Proxara

Due diligence & deployment, ready to download

The same documentation we hand to reviewers. Everything a security or IT team needs to assess Proxara, whether the firm connects its systems or also runs the device agent.

Two documents to download, in HTML and PDF, with no sign-in. Two more for the connector review, below.

Two documents for the device rollout

One for the team that rolls it out, one for the team that signs off on it.

01 · For IT · macOS & Windows

Deployment Guide

MDM and manual installation for macOS and Windows. Silent deployment, certificate trust, and proxy configuration.

  • Prerequisites & what the installer does
  • The Name-Constrained root certificate
  • MDM (Jamf · Intune · Kandji · Mosyle) & manual paths
  • Network architecture & day-one timeline
  • Verification & clean uninstall
Download HTMLPDF
02 · For Security & Compliance

Due Diligence Pack

Security assessment for the device-wide TLS proxy. Certificate handling, data isolation, and compliance documentation.

  • What it can and cannot do, by design
  • Data handling: flagged, unflagged, on-device
  • Encryption, isolation & access controls
  • Subprocessors & backend infrastructure
  • Compliance support mapped to the rules
Download HTMLPDF

Two more for the connector

Proxara Connect installs nothing on a device, so its review is a different one: what the firm authorises in Microsoft, and what happens to the records it reads.

A reviewer's pack, not a brochure

The Due Diligence Pack reads like an assessment, because it is one. Scope and coverage, the certificate's exact limits, where data goes when something is flagged and where it does not when nothing is, laid out plainly enough to forward to a regulator.
certificate
X.509 name constraints
encryption
AES-256 at rest, TLS 1.2+ in transit
tenancy
Single tenant, one AWS account
subprocessor
AWS only

What the review will find

Three things every security team asks about, answered in the pack and summarised here.

01

Coverage

Interception at the OS network layer, opened only when the destination is positively identified as AI. Banking, sign-in, healthcare, and government domains are excluded outright, with matching X.509 Name Constraints in the certificate as defence in depth.

scope
AI destinations only
examples
claude.ai, chatgpt.com
certificate
X.509 name constraints
02

Data handling

Flagged events are held for a short review window, then purge. Unflagged traffic passes through, stored content-free. AWS is the only subprocessor in the supervision plane.

tenancy
Single tenant, one AWS account
keys
AWS KMS, held by the firm
archive
Exported to the firm’s own store
03

Security

Encrypted at rest and in transit, with a tamper-evident audit log across the fleet and managed browser policy closing the side channels.

at rest
AES-256
in transit
TLS 1.2+
record
Signed and hash-chained

What deployment actually involves

Proxara provisions the backend. IT uploads one signed installer to the MDM the firm already runs. The service deploys silently, with no prompts and no reboots, and starts protecting at boot.

1
tenant authorization for Connect
0
devices Connect touches
1
signed installer for the device agent
0
reboots, prompts, or desk visits

The device agent ships through Jamf, Intune, Kandji, or Mosyle, installs by hand where that is easier, and comes off cleanly whenever the firm decides.

Written for the wealth firm’s reviewer

The pack sets Proxara against the rules a wealth-management compliance team answers to, with the firm’s compliance archive as the system of record, not Proxara.

Reg S-P
Safeguarding client information
FINRA 3110
Supervision, where the firm is a FINRA member
Advisers Act 204-2
The books and records an adviser produces. Broker-dealer members reading this under 17a-4 get the same chain.
disclosure
An employee monitoring notice the firm can adapt
Read the full security overview