Proton

Proton prioritizes our community’s privacy and data security in every aspect of our business. 

To further demonstrate our commitment, we underwent a rigorous external audit and – on May 2, 2024 – received our ISO 27001(new window) certification.

As an organization founded by scientists who met at CERN, we see peer review and transparency as a cornerstone of our mission. That’s why we make all our apps open source, allowing anyone to examine our code.

Here’s what this latest certification means and what’s next for Proton.

How we did it 

At Proton, our philosophy is to focus first on good security and let compliance with standards and frameworks follow. 

Our philosophy was confirmed by the fact that, to comply with ISO 27001:2022, we only needed to formalize and document some of our current processes. No fundamental changes in how our business or teams operate were required.

This comprehensive audit spanned 14 days and involved over 15 dedicated teams, each thoroughly evaluating the information security management systems underlying all Proton products.  

Basically, our security management operations were double-checked and validated by independent experts.

Why we did it 

At Proton, we believe in building products our community can trust. We also believe that trust must be earned. As an organization founded and run by former scientists, we believe all claims must be not only investigated but verified, including our own

Transparency and peer review are the best ways to ensure systems function as they’re supposed to and vulnerabilities are quickly resolved. This approach only becomes more important as we grow and add new services. This certification not only proves our methodology is sound, it makes it easier for us to work with larger organizations in the future. 

We pursued this certification for the same reason we open our products to scrutiny through external penetration tests and our bug bounty program: To ensure any vulnerabilities in our service are swiftly identified and resolved so your information remains safe. 

What’s next 

Looking ahead, we plan to strengthen support for our business customers, particularly those handling sensitive data, by publishing further information and audit reports detailing our security controls. 

Thank you for being part of our mission to build a better internet where privacy is the default. Stay tuned for more updates and new features designed to keep your data safe and secure.

Related articles

Roblox has been accused for years of exposing kids to inappropriate content and bad actors. We describe its safety features
  • Privacy guides
Roblox has suffered scandals over inappropriate content. We share what you need to know and what you can do to use it more safely.
Protect your family's privacy and safety on the internet
Kids, parents, and grandparents, everyone needs to know how to use the internet wisely. Learn how to keep your kids safe online and your family's data private.
Minecraft offers parental controls you can use to keep your kids safe while they play.
  • Privacy guides
Learn about Minecraft's parental controls and create a plan so your child has a fun, safe gaming experience without sacrificing their personal information.
Instagram now offers Teen Accounts, which turn on many several protections by default
  • Privacy guides
Learn about Instagram's default safety settings for teens and its parental controls so you can help your child avoid inappropriate content.
Teens' accounts on TikTok have many privacy protections turned on by default
  • Privacy guides
Many parents wonder if TikTok is safe. We explain the data TikTok collects, how its default protections work for teens, and how to use its parental controls.
A teen's account on Snapchat turns on many privacy protections by default
  • Privacy guides
Many parents wonder if Snapchat is safe. We explain the data Snapchat collects, how it keeps kids engaged, and how to use its parental controls.