Security and control

Control sits with your administrators, not with individual users.

How PrimeThink separates groups, controls access, handles your data and your keys, and lets you choose where it runs. Described plainly.

Isolation and access

Every group is its own tenant

Group isolation

Members, roles, chats, documents, collections, settings and agents live inside a group. One group's data is never visible from another, and chat databases are scoped per group in storage.

Role-based permissions

Administrators assign roles. Each role decides who can view, create or edit apps, data sources and workflows, and gates features such as model use and direct tool calls.

Chat membership

Chat content and files require both authentication and membership in the chat.

Scoped tokens for apps

Live Apps authenticate to the platform with per-chat tokens and CSRF protection, never with a user's credentials.

Accounts

Sign-in that fits how your company works

SSO and SAML on Enterprise

Enterprise connects to your identity provider through Kinde, including Microsoft Entra ID, Okta and Google Workspace, with custom SAML for any other SAML 2.0 provider.

Strong password policy

At least 12 characters, strength-checked, with common and personal passwords rejected. A group can tighten the rules.

Lockout and verification

Repeated failed logins lock sign-in temporarily. Accounts must verify their email, and the login page is protected by reCAPTCHA.

Your data and your keys

Choose the models, and what reaches them

Messages and documents an assistant processes are sent to the model provider you configure. Administrators decide which providers and models are available, so that data flow is a choice you make.

Bring your own keys

Connect your own provider keys per provider, or route through AWS Bedrock with your own AWS credentials.

Allowed models and defaults

Choose which models are available and the default for each kind of work, for example restricting sensitive work to a specific model.

Variables you cannot read back

Store a credential once, mark it private, and it is masked everywhere. It can be used without ever being readable again.

Capabilities on or off

Switch capabilities on or off per workspace, so features you do not want are never available and never consume budget.

Data is encrypted in transit and at rest.

Where it runs

Your region, your choice

On the Enterprise plan, PrimeThink runs single-tenant in the AWS region you choose. Your data and your model calls stay where you put them.

  • AWS Bedrock. Run inference in your own AWS account. Claude and GPT-5.6 models run within the geography you choose, for example Europe or the US. Other Bedrock models run in the single region you configure.
  • A European model path. Mistral is a European provider, a natural choice where you want an all-European model route.
  • Mix by sensitivity. Different models for different kinds of work.

Which regions are available for deployment is agreed during scoping.

Common questions

Security questions we are asked

Do you hold SOC 2 or ISO 27001?

We make no certification claims on this site. Tell us what your security review needs and we will say plainly what we can share.

Is my data used to train models?

Content is sent to the model provider you configure to generate responses. What happens there is governed by your agreement with that provider, which is why you can bring your own keys.

Can we run it in our own AWS region?

Yes. Enterprise is single-tenant, deployed in the AWS region you choose.

Walk us through your security review.

Send us your questionnaire or talk to us about your requirements.

Contact us →

Or email hello@primethink.ai