A DLP tool mustn't become the leak
You'd be trusting Prism with the moments your people nearly share something they shouldn't. So we keep as little as we can, keep it in the UK and EU, and say exactly what that is. This page is written for your security review and your DPO.
Cyber Essentials Plus Certified
Stabilise Ltd, the company behind Prism, holds the UK government-backed certification, independently tested.
ISO 27001 Underway
We're working towards certification of our information security management system. We'll say so here when it's awarded.
ICO ZB938192 Registered
Registered with the UK Information Commissioner's Office as a data controller for our own processing.
The value never reaches our database
Detectors find secrets, card numbers, bank details, NHS and National Insurance numbers, dates of birth, email addresses and phone numbers, and Prism swaps each one for a typed placeholder before the event is stored, queued, logged or sent to your SIEM. Your team sees what kind of data went where, and who sent it. We never hold the value.
Pasted
deploy with STRIPE_KEY=sk_live_51Hx…9fQ and email ops@example.com
Stored
deploy with STRIPE_KEY=[STRIPE_KEY_1] and email [EMAIL_1]
What Prism collects, and what it doesn't
Collected, only when someone pastes, uploads or sends
- What was pasted, uploaded or sent, at that moment, on the AI tools you choose. Text files' contents; other files only by name, type and size
- The site and page address, without query strings
- The person's work email, from your settings or their managed browser profile
- Which kind of account is signed in on the AI tool: the email domain, never a personal address
- How long each AI tool was in use each day, unless you turn that off
- Any reason the person types when they continue after a warning
Never collected or kept
- Keystrokes as people type, screen contents or browsing history
- Anything on websites you haven't chosen, or before Prism is configured
- The detected secrets and personal data themselves: they're replaced with placeholders before storage
- Selling, advertising or training AI models on your data
The full detail is in the extension privacy policy. We give you a staff notice to send before rollout, because people should know what's checked.
Where it's kept, and who can see it
- Isolated per organisation
- Every query runs as your organisation, enforced by the database's row-level security, so one customer's data can't be read in another's console.
- Encrypted
- HTTPS/TLS in transit; encrypted at rest by our database provider. Credentials for your Slack, Teams or webhook destinations are encrypted again with our own key.
- Your retention
- You choose how long events are kept: 90 days by default. Ask us and we delete all of your organisation's data.
- Your keys
- Sensor keys can only send events; read keys only export them. Create, revoke and replace them in the console.
- No AI model sees your data
- Decisions are made by our detectors and your rules. If we add an AI model, it'll be listed here first, under zero-retention terms.
Subprocessors
| Provider | For | Where |
|---|---|---|
| Supabase | Database and console sign-in | London, UK |
| Railway | Runs the Prism service | EU (Netherlands) |
| Resend | Sign-in emails and pilot requests (no event data) | EU |
| Vercel | Hosts this website (no customer data) | Global CDN |
Prism processes event data on your behalf; you are the controller.
Send us your security questionnaire
We'll answer it, and walk your security team or DPO through how Prism works before a pilot.