Deployment

Three ways to run PRISM. Pick the one your rules require.

Two questions decide this, and they are not the same question: where your files sit, and where the AI model that reads them runs. On the standard service the answers are Canada and outside Canada. If both have to be Canada, we run PRISM for you on dedicated Canadian hardware. If the work must never leave your building, we install it there.

Hosted and stored in Canada on the standard service Encrypted at rest, encrypted in transit Source review for enterprise procurement
In plain terms

What people call data sovereignty is really two separate questions: where your documents live, and where the computer that reads them is. We answer both, for each of the three ways you can run PRISM, and we don't blur them together to make the answer sound better.

The three tiers

Standard, private, or inside your own walls.

Described plainly, with what is true of each. Only the first one is something you can start on your own.

Tier one · Available today

The standard service.

An account on presaga.ca. Nothing to install, nothing to procure, nothing to schedule. This is what almost everyone uses, and it's the tier every page on this site describes.

  • What it isA Presaga account. You sign in, describe the situation, and read the briefing.
  • Your dataHosted and stored in Canada, on infrastructure we control. Your content is encrypted before it's written to the database or to disk, and backups are encrypted too.
  • The modelRuns outside Canada. Your account, documents and reports stay in Canada; the AI model that processes your content is not in Canada on this tier. We'd rather say so than let you assume otherwise.
  • Who it's forOrganizations whose requirements are about where information is held and who can reach it — most companies, and many public bodies.
  • How to get itCreate an account. Current plans and prices are in the app.
Tier two · Scoped with you

A private deployment on Canadian hardware.

The same PRISM, run for you on dedicated hardware in Canada, separate from the standard service. This is the tier that answers “the processing has to happen in the country, not just the storage.”

  • What it isA dedicated, isolated Presaga environment we operate for you on Canadian hardware. Outbound capabilities such as web research can be turned off; when one is off, the report says so rather than guessing.
  • Your dataIn Canada, on hardware dedicated to your organization and to nobody else.
  • The modelRuns in Canada. In-country processing end to end — the reason this tier exists.
  • Who it's forRules, contracts or ministries that require processing to stay in the country, not only storage.
  • How to get itA scoped engagement — we build it with you. There's no price list; tell us what your rules require and we'll tell you what it takes. Talk to us →
Tier three · Scoped with you

Inside your own building.

PRISM installed on hardware you own, on your own network, run by your people. For work that must never leave your walls — and for teams whose answer to “where does it go” has to be “nowhere.”

  • What it isA self-hosted installation on your infrastructure, planned with your infrastructure and security teams.
  • Your dataWherever you put it. It never reaches us.
  • The modelOn your hardware, under your control. Every outbound capability is governed and can be turned off — including installations with no outbound connection at all.
  • Who it's forClassified, regulated, or simply too sensitive to leave the premises under any arrangement.
  • How to get itA scoped engagement, sized to your environment rather than to a plan. Talk to us →
What you won't find on this page.

No uptime figure, no service-level table, no compliance badge, and no price for tiers two and three. We don't have the first three, and a marketing page is not the place to invent them. What we can do is describe exactly how the system handles your data, put your security team in front of the source, and answer specifics in writing.

True on every tier

The parts that don't change when the walls do.

Specifics, not adjectives. The full detail is on the security page.

Encrypted at rest

The material you submit, the reports PRISM produces, report-chat history and uploaded files are encrypted with AES (via the Fernet standard) before they're written to the database or to disk. Backups are AES-256 encrypted. Passwords are hashed; your two-factor secret is encrypted too.

Encrypted in transit

All traffic runs over HTTPS with HSTS enforced. On our infrastructure the database sits on the same machine over a loopback connection, so your content never crosses a network in the clear.

Your content isn't in our logs

Application logs record operational detail — identifiers, timings, errors — not the content of your submissions or your reports. Secrets are redacted before anything is written.

You decide how long we keep it

Delete a briefing, a project, or your entire account from your settings. Account deletion is confirmed with your password — and your two-factor code if you have turned it on — then removes your content and uploaded files. Financial records are anonymized and kept only as accounting requires.

Security review

You don't have to take our word for it.

Presaga isn't operated as a public open-source project. For enterprise and public-sector procurement, source-code review can be arranged as part of a security assessment — so the people who have to sign off can read how your data is handled rather than trust a claim on a page.

Bring the clause, the questionnaire or the audit you have to satisfy. We'd rather answer specifics than wave a badge, and we'll tell you plainly where the answer is no.

Request a source review →

Wax seal and document
The branded portal

Your reports, on your own subdomain.

Every account includes a branded portal at a subdomain you choose — yourorganization.presaga.ca — carrying your logo, your title and your own description. It's where clients, council or colleagues read the work without an account on the main app.

  • ✓ New projects are private by default; you grant access person by person
  • ✓ Or publish a project so anyone with the link can read it
  • ✓ Portal users sign in with their own credentials and never see your admin controls
  • ✓ Hand a project to a portal user with the run setup pinned — they supply the input, your balance covers it

How consultants use it →

A briefing published on a branded client portal
Who to talk to

Tell us what your rules require. We'll tell you which tier meets them.

The clause, the audit, the ministry, the client's security team — whatever is driving the question. If the standard service already meets it, we'll say so rather than sell you a deployment you don't need. For tiers two and three there's no price list: the scope is the price.

Say where your data has to live. We'll work from there.

Start on the standard service today — hosted and stored in Canada, encrypted at rest — and move to a private or self-hosted deployment when your rules require in-country processing end to end.

Talk to us → How we handle your data