It onboards like a new team member and it is governed like enterprise software. Read-only to start; you decide, task by task, what runs on its own.
SOC 2 Type II report issued 11 September 2026

The SOC 2 Type II report was issued on 11 September 2026 by an independent auditor, covering security, availability and confidentiality. The system is independently penetration-tested against the live environment, with every finding remediated.
Issued September 2026, clean, zero deviations. Available under NDA.
Third party, against the live system, findings remediated.
Personal data excluded and stripped by default.
Segregated schemas, scoped compute, least privilege.
Autonomy is not a switch. It is a set of permissions, spending limits, service commitments and approval thresholds that your team sets, workflow by workflow.
The finding, the evidence and the recommended action arrive together. Nothing happens until somebody says yes.
Approve a single action, or approve that class of action for that workflow from now on.
It runs on its own within the thresholds you set, and it shows up in the daily report either way.
An agent that cannot explain itself is an agent you cannot put near a payment run. Every action Prysmic takes carries the trigger that started it, the data it read, the decision it made and the outcome it produced, in one record, in one click.
We will walk your security team through the report, the data model and the approval architecture before anything connects.