Security

Your data is safe
with us. Always.

Enterprise-grade security built into every layer of PrabhaXAi — from encryption at rest to continuous penetration testing.

🛡️
SOC 2 Type II
Audited annually
🔒
ISO 27001
Certified
🇪🇺
GDPR
Fully compliant
🏥
HIPAA Ready
On Enterprise plan
🔐
256-bit AES
Encryption at rest

Security at every layer

We apply defence-in-depth across infrastructure, application, and organisational controls.

🔐

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys are rotated quarterly and managed via AWS KMS.

🏗️

Infrastructure

Hosted on AWS with multi-region redundancy, private VPCs, and WAF rules. No direct database access from the public internet.

🔍

Penetration Testing

Annual third-party penetration tests and continuous automated vulnerability scanning using industry-leading tools.

👤

Access Controls

Role-based access control (RBAC), SSO via SAML 2.0, enforced MFA, and full session audit logs for all admin actions.

📋

Compliance

SOC 2 Type II, ISO 27001, and GDPR compliance. Our data processing agreements (DPAs) are available on request.

🚨

Incident Response

24/7 security monitoring with a documented incident response plan. Affected customers are notified within 72 hours of any breach.

What we do, specifically

Data isolated per workspace

Each customer's data lives in logically separated stores. No cross-tenant data leakage is possible by design.

Automated daily backups

Backups run every 24 hours with 30-day retention and point-in-time recovery for the last 7 days.

Employee background checks

All Anthropic employees with any system access undergo background verification before being granted credentials.

Dependency scanning

Every pull request is scanned for known vulnerabilities in third-party libraries using Snyk and GitHub Advanced Security.

Bug bounty program

We partner with HackerOne to run a private bug bounty program. Responsible disclosures are rewarded and acknowledged publicly.

Uptime SLA

We guarantee 99.9% uptime on all paid plans, with real-time status at status.prabhaxai.com and historical incident logs.

Found a vulnerability?

We take security reports seriously. Please report any issues through our responsible disclosure programme and we'll respond within 48 hours.

Report a Vulnerability →