Content-minimised records
Routine evidence records the policy, decision and delivery result without retaining prompt or response text.
Google analytics are off.
Security, privacy and assurance
Promptective protects AI workflows across browsers, desktop apps and agents. Content is checked before provider delivery, and routine records exclude prompt and response text.
Trust Centre / Library
Start with the public records below, then request deployment-specific evidence for your organisation's security review.
How Promptective applies policy, handles failures and produces content-minimised evidence.
Policy authority, failure behaviour and the evidence recorded for supported decisions.
How supported content moves through the enforcement boundary before provider delivery.
A review of the controls, data paths and evidence relevant to your intended deployment.
Public policies governing personal information, website use and product services.
The authoritative record of the personal information the website and product actually process: what is collected, how it is used and shared, how long it is kept, and the rights available to you.
The current terms governing access to and use of Promptective services.
Current product boundaries, data-handling rules and published coverage information.
How data moves
Promptective checks supported content before provider delivery and keeps prompt and response text out of routine records.
AI interactions across browsers, desktop apps and custom agents.
Check content, apply organisation policy and continue only when the decision allows.
Approved content continues to the AI service selected by the organisation.
The dashboard records the decision, policy version, protection status and delivery result. Routine records exclude prompt and response text.
[2]Managed analysis is used only when selected and remains inside the declared boundary. Content stays out of routine records. Coverage is stated separately for each browser, desktop app and custom agent integration.
Decision outcomes
Promptective records the decision, the rule used and whether content was delivered.
Permit the supported interaction under the active policy.
Record content-minimised decision evidence for review.
Remove a detected value before permitted delivery.
Hold the interaction for an authorised decision.
Stop delivery when the active policy requires it.
Privacy / Data handling
Prompt and response plaintext stays out of routine remote evidence. Your deployment defines where content can be processed and which records can be retained.
Where it can exist
Transiently in the declared enforcement boundary, including managed analysis when selected, and in permitted provider transit when policy allows.Where it is excluded
Routine telemetry, event history, dashboards, product logs, and generic operating-system notifications.Where it can exist
Only in trusted endpoint memory and local detail UI, for a limited time when needed to explain a decision.Where it is excluded
Remote queues, control APIs, dashboards, logs, caches, and generic notifications.Where it can exist
Secure endpoint queues and the control plane, database, and dashboard as decision and delivery facts only.Where it is excluded
Their routine schemas cannot carry prompt or response content, local excerpts, credentials, or arbitrary attributes.Where it can exist
Endpoint or browser-profile storage, where they authenticate the installation or profile.Where it is excluded
Private key material stays on the endpoint. Shared data is limited to the verification material and signed proofs needed for trust.Integrity / Trust controls
Every security decision is bound to explicit authority, a policy version, and defined failure behaviour. Your team receives evidence it can review.
Routine evidence records the policy, decision and delivery result without retaining prompt or response text.
Organisation policy defines how supported sensitive content and AI destinations are handled.
Audit may fail open only by policy. Critical data-loss and destructive actions fail closed or require approval on supported paths.
Assurance / Evidence
We verify each supported surface against its declared protection boundary before publishing a coverage claim.
Independent reports and certifications are published only when they are complete and verifiable. Our security team will walk you through the evidence relevant to your review.
We state exactly where protection is active. A control is not described as protecting an AI interaction until we have verified that it can inspect and enforce that interaction.
Security review
Share your AI tools and security requirements. We will map the data flow, controls, evidence and supported boundaries your team needs to review next steps with confidence.