In Brief
PromptHalo Technologies provides security testing and runtime protection for AI and agentic systems. Our security practices are designed for our current size, services and technology environment.
PromptHalo does not use customer content to train or fine-tune general-purpose models, its own or a provider’s, unless a customer expressly agrees in writing.
PromptHalo uses cookies to run its site and platform, not to advertise. It does not use cookies to build advertising profiles or to track visitors across other sites.
The published vulnerability disclosure policy explains how good-faith security research can be reported.
Governance
A documented policy library governs security and privacy. Each policy carries an owner, a version and a review date, is reviewed at least annually, and is updated when significant changes occur.
Security Foundation
Identity and Access
The Access Control Policy governs access, applying least-privilege practices appropriate to our AWS and agentic AI environment. Multi-factor authentication is required, access is reviewed on a defined cadence, and access is removed on separation.
Customer Isolation
Customer data is logically separated through application and access controls. The effectiveness of these controls across relevant data and processing activities is addressed through our privacy program.
Data Protection
The Encryption Policy requires protection of data in transit and at rest. The Data Classification Policy sets how information is classified and handled according to its sensitivity, and secrets are held in managed storage rather than in code or configuration.
We avoid using production personal data in development and testing. Any necessary exception requires documented approval and appropriate safeguards.
Secure Development
The platform runs on AWS. The Change Management Policy requires changes to be reviewed, tested and approved on risk before release, and the Secure Software Development Policy covers code review and automated security testing across the development lifecycle.
Agentic AI Security
PromptHalo applies the following controls based on the risk and purpose of the agentic workflow.
Agent Authorization
Agents are limited to permitted identities, resources, tools and actions. Users and services are authenticated before an agent acts for them, and each agent is scoped to a role, a tenant and a defined set of resources.
Tool and MCP Security
Every API, tool and MCP connection an agent reaches is authenticated, authorized and constrained to what the workflow requires.
Agent Guardrails
Agents receive defined instructions and a defined context rather than open-ended latitude. Controls constrain the data, tools and actions available, to reduce excessive agency, unintended actions and unauthorized tool use.
Agentic Behavioral Analysis
Intent and context are used to observe deviations in agent behavior and orchestration. Sensitive actions require approval, and agent activity is logged so an action can be attributed after the fact.
PromptHalo evaluates risks such as prompt injection, data leakage, authorization bypass and tool misuse as part of its security testing.
Security Operations
Vulnerability Management
The Vulnerability and Patch Management Policy sets how vulnerabilities are identified, prioritized and addressed on risk. The published Coordinated Vulnerability Disclosure Policy explains how researchers can report potential security issues.
Logging and Monitoring
The Logging and Monitoring Policy sets what is logged, including authentication and administrative actions on the platform and on agent activity. Security alerts are reviewed and investigated on risk.
Incident Response
The Incident Response Policy covers reporting, investigation, containment, recovery and communication. We notify affected customers as required by applicable law and contractual commitments.
Resilience
The Business Continuity and Disaster Recovery Policy sets backup, recovery and continuity practices appropriate to the service. Additional documentation is available under a non-disclosure agreement.
Data and Assurance
AI Data Use
Customer prompts, responses and uploaded content follow documented data-use practices.
PromptHalo does not use customer content to train or fine-tune general-purpose models, its own or a provider’s, unless a customer expressly agrees in writing.
When PromptHalo uses third-party AI services, we select appropriate business protections and configure available data-use controls.
PromptHalo does not rely solely on automated processing for decisions that produce legal or similarly significant effects about an individual.
The AI Statement sets out how AI is used and governed. The AI Governance Policy behind it is available under a non-disclosure agreement.
Third Parties
The Vendor Management Policy governs review of cloud, model and service providers that may affect customer data or service security. We maintain a list of relevant sub-processors and give notice as customer agreements require. The current list is available on request.
Privacy and Retention
PromptHalo does not sell personal data or use it for cross-context behavioral advertising. We share personal data with service providers only when needed to operate and protect our services, subject to appropriate agreements.
When PromptHalo processes customer data on a customer’s behalf, we follow the customer’s documented instructions and applicable agreements. We may use de-identified information to detect threats and improve security.
The Data Retention and Disposal Policy sets retention against business, legal and contractual needs. When a period ends we delete or anonymize the information using reasonable methods, and backup copies expire through their normal retention cycle.
Two documents carry the detail. The Privacy Notice sets out what we collect, why, who it is shared with, how long it is kept, and the rights available. The Cookie Policy covers cookies and how to control them.
Assurance
The security program is aligned to the SOC 2 Trust Services Criteria for Security. SOC 2 Privacy is not currently within the scope of our examination, and PromptHalo maintains independent privacy practices alongside measures designed to support applicable GDPR and HIPAA requirements.
Security and compliance statements on this page reflect assurance activities actually completed. We review them and update them when our practices materially change.
Shared Responsibility
PromptHalo is responsible for protecting the service and its supporting environment. Customers are responsible for how they configure users, agent permissions, integrations, credentials, data sources and approvals within the service.
Document Availability
The Trust Center holds the current list of published and NDA documents in one place. Public documents open directly. Documents classified Internal are released under a non-disclosure agreement on request.
Open the Documents and Policies panel on the Trust Center to read a published document or to submit a request. Requests can also be sent directly to security@prompthalo.ai.
Contact
Send security questions, document requests, vulnerability reports and privacy inquiries to security@prompthalo.ai. We review and respond to reports as promptly as practicable. This page is informational and does not replace contractual commitments or underlying policies.
PromptHalo Technologies, 6475 Preston Rd, Unit 140, Frisco, TX 75034, USA.