Security

Security is not a feature.
It's a foundation.

Pryvonis is a platform that handles sensitive personal data on behalf of its customers. Our security posture is non-negotiable — built in from day one, not added later.

SOC 2
In progress
GDPR Compliant
Operational
E2E Encryption
At rest & transit
Tenant Isolation
Strict boundaries
Audit Trail
Immutable log
Zero-trust
Architecture

Infrastructure Security

Pryvonis runs on hardened cloud infrastructure with defence-in-depth controls at every layer. Our infrastructure is designed to minimise attack surface and eliminate single points of failure.

  • Hosted on ISO 27001-certified cloud infrastructure
  • Network segmentation with private subnets for all data processing
  • Web Application Firewall (WAF) and DDoS protection
  • Automated vulnerability scanning and dependency auditing
  • Security patches applied within 24 hours of critical disclosures
  • All inter-service communication over mTLS

Data Isolation

Every customer's data is strictly isolated at the storage and application layer. Cross-tenant data leakage is architecturally impossible by design.

  • Tenant-level database isolation — no shared schemas
  • All API requests validated against tenant context
  • Data residency controls per jurisdiction
  • Encryption keys managed separately per tenant
  • Zero standing access to customer data for Pryvonis staff
  • Formal access review process for any emergency access

Encryption at Rest

All data stored on Pryvonis infrastructure is encrypted using AES-256. This includes database contents, file attachments, and backup stores.

  • AES-256-GCM for stored data
  • Encrypted backups with separate keys
  • Automatic key rotation on schedule

Encryption in Transit

All data in transit is protected with TLS 1.3. Weak cipher suites are disabled. HSTS is enforced on all endpoints.

  • TLS 1.3 minimum for all connections
  • HSTS with one-year max-age
  • Certificate transparency monitoring

Audit & Logging

Every action on the platform generates a tamper-evident log entry. Logs are immutable, timestamped, and available for export.

  • Immutable event log per tenant
  • Real-time anomaly detection
  • Log export for SIEM integration

Compliance Certifications

We are actively pursuing formal security certifications. Our control framework is aligned with SOC 2 Type II and ISO 27001 requirements from day one.

SOC 2 Type II
Audit scheduled
In progress
ISO 27001
Framework aligned
Planned
GDPR Article 32
Operational
Compliant
UK GDPR
Operational
Compliant
CCPA / CPRA
Operational
Compliant
Cyber Essentials
UK scheme
Planned

Security questions? Ask them.

We're happy to share our security documentation, answer technical questions, and discuss our compliance posture in detail. No NDA required for initial conversations.