Security — Prysmic
Security and governance

Enterprise grade, by default.

It onboards like a new team member and it is governed like enterprise software. Read-only to start; you decide, task by task, what runs on its own.

SOC 2 Type II report issued 11 September 2026

A building, seen in structure
Certification

SOC 2 Type II, issued.

The SOC 2 Type II report was issued on 11 September 2026 by an independent auditor, covering security, availability and confidentiality. The system is independently penetration-tested against the live environment, with every finding remediated.

Report

SOC 2 Type II

Issued September 2026, clean, zero deviations. Available under NDA.

Testing

Penetration tested

Third party, against the live system, findings remediated.

Data

Operational only

Personal data excluded and stripped by default.

Isolation

Per tenant

Segregated schemas, scoped compute, least privilege.

Autonomy

Your rules decide what moves.

Autonomy is not a switch. It is a set of permissions, spending limits, service commitments and approval thresholds that your team sets, workflow by workflow.

Propose

It drafts, you decide

The finding, the evidence and the recommended action arrive together. Nothing happens until somebody says yes.

Approve once

Or approve always

Approve a single action, or approve that class of action for that workflow from now on.

Autonomous

Inside your limits

It runs on its own within the thresholds you set, and it shows up in the daily report either way.

Controls

Everything it did, and why.

  • Read-only OAuth tokens and secure APIs
  • TLS 1.2+ in transit, AES-256 at rest
  • Explicit retention controls and customer-triggered hard delete
  • Complete traceability on every agent action, exportable
  • The reasoning, the data, the decision and the outcome, kept
  • Every action validated against your own data before it runs

An agent that cannot explain itself is an agent you cannot put near a payment run. Every action Prysmic takes carries the trigger that started it, the data it read, the decision it made and the outcome it produced, in one record, in one click.

Get started

Talk to us about your controls.

We will walk your security team through the report, the data model and the approval architecture before anything connects.