Security and Compliance | PR.co

Security & Compliance

Enterprise-grade security for organizations that cannot afford to get it wrong

PR.co is trusted by communications teams at listed companies, government organizations, and some of the largest enterprises. We protect that trust through a formal information security program, independent audits, external security assessments, top-notch cloud infrastructure, and enterprise-grade controls across our platform, software, and organization.

Security at PR.co is not a collection of one-off measures. It is managed through policies, processes, technical controls, continuous monitoring, and independent validation.

ISO 27001:2022

PR.co has been ISO/IEC 27001:2022 certified since 9 June 2026 by RvA accredited certification body Brand Compliance B.V.

ISO/IEC 27001 is the internationally recognized standard for information security management. It confirms that an organization has implemented an Information Security Management System (ISMS) designed to identify, assess, treat, monitor, and continually improve how information security risks are managed.

For our customers, this means our ISMS is independently audited by an accredited certification body and built around structured risk management, documented controls, management accountability, continual improvement, and the protection of the confidentiality, integrity, and availability of information.

Download our ISO/IEC 27001 certificate

Learn more about Brand Compliance

Independent annual penetration testing

PR.co works with an independent software cybersecurity partner to conduct annual external grey-box penetration tests of our entire software platform.

Our external software security assessments are conducted by Secwatch and are designed to assess our platform from the perspective of a realistic attacker with controlled knowledge of the environment and access to controlled user accounts. The goal is not just to identify technical vulnerabilities, but to prioritize risk, validate remediation, educate the PR.co technical staff, and strengthen the platform over time.

Our penetration-testing program includes:

Security reports generated through this process are available to customers and prospective enterprise customers on request, subject to appropriate confidentiality arrangements.

In addition, some of our largest enterprise and government customers have performed their own recurring penetration tests and vendor security assessments of PR.co for more than a decade as part of their internal assurance processes.

Learn more about Secwatch

Hosted on AWS cloud infrastructure

PR.co is hosted on Amazon Web Services, one of the world’s leading cloud infrastructure platforms for highly regulated, security-sensitive, and enterprise workloads.

AWS operates global infrastructure, security, compliance, and resilience programs at a scale that would be impossible for most individual software vendors to reproduce independently. pr.co builds on this foundation while remaining responsible for the security of our own application, configurations, data, access controls, monitoring, and operational procedures under the AWS shared-responsibility model.

AWS maintains a broad compliance program covering many global security and privacy standards. AWS states that it supports 143 security standards and compliance certifications, including PCI DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-3, and NIST 800-171. AWS also maintains certifications for ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, ISO 22301, ISO/IEC 20000-1, ISO 9001, and CSA STAR CCM.

PR.co uses AWS to support:

Read about AWS Compliance

View AWS Compliance Programs

Secure payments with PCI compliance

Any direct payments (i.e. via credit card or SEPA) made to PR.co are fully facilitated through our PCI compliant partner ChargeBee. Chargebee is PCI DSS Level 1 certified – the highest standard of PCI compliance, and is listed on the VISA Global Registry of Service Providers.

View Chargebee's security page

Enterprise security features in the PR.co platform

Security must also be practical for the teams using PR.co every day. Our platform includes enterprise controls that help customers protect access, reduce risk, and align PR.co with their internal security policies.

Available platform security features include:

Additional controls and implementation options are available depending on your setup and contract.

Platform security, availability, and resilience

The PR.co platform is designed to remain secure, available, and resilient under changing traffic, operational, and threat conditions.

Our infrastructure uses distributed systems that can scale based on traffic and recover from incidents. Where possible, we use managed AWS services that benefit from AWS-managed operational controls, security patching, and infrastructure maintenance.

Our security and availability measures include:

We maintain a live platform status page so customers can view current and historical availability information.

View PR.co platform status

Secure development and change management

Security is built into how we design, review, test, and deploy the PR.co platform.

Our development process combines automated checks, human review, and AI-assisted safeguards to reduce the likelihood of introducing security, privacy, or availability issues into production.

Our secure development practices include:

This layered approach helps ensure that changes are reviewed, traceable, and aligned with our security and compliance obligations.

Organizational security and access governance

Security at PR.co extends beyond the application. We maintain organizational controls designed to protect customer data, internal systems, and company operations.

Our internal security controls include:

Only authorized personnel with a legitimate business need may access systems or data required for their role.

Privacy and regulatory compliance

PR.co is based in the Netherlands and operates with a strong focus on European privacy, security, and regulatory expectations.

Our privacy and compliance program is designed to support applicable obligations under relevant privacy, cybersecurity, and technology regulations, including the GDPR, UK GDPR, CCPA, ePrivacy Directive, NIS2-related cybersecurity requirements as implemented in applicable jurisdictions, the EU AI Act as it progressively applies, and other relevant laws and regulations applicable to our activities in the Netherlands and the European Union.

Our privacy and compliance measures include:

Read our Privacy Policy

Security documentation and enterprise assessments

We understand that enterprises, listed companies, public-sector organizations, and regulated teams often need detailed security documentation before selecting a software vendor.

Upon request, we can provide relevant security and compliance materials, including:

Please contact your PR.co account representative or email dpo@pr.co to request security documentation.

Vulnerability disclosure

We take security reports seriously. If you believe you have identified a vulnerability in PR.co, please contact us responsibly at: security@pr.co

Please include enough detail for our team to understand, reproduce, and assess the issue. We review reported issues, prioritize them based on risk, and take appropriate remediation steps. Urgent high-severity findings will be eligible for a reward.

That said, although we carefully review and respond to every report that gets sent our way, we can't promise any guaranteed rewards or bounties simply because of duplicates, too low severity, inability to reproduce, or then being out-of-scope.