Security
PRISM is built for engineering teams who handle sensitive AI infrastructure. Every layer of the stack is designed with security as a first-class constraint.
AES-256
Encryption at rest
TLS 1.3
In-transit security
4hr
Critical incident SLA
0
Data retained on simulation
Principles
From zero data retention to encrypted storage, every design decision prioritizes the security of your pipeline configurations and simulation results.
PRISM simulates pipeline behavior using synthetic traffic models. No actual user data, prompts, or API responses are stored during simulation runs. Results are ephemeral by default — persisted only when you explicitly export.
Simulations do not make real calls to OpenAI, Anthropic, or any third-party model provider. PRISM uses Monte Carlo behavioral models calibrated against empirical public benchmarks to project latency, token usage, and cost.
All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Pipeline definitions, simulation configurations, and exported reports are encrypted before storage.
We are actively pursuing SOC 2 Type II compliance. Our infrastructure runs on AWS with VPC isolation, and we conduct quarterly penetration testing with third-party security firms.
Practices
Infrastructure
Application
Organizational
Compliance
Penetration testing (Q1 2026)
AES-256 encryption at rest
TLS 1.3 in transit
SOC 2 Type II audit
ISO 27001 certification
HIPAA compliance module
Disclosure
If you discover a security vulnerability in PRISM, please report it responsibly. We commit to acknowledging reports within 24 hours and resolving critical issues within 72 hours.
security@getprism.devAcknowledgement of report
Initial assessment and severity classification
Resolution for critical vulnerabilities
Fix deployed for high-severity issues