Security is not a feature checkbox — it is the architecture.
You ask us for evidence for your ISMS. That is why we show how PRISM itself is built.
- Zero-trust architecture: JWT, PKCE and role/claims validation on every request — no "trusted zones"
- Tenant separation at database level (schema-per-tenant) — complete data separation between customers
- Hosting in Germany: server and AI processing exclusively in Germany
- On-premise option: independent operation on own infrastructure possible
- MFA via authenticator app (TOTP)
- Tamper-proof change history — every change to controls, policies and actions logged immutably
- Six standard roles (Admin, Manager, Editor, Auditor, Compliance Officer, Viewer), configurable
- External portal: targeted sharing of content without full PRISM access for auditors or partners
Memberships & Location
-
-
-
Health Cybersecurity Advisory Board
-
- Software · KI · Hosting — Made in Germany
Responsible Disclosure
Please report security vulnerabilities to hello@secaas.it. Details on our data processing can be found in the privacy policy.
Ask us about our architecture directly.
In the initial consultation we also address your security questionnaires.