At PromptFluent, security isn't an afterthought—it's foundational to how we build and operate our platform. Your prompt libraries represent your organization's intellectual approach to AI. We treat that responsibility seriously.
Last Updated: January 21, 2026
PromptFluent is actively pursuing SOC 2 Type II certification following the Trust Services Criteria for Security.
What This Means:
| Control Area | Status | Details |
|---|---|---|
| Access Controls | Implemented | Role-based access, MFA required, quarterly access reviews |
| Data Encryption | Implemented | AES-256 at rest, TLS 1.2+ in transit |
| Incident Response | Documented | Formal incident response plan with defined procedures |
| Vendor Management | Documented | Vendor assessment and monitoring procedures |
| Change Management | Implemented | Documented change procedures with approval workflows |
| Monitoring & Logging | Implemented | Security event logging with defined retention |
All customer data is encrypted using AES-256 encryption. This includes:
All data transmitted to and from PromptFluent is encrypted using TLS 1.2 or higher. We enforce HTTPS for all connections and implement HTTP Strict Transport Security (HSTS).
Each organization's data is logically isolated using row-level security policies. Your prompts and data are never accessible to other customers.
This is a core commitment:
Customer prompt libraries, usage data, and any content created or stored within the PromptFluent platform is never used to train machine learning models, improve AI algorithms, or for any purpose other than delivering the PromptFluent service to that specific customer.
This applies to:
You can export your prompt libraries at any time in standard formats (XLSX, JSON).
Upon account termination or request:
PromptFluent is hosted on enterprise-grade cloud infrastructure:
| Component | Provider | Certifications |
|---|---|---|
| Application Hosting | Vercel | SOC 2 Type II |
| Database | Supabase (AWS/GCP) | Runs on SOC 2 certified infrastructure |
| CDN/Edge | Vercel Edge Network | SOC 2 Type II |
We maintain a formal Incident Response Plan that includes:
If you discover a potential security vulnerability:
We maintain a formal vendor management program that includes:
| Vendor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting | US/EU (selectable) |
| Vercel | Application hosting | Global (US primary) |
| Stripe | Payment processing | US |
For enterprise customers and prospects, we can provide:
Contact: sales@promptfluent.com
This page reflects our security practices as of January 21, 2026. We continuously improve our security posture and update this page accordingly.