Skip to content

Security, Audit Trail, and Compliance

Power Prompt embeds enterprise-grade security and regulatory compliance controls into its architectural foundation.


1. Cryptographic Protection and Data Encryption

Safeguarding proprietary prompt assets and API credentials relies on stringent cryptographic controls:

  • Encryption in Transit: All client, API, and extension traffic is encrypted using TLS 1.3 with forward-secret cipher suites.
  • Encryption at Rest: Prompt instruction text, metadata, version revisions, and model secrets are encrypted at rest in the database using industry-standard AES-256.
  • Key Management & Rotation: Master data encryption keys support scheduled rotation in alignment with corporate cybersecurity policies.

2. Comprehensive Security Audit Trail

To satisfy enterprise compliance and regulatory audit mandates, Power Prompt records an immutable log of system events:

  • Authentication Events: Timestamps of successful logins, failed attempts, MFA challenges, and session renewals.
  • Prompt Lifecycle Actions: Full provenance for prompt creation, editing, deletion, version rollback, and category moves.
  • Access Control Shifts: Records of role reassignments, permission changes, and team modifications.
  • Member Lifecycle: History of dispatched invitations, account activations, and member offboarding.
  • Data Ingestion & Exports: Logging of batch imports, telemetry exports, and report downloads.
  • Infrastructure Operations: Modification of system settings, API key provisioning, and model whitelist shifts.

Audit trail streams are tamper-evident and can be exported to enterprise SIEM platforms.


3. Regulatory Compliance

Power Prompt supports major international and European compliance standards:

  • General Data Protection Regulation (GDPR):
    • Built-in support for data subject rights (erasure, rectification, and portability).
    • Formal zero-retention and zero-training guarantees on prompt content.
    • EU sovereign hosting or dedicated On-Premise deployment within customer data centres.
  • SOC 2 Type II Alignment: Adherence to Trust Services Criteria regarding security, availability, and processing integrity.
  • Retention Policies: Configurable retention periods for historical versions and test execution logs.
  • Resilience and Backup: Automated snapshot schedules and verified disaster recovery playbooks.