Trust Center.
Security posture. Compliance status. Sub-processors. Data handling. The full picture. Documents referenced as NDA-required are provided upon written request via security@praesensus.com.
The three invariants
Every claim in this Trust Center reinforces three architectural invariants. Break any one, and we break the brand.
Insight-only
Fail-closed governance
Federate patterns, not privileged content
Compliance status
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type I | Attained | Report available under NDA. |
| SOC 2 Type II | Audit in progress | Attestation expected Q[X] [Year]. |
| ISO 27001 | Planned Y3 | Path evaluated; scoping in progress. |
| GDPR | DPA + SCCs available | Standard Contractual Clauses (Module 2) attached. |
| UK GDPR | DPA + IDTA available | International Data Transfer Addendum attached. |
| CCPA / CPRA | DPA available | Service provider language incorporated. |
| HIPAA | BAA available | Business Associate Agreement for healthcare-vertical customers. |
| PIPEDA (Canada) | Compliant | DPA incorporates PIPEDA obligations. |
| FedRAMP Moderate | Path Y4 | Channel-dependent; evaluated based on demand. |
Security posture
Encryption
- At rest: AES-256-GCM for all Customer Data + Federation aggregations.
- In transit: TLS 1.3 for all data in transit. mTLS for the Federation channel.
- Key management: per-tenant keys via cloud KMS. HSM-backed for highest-value modules.
Identity + access
- SAML 2.0, OIDC, SCIM 2.0, LDAP supported for Customer identity providers.
- MFA required for all administrative access.
- Role-based access control (RBAC) with least-privilege enforcement.
- Quarterly access reviews for administrative access.
Monitoring + detection
- 24/7 monitoring via centralized SIEM.
- Endpoint EDR on all corporate devices.
- Runtime container security (Falco); image signing (Sigstore/Cosign).
Business continuity + disaster recovery
- RTO (P0 systems)
- 4 hours (Cloud Tenant).
- RPO (P0 systems)
- 15 minutes (continuous replication).
- Redundancy
- Multi-region cloud deployment with automated failover.
- DR testing
- Full annual drill + quarterly restore verification.
Incident response
- Documented plan
- Yes; reviewed quarterly; tested quarterly.
- Customer Data breach notification
- 72 hours from confirmation.
- External IR panel
- Firm on retainer (Mandiant / CrowdStrike Services).
Federation architecture
Praesensus's Federation is the anonymized pattern-intelligence network that enables cross-firm benchmarks and standard-form defect detection. The Federation is what makes Praesensus a network product, not a point tool. And it operates without ever accessing your privileged content.
Federate patterns, not privileged content. The Federation processes only derived typed structure and outcome patterns. Prohibited content types (privileged text, client identifiers, matter identifiers, attorney communications) are excluded architecturally, not by policy.
Differential privacy
- Standard configuration
- ε=1.0, δ=10−6, k-anonymity floor 25.
- Enhanced configuration
- ε=0.5, δ=10−8, k-anonymity floor 50.
- Certification
- Independent third-party certification of DP implementation, updated annually.
Authentication (automated pull)
Two-factor machine authentication: (1) mTLS client certificate rotated every 90 days; (2) hardware-backed signed request token (HSM, YubiKey PIV, or equivalent). Optional human Custodian Seal Renewal.
Sub-processors
Praesensus maintains a live list of Sub-Processors below. Customer is notified 30 days before any material change.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting — Cloud Tenant | Customer-selected region |
| Microsoft Azure | Cloud hosting (optional) | Customer-selected region |
| Google Cloud Platform | Cloud hosting (optional) | Customer-selected region |
| Stripe | Payment processing (PCI DSS Level 1) | US |
| DocuSign | Contract signature | US |
| PagerDuty | Incident notification routing | US |
| Datadog | Application performance monitoring | Customer-selected region |
| Vanta / Drata | Compliance automation | US |
Documents available under NDA
- Latest SOC 2 Type I report (Type II when available)
- Latest penetration test executive summary
- CAIQ v4.0 pre-filled response workbook
- SIG Lite + SIG Core pre-filled response workbook
- HIPAA Security Rule assessment
- Incident Response Plan (redacted for operational security)
- Business Continuity + Disaster Recovery Plan (redacted)
- Software Bill of Materials (CycloneDX)
- Certificate of Insurance (COI) naming Customer as additional insured
To request: security@praesensus.com with a mutual NDA executed. Turnaround: 3 business days for standard documents.
Security disclosure
We welcome coordinated security research. If you believe you have identified a vulnerability, please email security@praesensus.com. We commit to acknowledging reports within 2 business days and to providing status updates every 7 days until resolution.
Safe harbor: Security research conducted in good faith is authorized under our published policy. We will not initiate legal action against researchers acting under this policy.
Contact
- Security disclosures
- security@praesensus.com
- Privacy inquiries
- privacy@praesensus.com
- Compliance + audit
- compliance@praesensus.com
- General inquiries
- hello@praesensus.com