Security at PMWISE.AI
Security is not a feature we bolted on — it is the first thing we designed. This page is our open, living register of what we do to stay secure. We publish it, gaps and all, because a promise you can examine is the only honest basis for trust. It is a work in progress and we will keep it current as we build.
Everything we do falls into one of two lanes — or, for the strongest controls, both. We keep one list across both so nothing falls between the cracks.
Your data is yours. We are built so we cannot read what we should not, cannot lose what we hold, and cannot let one client’s world touch another’s.
The service itself must not be the weak link — a problem in our systems must never become a problem for you.
Protecting you
Every document is private to your profile and isolated from every other client
LiveFiles are stored in private storage — no public, guessable links; downloads use short-lived signed links
LiveUploaded documents are scanned for malware and validated before they can be used or read by our AI
LiveData is encrypted in transit and at rest
LiveClient-held encryption keys (BYOK) — so only you can unlock your document content
In designA confidential-computing enclave (TEE) so even we cannot read your documents during analysis
In designA tamper-evident log of every access to your content, visible to you
In designOne-click export of everything you have put in, to take elsewhere
PlannedProtecting the platform
Untrusted document content is treated as data, never instructions — it cannot hijack our AI
LiveSecrets and keys are server-side only and never reach your browser
LiveDatabase access is locked down and mediated only through our server
LiveAn ethics layer governs every AI action
LiveEvery code change is security-reviewed before it ships
In designAutomated dependency, secret and configuration scanning
In designSign-in with multi-factor authentication for team accounts
PlannedA written incident-response plan and responsible-disclosure programme
PlannedContinuous, not one-time
Being secure at launch means little; being still secure today is what counts. We are building automated checks that run continuously — confirming our controls still hold, and scanning for new kinds of threat to add to this list. In design
Certification when you need it
We build to 80%+ of what IRAP, the Essential Eight and SOC 2 require by design, and keep the evidence ready. We take the final certifying step — independent penetration testing and formal audit — when an enterprise or government client requires it. We are not certified yet, and we say so plainly.
Radical transparency
We show what is live, what we are building, and where the gaps are — because pretending gaps do not exist is itself a security risk. If you are a security researcher and you find a flaw, we want to hear from you.
Responsible disclosure contact: coming soon.
Questions about how we handle your data?
Enterprise buyer or curious individual — ask us anything. We’d rather you know before you sign up.
Ask about security