Skip to content
Security Radar · Work in progress — published openly

Security at PMWISE.AI

Security is not a feature we bolted on — it is the first thing we designed. This page is our open, living register of what we do to stay secure. We publish it, gaps and all, because a promise you can examine is the only honest basis for trust. It is a work in progress and we will keep it current as we build.

Everything we do falls into one of two lanes — or, for the strongest controls, both. We keep one list across both so nothing falls between the cracks.

Protecting you

Your data is yours. We are built so we cannot read what we should not, cannot lose what we hold, and cannot let one client’s world touch another’s.

Protecting the platform

The service itself must not be the weak link — a problem in our systems must never become a problem for you.

Protecting you

Every document is private to your profile and isolated from every other client

Live

Files are stored in private storage — no public, guessable links; downloads use short-lived signed links

Live

Uploaded documents are scanned for malware and validated before they can be used or read by our AI

Live

Data is encrypted in transit and at rest

Live

Client-held encryption keys (BYOK) — so only you can unlock your document content

In design

A confidential-computing enclave (TEE) so even we cannot read your documents during analysis

In design

A tamper-evident log of every access to your content, visible to you

In design

One-click export of everything you have put in, to take elsewhere

Planned

Protecting the platform

Untrusted document content is treated as data, never instructions — it cannot hijack our AI

Live

Secrets and keys are server-side only and never reach your browser

Live

Database access is locked down and mediated only through our server

Live

An ethics layer governs every AI action

Live

Every code change is security-reviewed before it ships

In design

Automated dependency, secret and configuration scanning

In design

Sign-in with multi-factor authentication for team accounts

Planned

A written incident-response plan and responsible-disclosure programme

Planned

Continuous, not one-time

Being secure at launch means little; being still secure today is what counts. We are building automated checks that run continuously — confirming our controls still hold, and scanning for new kinds of threat to add to this list. In design

Certification when you need it

We build to 80%+ of what IRAP, the Essential Eight and SOC 2 require by design, and keep the evidence ready. We take the final certifying step — independent penetration testing and formal audit — when an enterprise or government client requires it. We are not certified yet, and we say so plainly.

Radical transparency

We show what is live, what we are building, and where the gaps are — because pretending gaps do not exist is itself a security risk. If you are a security researcher and you find a flaw, we want to hear from you.

Responsible disclosure contact: coming soon.

Legend:Live — built and in effectIn design — designed and committed, build to followPlanned — committed, not yet designed in detail

Questions about how we handle your data?

Enterprise buyer or curious individual — ask us anything. We’d rather you know before you sign up.

Ask about security