PPrismaVerify
  • Features
  • Pricing
  • Security
  • Contractors
  • ROI
Sign inStart free trial
FeaturesPricingSecurityContractorsROI
Sign inStart free trial
PPrismaVerify
Refinery integrity, verified by AI.
API 510 · 570 · 653 · 581 · ASME

Product

  • Features
  • Pricing
  • Contractor Portal
  • ROI Calculator
  • AI Copilot

Company

  • About
  • Careers
  • Security
  • Contact

Resources

  • Documentation
  • API Standards Guide
  • Case Studies
  • Support
© 2026 PrismaVerify · API 510 · 570 · 653 · 581 · ASME
PrivacyTermsSecurityContact
Security documentation

Security Whitepaper

A complete description of how Prisma Verify isolates tenant data, protects it at rest and in transit, keeps inspection records verifiable, and governs AI so that no automated system signs off on a safety decision. Written for the security reviewers and IT architects who evaluate the platform before deployment.

Prisma Verify Security Whitepaper
PDF · 6 pages · Version 1.0, August 2026
Download PDF

What's inside

01
Purpose and scope
What the platform protects and who this document is for.
02
Deployment models
Managed cloud, self-hosted, and fully air-gapped operation.
03
Tenant isolation
Row-level security enforced by the database under a non-privileged role.
04
Identity and access control
SSO over OIDC and SAML, multi-factor authentication, capability-based RBAC.
05
Encryption and key management
AES-256-GCM for stored secrets, encrypted local database, supported key rotation.
06
Auditability and evidence integrity
Hash-chained audit records and verifiable evidence packages.
07
AI governance
Human sign-off on every verdict, cited sources, tenant-scoped retrieval, local inference.
08
Application and platform security
CSRF and SSRF protection, injection resistance, safe error handling.
09
Secure development lifecycle
CodeQL, Semgrep, Trivy, Gitleaks, SBOM, signed artefacts, enforced regression gate.
10
Data protection and privacy
Erasure workflow, residency, portability, and retention.
11
Compliance posture
A plain statement of what is implemented and what is not yet attested.
12
Vulnerability disclosure
How to report a suspected vulnerability.

Need something this document does not cover — a security questionnaire, an architecture review, or deployment specifics for your environment? Contact the security team.