Security
Your data stays inside your organisation.
Most AI tools become useful only once your data and keys move into their cloud. Prism works the other way round.
How custody works
A typical AI tool
Your data and keys move into someone else's cloud to be useful.
Prism
Everything stays inside. Only the prompt goes out, under your own AI account.
- Runs on your machinesThe app, the agents and the products you install through it.
- Your AI accountsPrism never holds the credential.
- Keys in the OS keychainWith guards that block key material from being sent out.
- Governed data accessRead-only, granted per agent, every access logged.
Our hosted services
What we run for you is sealed off too.
Some Prism products run on our own servers so that anyone can open them in a browser, such as Prism Microclimate and the sign-in pages. Each public service is locked down the same way.
- A sandbox for each serviceEvery public service runs in its own sandbox, with only its own files and its own secrets. The rest of the server is hidden from it.
- No route to administrator rightsNo public service can gain administrator rights on the server.
- No reaching other servicesEach service can connect only to the few things it needs. It cannot reach the databases or services of any other product on the server.
- Checked from the insideEach of these was tested from inside the running service, not assumed from its settings.
Most services also run under an account of their own. One, whose analyses use the founder's own AI subscriptions, runs under the founder's account, inside the same sandbox. Prism Map Studio has no server part at all: files you add are read inside your browser and are not sent to us.
"We can't send this data to a vendor" is where enterprise AI projects stall. Here, it never has to go.
For the formal policy, see the security statement and the privacy policy.