting.
- Enforcement: Personnel who violate this Policy are subject to corrective action, up to and including termination of employment or engagement.
13. Physical Security
Production systems are hosted in cloud provider data centers with physical security controls maintained and audited by those providers, including access badging, surveillance, and environmental protections. PropIQ does not operate its own data centers. Personnel working remotely must take reasonable precautions to prevent unauthorized viewing or access to company data and devices.
14. Security Incident Response
PropIQ maintains an incident response process covering the full incident lifecycle:
- Detection and reporting: Personnel must report suspected security incidents — including phishing, credential compromise, lost devices, or suspected unauthorized access — immediately to support@trypropiq.ai.
- Triage and assessment: The security owner assesses reported events to determine severity, scope, and whether personal data may be affected.
- Containment and remediation: Affected systems and accounts are isolated or disabled as needed to contain the incident, followed by remediation of the root cause.
- Notification: If an incident results in unauthorized access to personal information, PropIQ will notify affected individuals, customers, and regulators as required by applicable law and contractual commitments, without undue delay.
- Post-incident review: After significant incidents, PropIQ conducts a post-incident review to identify lessons learned and improve controls.
15. Business Continuity and Data Backup
Production data is backed up on a regular schedule with backups stored redundantly within our cloud infrastructure. Backup restoration capabilities are validated as appropriate. PropIQ leverages the availability and redundancy capabilities of its cloud providers to support recovery of the Services in the event of a disruption.
16. Data Retention and Secure Disposal
Data is retained in accordance with PropIQ’s data retention practices and applicable legal requirements, as described in our Privacy Policy. When data is no longer required, it is deleted or de-identified using secure methods. Decommissioned storage media and devices are sanitized or destroyed in a manner that prevents data recovery.
17. Compliance, Risk Assessment, and Policy Review
PropIQ periodically assesses risks to its systems and data and adjusts controls accordingly. This Policy is reviewed periodically, and upon significant changes to the business, technology environment, or legal requirements, and is updated as needed. Exceptions to this Policy require approval by the security owner.
18. Questions and Reporting
Questions about this Policy, and reports of suspected security vulnerabilities or incidents, should be directed to:
Rocketfuel AI, Inc. d/b/a PropIQ — Security
Cincinnati, Ohio
Email: support@trypropiq.ai (subject line: “Security”)
Website: https://predicted.trypropiq.ai