Security at PMWISE.AI
Security is not a feature we bolted on — it is the first thing we designed. This page is our open, living register of what we do to stay secure. We publish it, gaps and all, because a promise you can examine is the only honest basis for trust. It is a work in progress and we will keep it current as we build.
Everything we do falls into one of two lanes — or, for the strongest controls, both. We keep one list across both so nothing falls between the cracks.
Your data is yours. We are built so we cannot read what we should not, cannot lose what we hold, and cannot let one client’s world touch another’s.
The service itself must not be the weak link — a problem in our systems must never become a problem for you.
Protecting you
Each client’s information is walled off from every other client’s — enforced by the database itself, not just by our code
LiveYou decide who sees each project: people you invite can read for free, and only people you choose can change anything
LiveSensitive documents are visible only to the people you trust with them, project by project
ReadyFiles are stored privately — no public or guessable links; downloads use short-lived signed links
LiveUploads are checked before our AI will read them: file type verified from the contents, executables and known test malware refused
LiveA full antivirus engine on every upload
ReadyData is encrypted in transit and at rest
LiveA permanent record of every change to who can access what
LiveExport your plans and reports to take elsewhere — and you keep that even if you stop paying
LiveClient-held encryption keys (BYOK) — so only you can unlock your document content
In designA confidential-computing enclave (TEE) so even we cannot read your documents during analysis
In designA log of every access to your content, visible to you
In designProtecting the platform
Untrusted document content is treated as data, never instructions — it cannot hijack our AI
LiveSecrets and keys are server-side only and never reach your browser
LiveEvery read and write is checked by the database against who you are — the master key is kept for a short, audited list of jobs
LiveAn ethics layer governs every AI action
LivePayments handled entirely by Stripe — your card details never touch PMWISE
ReadyEvery code change is security-reviewed before it ships
In designAutomated checks on the software we depend on
LiveSecret and configuration scanning
In designA written incident-response plan and responsible-disclosure programme
PlannedMulti-factor sign-in — a password signs you in and a reset comes only by emailed link; we chose simplicity here and will revisit it for enterprise clients
Not plannedContinuous, not one-time
Being secure at launch means little; being still secure today is what counts. We are building automated checks that run continuously — confirming our controls still hold, and scanning for new kinds of threat to add to this list. In design
Certification when you need it
We build to 80%+ of what IRAP, the Essential Eight and SOC 2 require by design, and keep the evidence ready. We take the final certifying step — independent penetration testing and formal audit — when an enterprise or government client requires it. We are not certified yet, and we say so plainly.
Radical transparency
We show what is live, what we are building, and where the gaps are — because pretending gaps do not exist is itself a security risk. If you are a security researcher and you find a flaw, we want to hear from you.
Responsible disclosure contact: security@pmwise.ai
Questions about how we handle your data?
Enterprise buyer or curious individual — ask us anything. We’d rather you know before you sign up.
Ask about security