Trust & security
Security at Prem
Private superintelligence you own. Your data and models never leave your control, safe because no one else can touch them.
Robust privacy
Your data is never utilized for training or refining AI models. We don’t perform user profiling.
Industry standards
Aligned with leading data-privacy and security regulations and best practices.
Sovereignty
Designed in Lugano, powered in Switzerland and Europe.
Transparency
Request policies in our Trust Center (NDA signing may be required), and clear legal terms you can read before you agree with.
Our Security Model
Sovereignty is the security model
Most AI security defends someone else’s cloud while your data sits inside it. Ours starts a level earlier, making the intelligence yours in the first place. What you own, no one else has to be trusted with.
Private
Your data serves only you. Used to answer you, and nothing else. Never mined, monetized, or fed to another model. You decide what's kept, for how long, and when it's gone.
Verifiable
Proof over promises. Every claim backed by something you can check: cryptographic proof, open-source code, and published audits your security team can review.
Compounding
The more you use the sovereign agents, the more they learn how your organization works and improve themselves. Turning AI from a tool you rent into owned, appreciating IP.
Your data is yours across its entire lifecycle
You decide what's stored and when it's deleted. Choose our Enclave APIs and nothing is retained at all: we cannot produce what we do not hold.
Built in the Open
Security that hides its workings isn't security
Prem is an applied research lab before it’s a vendor. Sovereignty only counts if the community can inspect it, so we publish the research, open the code, and put our trust posture where anyone can read it.
Open-source foundations
We publish our research, experiments and tools on GitHub. Access our open-weight models on HuggingFace.
Public transparency
A public trust center, comprehensive documentation, and downloadable whitepapers. When something changes in how we operate, the record is there.
Honest about limits
No system is beyond question. We document our threat model and its boundaries openly, what we protect against, what we can’t, and what we’re doing about it.
Protecting what you own
Defense in depth around your intelligence
Ownership is the model, engineering is the enforcement.
Encryption
At rest and in transit with industry recognized ciphersets.

Post-quantum ready
Sovereignty has to outlast today’s cryptography. Hybrid post-quantum encryption defeats “harvest now, decrypt later”, sealed for decades, not quarters.

Keys under control
Keys and secrets live in managed stores with a rotation schedule, never hardcoded.

Protected in use
For our Confidential Compute offerings, data stays protected even while it's processed.

Compliance
Sovereign in three jurisdictions
We don't wait for annual audits. Vanta continuously assesses our compliance posture in real time, and every action across our systems is monitored, logged, and auditable.
EU AI Act


EU
AI ACT
Assessed
Formal risk classification under Regulation (EU) 2024/1689, reviewed annually and on material change.
HIPAA


HIPAA
Soon
Business Associate Agreements and a healthcare compliance framework for clinical deployments.
SOC 2


SOC 2
type I
Type I attained · Type II underway
Independent audit of security controls.
ISO 9001


ISO
9001
Soon
Quality management aligned to the international standard.
GDPR


GDPR
Operational
DPAs, records of processing, impact assessments, data subject rights, and a designated EU representative.
Swiss FADP


FADP
Operational
Processing records, impact assessments, data subject rights.
ISO 27001


ISO
27001
Soon
Information security management aligned to the international standard.
Security practices
Architecture protects the data. Operations protect everything else.
Ownership guarantees mean little if the organization around them is sloppy. A documented, audited program covers the people, code, and vendors that architecture alone can't.
Penetration testing
We engage independent security specialists to perform external penetration tests at least annually and after major changes.
Secure development
A formal SDLC governs code review, dependency hygiene, and release gates, with documented change management, approvals, and rollback for anything touching production. Our pipelines involve automated assessment tools during development cycles.
Access control
Least privilege and legitimate business need, enforced with strong authentication measures. Periodic review is performed on a recurrent schedule to validate that access to critical systems is up to date with roles and responsibilities.
People
All staff complete security training at onboarding and annually, with additional role-specific awareness programs.
Vendors and continuity
Vendors are risk-rated, with audit evidence (under ISO 27001 or SOC 2 Type II) required where risk warrants it. A maintained continuity and disaster recovery plan keeps an incident from becoming an outage.
Privacy
Your intelligence compounds for you, not for us
Most AI economics run on your data. Ours don’t. What your organization feeds its AI builds your capability and your IP; none of it flows back to Prem or anyone else. Where a product stores data to do its job, like your Fluso workspace, it’s kept only for you; our Enclave APIs store nothing at all.
Never used for training
Residency you choose
Retention under your control
Documented access, rectification, erasure, and portability under GDPR and the FADP, with defined timelines. Stored data follows a maintained retention schedule; each product's terms spell it out.
A minimal circle
Responsible disclosure
Security is a community effort
Sovereign AI gets stronger when researchers probe it. Found a vulnerability, weakness, or incident? Tell us first, what you found, when, the affected systems, and any indicators of compromise. We triage every report, and good-faith research in line with responsible disclosure never meets legal action from Prem.
Contact
Security & disclosure: security@premai.io


Own your intelligence
Bring your security and compliance teams, we like the hard questions. Start your review in the Trust Center, or talk to us directly.


