Security & data practices

Product trust begins with clear data boundaries.

Pristone Intelligence is offered through scoped engagements. Access, data movement, retention, deletion, export, and operational responsibility are confirmed before production use.

Current product controls

These statements describe controls present in the current product and commercial policy. They are not a claim of regulatory certification.

Authenticated product access

Private product workspaces require authenticated access rather than relying on hidden URLs.

Tenant-scoped requests

Product data requests are evaluated in the context of the authenticated organization and user.

Role and module permissions

Workspace capabilities are limited by assigned roles and enabled product modules.

Fresh operational reads

Private intelligence APIs use non-cached responses where current operational state matters.

Client data ownership

Clients retain ownership of the data they provide. Reusable Pristone software remains Pristone property.

No training by default

Pristone does not use identifiable client data for model training unless a separate, explicit agreement permits it.

Data minimization

Pristone defines the operational decision first, then requests only the fields needed to support that decision. Lower-sensitivity derived records are preferred when raw content is unnecessary.

Before production

  • • Approved systems, fields, users, roles, and permitted purposes
  • • Deployment model, encryption responsibilities, and credential management
  • • Retention, deletion, client export, backup, and restoration requirements
  • • Monitoring, support, incident communication, and recovery responsibilities
  • • Human review, prohibited uses, and escalation paths

Need a deployment-specific security review?

Pristone will document the applicable data path and safeguards as part of pilot scoping.

Book a Decision Audit