Security isn't a feature — it's the floor.
PrysmOS touches the data your business runs on, so we treat access like it's ours to lose. Here's what the floor actually looks like — no badge clipart, no vibes.
What every workspace gets
These aren't enterprise-tier upsells. They're how the product is built.
Org-scoped multi-tenancy
Every row, query, and object is scoped to your organization at the data layer — not filtered by convention. Cross-org access isn't a permission you can misconfigure; it isn't in the model.
Encrypted credentials at rest
Connector credentials — Postgres passwords, OAuth tokens, API secrets — are stored encrypted and decrypted only at the connector layer, only when a sync you configured runs.
CSRF same-origin checks
Every mutating request passes same-origin and CSRF validation, so another site can't ride your session into changing your data.
Role-based access control
Owner, admin, member, and viewer roles out of the box, plus custom roles when you need finer lines. Default is least privilege, not owner-of-everything.
Scoped API keys
Public endpoints sit behind API keys with their own scopes, per-key rate limits, and IP allow/deny rules. A leaked read-only key can read — nothing more.
Audit log on every mutation
Every change — human, script, or Juno — lands in an append-only audit log with actor, timestamp, and diff. Export it anytime.
Secrets never reach the AI
Juno works inside your permission boundary, but credentials are never placed in prompts or model context — they're injected at the connector layer after the model has spoken.
Approval-gated AI actions
Juno can draft anything but executes nothing destructive without a human approval — shown with blast radius up front, logged after the fact.
Compliance, honestly stated
We're working toward SOC 2 Type II. Until the report lands we'll share our architecture notes, subprocessors, and security packet on request — and we won't claim a badge we don't hold.
Found a vulnerability?
Tell us before you tell anyone else. Report to security@prysmhq.co — a human reads every report, we acknowledge within one business day, and we'll never threaten a good-faith researcher.
Want the full security packet?
Architecture notes, data-flow overview, and our SOC 2 status — send us a note and we'll share what we have, not what marketing wishes we had.