Security
Built for financial services security requirements
Pramaana processes confidential audit documents for regulated institutions. Our security architecture reflects that responsibility at every layer: data classification, access control, encryption, and independent verification.
Security Controls
How we protect your documents
Four independent control planes, each designed for the threat model of a financial services SaaS platform handling confidential third-party documents.
Data isolation
Each customer's documents and trace records are stored in logically isolated environments. No customer can access another's data, and Pramaana staff access to customer data requires explicit, time-limited authorization with full audit trail.
Access control
Role-based access at the document, project, and organization level. Reviewer roles cannot ingest new documents or export evidence packages without explicit grant. Enterprise plans include SSO via SAML 2.0 and SCIM-based provisioning.
Encryption
Documents are encrypted at rest with AES-256 using customer-specific keys. All data in transit uses TLS 1.3. The document content and trace graph are stored separately and require two separate authorization checks to assemble.
Immutable audit log
Every document ingest, trace query, citation confirmation, and evidence export is logged with user identity, IP address, timestamp, and object ID. Logs are append-only, signed, and cannot be modified retroactively by any user including administrators.
Data Flow
Where your documents go
A numbered account of the path each document takes from upload to trace, and what controls apply at each stage.
Encrypted upload
Documents are uploaded over TLS 1.3 to a customer-isolated S3-compatible bucket in AWS us-east-1. At rest, each file is encrypted with AES-256 using a per-customer KMS key. No document is stored unencrypted at any point.
In-boundary parsing
Document parsing runs inside the customer's isolated processing tenant. No document content leaves the processing boundary for third-party parsing. OCR for scanned PDFs uses an on-premises model deployed in the same isolated environment.
Citation graph storage
The trace engine stores a citation graph, not the document content itself. Graph nodes reference encrypted content by pointer. The content and the graph are stored in separate services with independent access tokens. Both are required to reconstruct a citation.
Export and delivery
Evidence packages are assembled on demand, signed with a Pramaana-issued certificate, and delivered via secure pre-signed URL that expires in 24 hours. The URL is single-use and tied to the requesting user's session. Packages are not stored in an accessible location after delivery.
Retention and deletion
Documents and trace records are retained for seven years by default. Customers can initiate deletion at any time; deletion cascades to the citation graph, processed content, and audit log entries within 30 days. Enterprise plans support custom retention schedules aligned with your records management policy.
Our Position
What we will never do with your documents
We will never use your documents or trace results to train or fine-tune any machine learning model, including Pramaana's own.
We will never disclose document content to other customers, third-party analytics providers, or advertising platforms.
We will never allow Pramaana employees to read document content without an explicit, customer-approved support ticket and a corresponding audit log entry.
We will never retroactively alter a completed trace record. All modifications create a new dated revision; the original remains intact in the audit log.
Need our security brief or DPA?
We provide a detailed security brief covering our architecture, controls, and third-party dependencies. Enterprise DPA available for institutions with specific contractual requirements.