Every certificate on this page is genuine and admin-published — nothing here is a placeholder badge. If a certification isn't listed, we don't hold it yet.
We built this page on the same principle we apply to the rest of the platform: a security claim is only published here once it's true and verifiable, not when it would be convenient to say so. That means this page will look sparse while a certification is in progress, and that's intentional — an inflated Trust Center is worse than an honest one.
We're actively pursuing recognized security and privacy certifications. As certificates are issued, they'll be published here with the real issuer, certificate number, and validity dates — not before. In the meantime, see our real security practices below, or reach out with any compliance questionnaire (SIG/CAIQ) requests.
Credentials are hashed with bcrypt — never stored in plaintext or reversible form.
TOTP-based MFA is available and enforceable per tenant, with encrypted secret storage.
Authentication and administrative actions are recorded to an append-only audit trail.
Admin console access is gated by role, with tenant isolation enforced at the query level.
We run a published security.txt policy — security researchers have a real, monitored channel to report issues.
Sessions expire automatically and can be revoked; stale sessions are cleaned up on a schedule.
CRYSTALS-Kyber, the NIST-standardized post-quantum algorithm, is implemented and live in our cryptographic layer — not just on a roadmap.
Stored credentials such as configured mail-provider passwords are encrypted with AES-256-GCM, not reversible plaintext, in the underlying database.
OAuth access tokens support DPoP (RFC 9449) proof-of-possession binding, so a stolen token alone isn't enough to replay a session elsewhere.
Login and API endpoints are rate-limited to blunt credential-stuffing and brute-force attempts before they reach application logic.
Multi-tenant data is scoped at the query level, with an isolation test harness run against both SQLite and PostgreSQL backends.
All traffic to and within PRISM is served over HTTPS/TLS — there's no unencrypted path to any customer data.
If you're evaluating PRISM as part of a vendor security review, we can respond to a completed SIG (Standardized Information Gathering) or CAIQ (Consensus Assessments Initiative Questionnaire) questionnaire, and share our current certification roadmap and target dates under NDA where appropriate. Reach out via the link below and a real person on our security team will respond — not an automated ticket queue.