praesensus
Trust Center · Updated 2026-08-01

Trust Center.

Security posture. Compliance status. Sub-processors. Data handling. The full picture. Documents referenced as NDA-required are provided upon written request via security@praesensus.com.

The three invariants

Every claim in this Trust Center reinforces three architectural invariants. Break any one, and we break the brand.

Invariant 1

Insight-only

Praesensus observes, reasons, and advises. It never actuates on legal matters. Permanent, not a phase.

Invariant 2

Fail-closed governance

Default-deny. Every advisory carries an approval-tier requirement, a reason code, and a HALT path.

Invariant 3

Federate patterns, not privileged content

Raw privileged material never leaves the firm. Enforced architecturally, not by policy.

Compliance status

FrameworkStatusNotes
SOC 2 Type IAttainedReport available under NDA.
SOC 2 Type IIAudit in progressAttestation expected Q[X] [Year].
ISO 27001Planned Y3Path evaluated; scoping in progress.
GDPRDPA + SCCs availableStandard Contractual Clauses (Module 2) attached.
UK GDPRDPA + IDTA availableInternational Data Transfer Addendum attached.
CCPA / CPRADPA availableService provider language incorporated.
HIPAABAA availableBusiness Associate Agreement for healthcare-vertical customers.
PIPEDA (Canada)CompliantDPA incorporates PIPEDA obligations.
FedRAMP ModeratePath Y4Channel-dependent; evaluated based on demand.

Security posture

Encryption

  • At rest: AES-256-GCM for all Customer Data + Federation aggregations.
  • In transit: TLS 1.3 for all data in transit. mTLS for the Federation channel.
  • Key management: per-tenant keys via cloud KMS. HSM-backed for highest-value modules.

Identity + access

  • SAML 2.0, OIDC, SCIM 2.0, LDAP supported for Customer identity providers.
  • MFA required for all administrative access.
  • Role-based access control (RBAC) with least-privilege enforcement.
  • Quarterly access reviews for administrative access.

Monitoring + detection

  • 24/7 monitoring via centralized SIEM.
  • Endpoint EDR on all corporate devices.
  • Runtime container security (Falco); image signing (Sigstore/Cosign).

Business continuity + disaster recovery

RTO (P0 systems)
4 hours (Cloud Tenant).
RPO (P0 systems)
15 minutes (continuous replication).
Redundancy
Multi-region cloud deployment with automated failover.
DR testing
Full annual drill + quarterly restore verification.

Incident response

Documented plan
Yes; reviewed quarterly; tested quarterly.
Customer Data breach notification
72 hours from confirmation.
External IR panel
Firm on retainer (Mandiant / CrowdStrike Services).

Federation architecture

Praesensus's Federation is the anonymized pattern-intelligence network that enables cross-firm benchmarks and standard-form defect detection. The Federation is what makes Praesensus a network product, not a point tool. And it operates without ever accessing your privileged content.

Federate patterns, not privileged content. The Federation processes only derived typed structure and outcome patterns. Prohibited content types (privileged text, client identifiers, matter identifiers, attorney communications) are excluded architecturally, not by policy.

Differential privacy

Standard configuration
ε=1.0, δ=10−6, k-anonymity floor 25.
Enhanced configuration
ε=0.5, δ=10−8, k-anonymity floor 50.
Certification
Independent third-party certification of DP implementation, updated annually.

Authentication (automated pull)

Two-factor machine authentication: (1) mTLS client certificate rotated every 90 days; (2) hardware-backed signed request token (HSM, YubiKey PIV, or equivalent). Optional human Custodian Seal Renewal.

Sub-processors

Praesensus maintains a live list of Sub-Processors below. Customer is notified 30 days before any material change.

Sub-ProcessorPurposeLocation
Amazon Web Services (AWS)Cloud hosting — Cloud TenantCustomer-selected region
Microsoft AzureCloud hosting (optional)Customer-selected region
Google Cloud PlatformCloud hosting (optional)Customer-selected region
StripePayment processing (PCI DSS Level 1)US
DocuSignContract signatureUS
PagerDutyIncident notification routingUS
DatadogApplication performance monitoringCustomer-selected region
Vanta / DrataCompliance automationUS

Documents available under NDA

  • Latest SOC 2 Type I report (Type II when available)
  • Latest penetration test executive summary
  • CAIQ v4.0 pre-filled response workbook
  • SIG Lite + SIG Core pre-filled response workbook
  • HIPAA Security Rule assessment
  • Incident Response Plan (redacted for operational security)
  • Business Continuity + Disaster Recovery Plan (redacted)
  • Software Bill of Materials (CycloneDX)
  • Certificate of Insurance (COI) naming Customer as additional insured

To request: security@praesensus.com with a mutual NDA executed. Turnaround: 3 business days for standard documents.

Security disclosure

We welcome coordinated security research. If you believe you have identified a vulnerability, please email security@praesensus.com. We commit to acknowledging reports within 2 business days and to providing status updates every 7 days until resolution.

Safe harbor: Security research conducted in good faith is authorized under our published policy. We will not initiate legal action against researchers acting under this policy.

Contact

Security disclosures
security@praesensus.com
Privacy inquiries
privacy@praesensus.com
Compliance + audit
compliance@praesensus.com
General inquiries
hello@praesensus.com