How we handle your data.
Plain answers, not buzzwords. Everything on this page describes how Presaga works today — not what we intend to do. If it isn't live, it isn't here. Where we can't claim something, we say so on the same page.
What you send us is locked before it is written down, so a stolen file or backup is unreadable. It is stored in Canada. You can delete any of it yourself, whenever you like. And where we can't promise something, this page says that instead of implying it.
Hosted and stored in Canada.
Your account, documents and reports are hosted and stored in Canada, encrypted at rest. On the standard service the AI model that processes your content runs outside Canada; if your rules require in-country processing end to end, we run PRISM for you on dedicated Canadian hardware as a private deployment.
The processors are named, not summarized.
Running a briefing means sending parts of your content to the AI infrastructure providers our engine uses. Those providers are named in our privacy policy, together with what leaves, what never leaves, and where it goes. We point you at that list rather than paraphrasing it here, because the list is the thing you should be able to check — and because a list restated in marketing copy is the first thing to go stale.
The same policy carries the commitment that matters most to the people who ask this question. In its own words: “Your document is not used to train or fine-tune AI models.”
The data you entrust to us.
To run a briefing we hold your account details (name, email, organization), the material you submit (the situation, message, or document you're testing), and what PRISM produces from it (reports, findings, and any report-chat history). The content you submit and everything derived from it is encrypted at rest — see below.
And what never touches our database.
We do not store your payment card details — card data is handled entirely by Stripe; we keep only a customer reference. Messages sent through our contact form are emailed to us, not saved to a database. And we do not sell customer data, ever.
What leaves our systems, and when
Research traffic: when a briefing needs a fact you didn't supply, PRISM sends short research terms (a place and a role — never your content) to a web-search provider, and reads the links you supply as an ordinary visitor would. Every outbound capability is controlled — each can be turned off, and the report says so when one is and can be disabled for a private deployment; our privacy policy states exactly what leaves and where it goes.
Encrypted at rest. Encrypted in transit.
Specifics, not adjectives.
Your content is encrypted before it's stored
The material you submit, the reports PRISM generates and everything derived from them, report-chat history, and uploaded files are encrypted with AES (via the Fernet standard) before they're written to the database or disk. Your two-factor secret is encrypted too; passwords are hashed with bcrypt.
Everything travels over TLS
All traffic to Presaga is served over HTTPS with HSTS enforced. The database runs on the same machine over a loopback connection — your content never crosses a network in the clear.
Backups are encrypted too
Database backups are AES-256 encrypted and access-restricted. A stolen backup is ciphertext.
Because your content is encrypted before it reaches the database or a backup, theft of our database or a backup alone cannot expose it. This is encryption at rest, not zero-knowledge encryption: running the service means our systems decrypt your content to process it, so we don't claim that even we can never see it. We'd rather state the boundary precisely than imply more than is true.
You decide how long we keep it.
We keep your content until you remove it
Your briefings, reports and uploads are retained until you delete them — we don't quietly age them out, and we don't repurpose them. They're there when you need them, and gone when you say so.
Delete a briefing, or your whole account
You can delete an individual briefing, a project, or your entire account from your settings. Account deletion is confirmed with your password — and your two-factor code if you have turned it on — then removes your content and uploaded files. Financial records are anonymized and retained only as required for accounting.
Your content isn't in our logs
Application logs record operational details — identifiers, timings, errors — not the content of your submissions or reports. Secrets are redacted before anything is written.
No badge we haven't earned.
You won't find a certification logo, an accessibility conformance statement, an uptime figure, or a breach-notification timeline on this page. We don't have those to hand you today, and a claim we can't support is worth less to your risk team than a precise no. If your procurement process needs one of those answers, ask us and we'll tell you exactly where we stand, in writing.
You don't have to take our word for it.
Presaga is not operated as a public open-source project. For enterprise customers, source-code review can be arranged as part of a security or procurement assessment — so your security team can verify exactly how your data is handled, rather than trusting a claim on a page. We prefer precise claims over broad ones.