Trust

Your data is not ours

Runs in Prizmal's environment or yours. One key, one audit record, one kill switch. What follows is not a values statement; it is how the system is built, and each article is a contract term.

The doctrine

Five articles. Each one falsifiable. Referenced from the Terms and the Privacy Policy.

  • D-01
    Non-usage

    We do not train on your content. Not our models, not third parties' models. No exceptions, no toggles, no anonymized carve-outs, and we do not sell your data.

  • D-02
    Zero retention

    We do not store the content of your prompts, reasoning, or completions after a request is served. It is processed in transit to return your result and is not retained afterwards. Safety inspection happens in-flight and does not create a stored copy.

  • D-03
    Access

    We do not look. There is no stored content to look at, and any human access to customer data requires your authorization, is time-boxed, and is itself written to the audit record.

  • D-04
    Context

    Context never crosses tenants. Escalation hands off the minimum reasoning context required for that request. Caches are tenant-keyed; a token computed for you is never served to anyone else.

  • D-05
    Departure

    You leave with everything. Audit records and configuration export on demand; departure is a base-URL swap.

Chain of custody

Who holds it, for how long, under whose key.

C-01
Prompt
Holder:
Customer
Window:
Origin
Key:
Customer
C-02
PrizmalSwitch
Holder:
Prizmal, transit
Window:
TLS only, no persistence
Key:
Customer
C-03
Model class
Holder:
Open: our env or yours. Frontier: our provisioned access
Window:
In transit only
Key:
Customer
C-04
Completion
Holder:
Customer
Window:
Returned, not stored by us
Key:
Customer
C-05
Audit record
Holder:
Customer-readable, metadata only
Window:
Up to one year
Key:
Tenant-keyed

Prompt, reasoning, and completion content is never stored after a request is served. Operational metadata and Warden audit records are immutable, contain no prompt or completion content, and are kept up to one year, or longer where the law requires.

Product improvement

We improve the Service from how it runs, not from what you write.

What we use
  • Only operational metadata and telemetry, never the content of prompts, reasoning, or completions
  • On by default, opt out any time at privacy@prizmal.ai or in account settings, with no effect on your access
  • Where the law requires consent (EEA, UK, Quebec), we rely on consent and do not proceed without it
What we never use
  • The content of your prompts
  • Intermediate reasoning
  • Completions returned to you

The escalation clause

When the doubt gate routes a request to a frontier provider, the minimum reasoning context for that request crosses the boundary, under access Prizmal provisions and pays for, and is processed in transit only. Preserving your context across the open fleet is our job. Sharing it is not a feature we offer anyone, including ourselves.

Crosses
  • Minimum reasoning context for this request
  • Processed in transit, on our instructions, to return a result
  • Provider contracted against training on your content
Never crosses
  • Other tenants' context
  • Your prior requests beyond this one
  • Cache entries from any tenant

Isolation postures

Choose per workload, not per contract. Warden policy can pin a data class to a posture.

P-4
Shared
Multi-tenant cloud. Tenant-keyed encryption; isolation enforced at storage and cache layers.
P-3
Dedicated
Single-tenant cloud. Dedicated control plane and storage within the Prizmal environment.
P-2
Your VPC
Customer network. Prizmal control plane operates inside the customer VPC; data path stays in the customer account.
P-1
Sovereign
On-prem. Air-gappable. Customer jurisdiction. Both control plane and data path customer-owned.

Compliance posture

Status, not aspiration. A SOC 2 examination is in progress. Everything else below is mapped and aligned to, not certified.

SSO / SCIM
Identity federation, role provisioning, lifecycle automation. Shipped, via Warden.
SOC 2
Security, availability, and confidentiality controls. Examination in progress with an independent auditor. Not yet certified.
EU AI Act
Mapped and aligned to: risk tier mapping, transparency obligations, audit record retention. Not a certification.
ISO 27001 / 27701 / 42001
Mapped and aligned to information security, privacy information management, and AI management system controls. Not a certification.
GDPR / PIPEDA / Law 25
Mapped and aligned to. Data subject rights, breach notification, and lawful basis are handled as described in the Privacy Policy.
Subprocessors
We use third-party model and infrastructure providers to deliver the Service. A current list is available on request via privacy@prizmal.ai.
Availability
We target 99.9% availability of the routing layer per calendar month, excluding maintenance, provider outages, and events outside our control. A good-faith operational target, not a warranty, and not offered with service credits.
Local and Enterprise
Governed by the data terms of the applicable signed agreement, covering residency, retention, isolation, and subprocessors. Those terms control for the data they describe.
Access and verification
  • Least-privilege roles, scoped API keys, just-in-time elevation with expiry
  • Administrative actions written to the customer-readable audit record
  • Immutable audit export on demand; controls matrix on request
  • Independent penetration test: 2026 Q3 target

Coordinated disclosure to security@prizmal.ai. Acknowledgment within 48 hours. Safe harbor for good-faith research.

This page is maintained by Prizmal to answer common security and privacy questions. It describes current practices and enabled controls. It is not an independent certification. It sits alongside the Terms of Service and the Privacy Policy; accepting your account terms means accepting all three.

Proof over posture

The R/E Audit runs in shadow mode, read-only, reversible at every step. See the controls on your own traffic.