Trust Center

A security company you can audit

We ask customers to trust us with their most sensitive data flows. That request comes with paperwork, architecture, and a disclosure policy attached.

How the platform is built

  • Tenant isolation at every layer, with per-tenant encryption keys and no cross-tenant data paths.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256) everywhere; customer-managed keys on dedicated plans.
  • Private data plane option: content is scanned inside your boundary and only metadata reaches the control plane.
  • Least-privilege connectors: every scope a connector requests is documented on its coverage page.
  • Full audit logging of administrator and policy actions, exportable to your SIEM.

Certifications & attestations

SOC 2 Type II
PrismSek platform: security, availability, confidentiality
Report available under NDA
ISO 27001
Information security management system
Certificate available on request

Security & legal documents

GDPR Data Processing Addendum
Processor terms, SCCs, and subprocessor list
Standard DPA available for review
HIPAA Business Associate Agreement
PHI handling terms for covered-entity customers
BAA available for healthcare deployments
Penetration Test Summary
Annual third-party assessment of platform and agents
Latest summary available under NDA
Security Architecture Overview
Data flows, encryption, tenancy isolation, and key management
Available for review

Published policies

Data Retention & Deletion Policy
Customer data lifecycle across control and data planes
Published
Responsible Disclosure Policy
Vulnerability reporting terms and safe-harbor commitment
Published

Responsible disclosure

Found a vulnerability? Report it to security@prismsek.com. We commit to acknowledgment within 48 hours, a safe harbor for good-faith research, and credit where you want it.

Need documents for a security review?

Request the SOC 2 report, pen-test summary, or DPA and we will get them to your team under NDA.