A DLP tool mustn't become the leak

You'd be trusting Prism with the moments your people nearly share something they shouldn't. So we keep as little as we can, keep it in the UK and EU, and say exactly what that is. This page is written for your security review and your DPO.

Cyber Essentials Plus Certified

Stabilise Ltd, the company behind Prism, holds the UK government-backed certification, independently tested.

ISO 27001 Underway

We're working towards certification of our information security management system. We'll say so here when it's awarded.

ICO ZB938192 Registered

Registered with the UK Information Commissioner's Office as a data controller for our own processing.

The value never reaches our database

Detectors find secrets, card numbers, bank details, NHS and National Insurance numbers, dates of birth, email addresses and phone numbers, and Prism swaps each one for a typed placeholder before the event is stored, queued, logged or sent to your SIEM. Your team sees what kind of data went where, and who sent it. We never hold the value.

Pasted

deploy with STRIPE_KEY=sk_live_51Hx…9fQ and email ops@example.com

Stored

deploy with STRIPE_KEY=[STRIPE_KEY_1] and email [EMAIL_1]

What Prism collects, and what it doesn't

Collected, only when someone pastes, uploads or sends

  • What was pasted, uploaded or sent, at that moment, on the AI tools you choose. Text files' contents; other files only by name, type and size
  • The site and page address, without query strings
  • The person's work email, from your settings or their managed browser profile
  • Which kind of account is signed in on the AI tool: the email domain, never a personal address
  • How long each AI tool was in use each day, unless you turn that off
  • Any reason the person types when they continue after a warning

Never collected or kept

  • Keystrokes as people type, screen contents or browsing history
  • Anything on websites you haven't chosen, or before Prism is configured
  • The detected secrets and personal data themselves: they're replaced with placeholders before storage
  • Selling, advertising or training AI models on your data

The full detail is in the extension privacy policy. We give you a staff notice to send before rollout, because people should know what's checked.

Where it's kept, and who can see it

Isolated per organisation
Every query runs as your organisation, enforced by the database's row-level security, so one customer's data can't be read in another's console.
Encrypted
HTTPS/TLS in transit; encrypted at rest by our database provider. Credentials for your Slack, Teams or webhook destinations are encrypted again with our own key.
Your retention
You choose how long events are kept: 90 days by default. Ask us and we delete all of your organisation's data.
Your keys
Sensor keys can only send events; read keys only export them. Create, revoke and replace them in the console.
No AI model sees your data
Decisions are made by our detectors and your rules. If we add an AI model, it'll be listed here first, under zero-retention terms.

Subprocessors

ProviderForWhere
SupabaseDatabase and console sign-inLondon, UK
RailwayRuns the Prism serviceEU (Netherlands)
ResendSign-in emails and pilot requests (no event data)EU
VercelHosts this website (no customer data)Global CDN

Prism processes event data on your behalf; you are the controller.

Send us your security questionnaire

We'll answer it, and walk your security team or DPO through how Prism works before a pilot.