Control sits with your administrators, not with individual users.
How PrimeThink separates groups, controls access, handles your data and your keys, and lets you choose where it runs. Described plainly.
Every group is its own tenant
Group isolation
Members, roles, chats, documents, collections, settings and agents live inside a group. One group's data is never visible from another, and chat databases are scoped per group in storage.
Role-based permissions
Administrators assign roles. Each role decides who can view, create or edit apps, data sources and workflows, and gates features such as model use and direct tool calls.
Chat membership
Chat content and files require both authentication and membership in the chat.
Scoped tokens for apps
Live Apps authenticate to the platform with per-chat tokens and CSRF protection, never with a user's credentials.
Sign-in that fits how your company works
SSO and SAML on Enterprise
Enterprise connects to your identity provider through Kinde, including Microsoft Entra ID, Okta and Google Workspace, with custom SAML for any other SAML 2.0 provider.
Strong password policy
At least 12 characters, strength-checked, with common and personal passwords rejected. A group can tighten the rules.
Lockout and verification
Repeated failed logins lock sign-in temporarily. Accounts must verify their email, and the login page is protected by reCAPTCHA.
Choose the models, and what reaches them
Messages and documents an assistant processes are sent to the model provider you configure. Administrators decide which providers and models are available, so that data flow is a choice you make.
Bring your own keys
Connect your own provider keys per provider, or route through AWS Bedrock with your own AWS credentials.
Allowed models and defaults
Choose which models are available and the default for each kind of work, for example restricting sensitive work to a specific model.
Variables you cannot read back
Store a credential once, mark it private, and it is masked everywhere. It can be used without ever being readable again.
Capabilities on or off
Switch capabilities on or off per workspace, so features you do not want are never available and never consume budget.
Data is encrypted in transit and at rest.
Your region, your choice
On the Enterprise plan, PrimeThink runs single-tenant in the AWS region you choose. Your data and your model calls stay where you put them.
- AWS Bedrock. Run inference in your own AWS account. Claude and GPT-5.6 models run within the geography you choose, for example Europe or the US. Other Bedrock models run in the single region you configure.
- A European model path. Mistral is a European provider, a natural choice where you want an all-European model route.
- Mix by sensitivity. Different models for different kinds of work.
Which regions are available for deployment is agreed during scoping.
Security questions we are asked
Do you hold SOC 2 or ISO 27001?
We make no certification claims on this site. Tell us what your security review needs and we will say plainly what we can share.
Is my data used to train models?
Content is sent to the model provider you configure to generate responses. What happens there is governed by your agreement with that provider, which is why you can bring your own keys.
Can we run it in our own AWS region?
Yes. Enterprise is single-tenant, deployed in the AWS region you choose.
Walk us through your security review.
Send us your questionnaire or talk to us about your requirements.
Contact us →Or email hello@primethink.ai