— Trust Center

Built for the people who pay the bill.

Prompts are intellectual property. We treat them that way — encrypted, auditable, deletable on request, and never used to train anyone's model.

Compliance roadmap

SOC 2 Type II — in progress (Q3 target). GDPR & CCPA aligned. DPA available on request. HIPAA with BAA on the roadmap.

Encryption

TLS 1.3 in transit. AES-256 at rest. Tenant-isolated row-level security on every table. Secrets stored in a managed vault.

Access control

SSO/SAML & SCIM (via WorkOS), RBAC across owner / admin / editor / member / reviewer / viewer / billing. Optional MFA enforcement, session policies, and IP allowlists.

Audit & retention

Every prompt edit, run, share, role and policy change is logged with actor, IP, before/after diff — and exportable as CSV. Retention is configurable per data type.

Data residency

US default. EU (Frankfurt) on the roadmap. Bring-your-own-key (BYOK) for OpenAI, Anthropic, and Google supported.

No training, ever

Prompts and outputs are never used to train AI models — ours, our gateway's, or any provider's. Contractually enforced with sub-processors.

Sub-processors

VendorPurposeRegion
SupabaseDatabase, auth, storageUS / EU
CloudflareEdge runtime, DDoS, CDNGlobal
Lovable AI GatewayModel routingUS
ResendTransactional emailUS
StripeBillingUS / EU
Need our DPA, security questionnaire, or SOC 2 letter?

Email security@prompsy.app — we reply within one business day.