AI and agentic threats continue to evolve. PromptHalo continuously reviews vendors, vulnerabilities and emerging risks, and monitors agent behavior against defined permissions and intended use. This Trust Center is updated as our controls evolve.

Compliance ledger

Statuses reflect the current program state. Alignment to a framework is not certification. Evidence is available under NDA; see Document requests.

TRUST DETAIL
Security

Security practices

DISCLOSURE
Advisories

Security advisories & CVEs

Advisories affecting this product, plus our assessment of relevant third-party CVEs and external guidance. Ask the assistant about a specific CVE to have it check both this list and current public sources.

Ecosystem

Security incidents

Disclosure record

Coordinated disclosure record

Coordinated vulnerability disclosure

Responsible disclosureOpen to researchers

Good-faith security research is welcome. Reports are acknowledged within 2 business days, triaged and severity-scored, remediated on severity-based timelines (critical 7 days, high 30, medium 60, low 90), and disclosed in coordination with the reporter within 90 days by default. The full terms (scope, safe harbour, and what we commit to at each stage) are in the Coordinated Vulnerability Disclosure Policy.

Safe harbor. Research conducted in good faith and within this policy will not be met with legal action. Do not access, modify, or exfiltrate data beyond what is required to demonstrate the issue; stop and report immediately if personal data is encountered.

Report a vulnerability

Safe harbor applies

Submit a report below: it composes a structured email to the security team with a tracking reference, and nothing is transmitted from this page itself.

Opens your mail client with a tracking reference. Response within 2 business days.
No reports logged on this device yet.
DATA & OPERATIONS
Privacy

Data & privacy

CategoryHandling
Reliability

Availability & resilience

AreaCommitment
Third parties

Subprocessors

Vendors that may process data in delivering the service. Each is reviewed before onboarding and annually.

The current list, with purpose, region and safeguards, is released under a non-disclosure agreement. Customers are given notice before a new subprocessor begins processing their data, as their agreement requires.

Request the subprocessor list →

Evidence

Documents & Policies

Public documents open directly. Private policies and assurance materials are available under NDA on request. Requests generate a pre-filled email and are logged locally in your browser only.

Policies
Assurance
Opens your mail client. Nothing is transmitted from this page.
No requests logged on this device yet.
REFERENCE
Common questions

FAQ

Reach the trust desk

Contact

For active incidents affecting your data, use the security contact and include "INCIDENT" in the subject line.