← Back to home
🛡 Trust Center

Certifications & Security Posture

Every certificate on this page is genuine and admin-published — nothing here is a placeholder badge. If a certification isn't listed, we don't hold it yet.

We built this page on the same principle we apply to the rest of the platform: a security claim is only published here once it's true and verifiable, not when it would be convenient to say so. That means this page will look sparse while a certification is in progress, and that's intentional — an inflated Trust Center is worse than an honest one.

📋

Certification program in progress

We're actively pursuing recognized security and privacy certifications. As certificates are issued, they'll be published here with the real issuer, certificate number, and validity dates — not before. In the meantime, see our real security practices below, or reach out with any compliance questionnaire (SIG/CAIQ) requests.

Security Practices (in every PRISM deployment today)
🔐

Password hashing

Credentials are hashed with bcrypt — never stored in plaintext or reversible form.

🔑

Multi-factor authentication

TOTP-based MFA is available and enforceable per tenant, with encrypted secret storage.

📜

Audit logging

Authentication and administrative actions are recorded to an append-only audit trail.

🧩

Role-based access

Admin console access is gated by role, with tenant isolation enforced at the query level.

🛰

Responsible disclosure

We run a published security.txt policy — security researchers have a real, monitored channel to report issues.

🔄

Session controls

Sessions expire automatically and can be revoked; stale sessions are cleaned up on a schedule.

🧬

Post-quantum cryptography

CRYSTALS-Kyber, the NIST-standardized post-quantum algorithm, is implemented and live in our cryptographic layer — not just on a roadmap.

🗝️

Encrypted secrets at rest

Stored credentials such as configured mail-provider passwords are encrypted with AES-256-GCM, not reversible plaintext, in the underlying database.

🎫

DPoP token binding

OAuth access tokens support DPoP (RFC 9449) proof-of-possession binding, so a stolen token alone isn't enough to replay a session elsewhere.

🚦

Rate limiting

Login and API endpoints are rate-limited to blunt credential-stuffing and brute-force attempts before they reach application logic.

🏢

Tenant isolation

Multi-tenant data is scoped at the query level, with an isolation test harness run against both SQLite and PostgreSQL backends.

🔒

Encryption in transit

All traffic to and within PRISM is served over HTTPS/TLS — there's no unencrypted path to any customer data.

How to get compliance documentation

If you're evaluating PRISM as part of a vendor security review, we can respond to a completed SIG (Standardized Information Gathering) or CAIQ (Consensus Assessments Initiative Questionnaire) questionnaire, and share our current certification roadmap and target dates under NDA where appropriate. Reach out via the link below and a real person on our security team will respond — not an automated ticket queue.

Questions about our security or compliance program? Talk to our team →