Praesidia Trust Center
One page for security reviewers, procurement, and compliance teams: what we attest to today, where customer data is processed, which controls the platform provides, how to verify our audit evidence independently, and who to contact.
What we do and do not attest to
Praesidia does not currently publish a SOC 2 report or an ISO/IEC 27001 certificate. We say this plainly so that your assessment starts from the right baseline.
What we do publish is a set of control mappings to the frameworks regulated teams are measured against — SOC 2, GDPR, EU AI Act, ISO/IEC 42001, NIST AI RMF, and the OWASP LLM Top 10. These mappings support your assessment and do not constitute certification. They describe which platform controls and which exportable evidence correspond to each requirement; the assessment, and any customer-side responsibilities, remain yours.
- Compliance hub — one control-mapping page per framework.
- Security & Compliance — the full control list and framework overview.
Where customer data is processed
Praesidia is built and operated by Squad Technology SRL, a company registered in Cluj-Napoca, Romania, and therefore operates under GDPR as an EU-incorporated company. Company registration details are on the About page.
The current live production host for Praesidia's public app, API, and MCP services is Render, behind Cloudflare; that is where customer data is processed today. AWS is not used for production compute and appears in our provider inventory only for platform integrations (key management, object storage, and message queuing) where those features are configured.
Other documented providers are Stripe (billing), Mailgun (transactional email), Sentry (error monitoring, when configured), Sigstore Rekor (public transparency-log anchoring, when external anchoring is enabled), and OpenAI (model inference only when an organization uses the platform-configured default instead of its own provider connection). Organizations can route model requests exclusively to their own provider connection.
The service provider inventory is a technical inventory: it does not assert provider regions, transfer mechanisms, change-notice periods, or negotiated legal roles. Data-residency options are discussed during evaluation; reviewed contractual information is available from legal@praesidia.ai.
Controls built into the platform
A condensed view. The full descriptions live on Security & Compliance.
Identity for every agent
Each agent authenticates with its own attributable, individually revocable credential — no shared service accounts. Revoking one agent contains the blast radius to that agent.
Tamper-evident audit trail
Every request, response, and policy decision is recorded in an append-only log. With cryptographic signing enabled, exported evidence becomes independently verifiable offline.
Tenant isolation
Strict multi-tenant isolation: every request is scoped to your organization, so one organization can never read another's data.
SSO & SCIM for the humans
SAML and OIDC single sign-on, automated user lifecycle with SCIM, MFA, and passkeys for the people who manage your agents.
Least-privilege access
Role-based access control and scoped API keys, so every human and integration gets exactly the access it needs and no more.
Content guardrails
Bidirectional inspection blocks prompt injection and stops sensitive data from leaving through an agent's output.
Signed, verified webhooks
Outbound events are signed so your systems can verify they genuinely came from Praesidia before acting on them.
Vaulted secrets & BYOK
Provider keys and agent credentials are vaulted — shown once, never exposed in logs. Regulated deployments get per-region bring-your-own-key custody for audit-record signing.
Verify our audit evidence without trusting us
For organizations with cryptographic audit signing enabled, every exported compliance bundle can be checked by your own team or your auditor with an Apache-2.0, dependency-free command-line verifier that runs fully offline and never calls our servers. It confirms every signature and tamper check, and — when external anchoring is enabled — the Sigstore Rekor transparency-log anchor, a public log we do not control. It also states plainly what it does not prove.
Terms, privacy, and data processing
Our terms of service, privacy policy, and data processing agreement are available on request. Email legal@praesidia.ai and tell us which documents you need and the organization you are evaluating on behalf of. Technical privacy questions go to privacy@praesidia.ai.
Found a vulnerability? Tell us
We welcome reproducible security reports. The security reporting guide explains what to include, which systems the channel covers, and how to keep testing safe for other customers. Machine-readable contact details are at /.well-known/security.txt.
Working through a vendor assessment?
Send security questionnaires and architecture questions to security@praesidia.ai. Include the framework or questionnaire format you are using, the deployment you are evaluating (plan, model providers, integrations), and any deadline on your side so the reply is useful the first time. For everything else, see the Contact page.
Govern AI with confidence
Get started for free. No credit card required.