1. Encryption
Data is encrypted in transit using TLS and at rest using industry-standard algorithms. Secrets and connector credentials are stored encrypted and used only for the scheduled ingestion and queries you configure.
2. Access control
- Role-based access control (RBAC) at the workspace, category, and document level.
- Single sign-on via SAML and OIDC, plus Google social login.
- Multi-factor authentication (TOTP) with backup keys and brute-force lockout.
- Session control—view active devices and revoke access instantly.
3. Infrastructure and isolation
Each workspace is isolated with its own vector index, configuration, chat history, and access control list. Cross-workspace access requires explicit permissions. Data is processed only within the boundary you choose.
4. Audit logging and monitoring
Every query, tool call, and document access is recorded in tamper-evident audit logs capturing who did what, when, and against which data. Execution, tool, and API gateway logs give you full traceability, and traces can be exported to your observability stack via OpenTelemetry.
5. AI governance
- AI Policy Engine enforces what agents are permitted to do.
- AI Risk Engine scores each response for risk.
- Data-loss prevention (DLP) guardrails help prevent sensitive data from leaking.
- Your content is never used to train publicly available AI models.
6. Deployment options
Deploy the way your security posture requires. Available today: your own private cloud (AWS, Azure, GCP) or fully on-premise and air-gapped with local models—so your data never leaves your chosen boundary and we never access it. A fully managed, multi-tenant cloud is coming soon. Learn more on our deployment overview.
7. Compliance
We align our controls to recognized industry frameworks. SOC 2 Type II is in progress. For current certifications, questionnaires, or a copy of available reports, contact our team.
8. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please email security@promptly-ai.co with details so we can investigate. Please avoid accessing or modifying data that is not yours and give us reasonable time to remediate before public disclosure.
9. Contact
Security questions or documentation requests? Contact security@promptly-ai.co.