Privent AI

Privent AI

Trust Center

Privent is an enterprise security platform for agentic AI.

It sits inside your agent pipelines, understands what your agents are doing in real time, and ensures sensitive data never reaches external AI providers.

Controls

Comprehensive overview of the security control frameworks we run — grouped by category so you can jump straight to the domain you care about.

Control Environment

  • Security awareness training implemented

    Employees are required to complete security awareness training within 30 days of being hired and at least once a year thereafter.

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Board oversight briefings conducted

    Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.

Communication and Information

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Data integrity maintained

    The company has implemented policies and procedures to safeguard electronic Protected Health Information (ePHI) against unauthorized alteration or destruction.

  • Third-party agreements established

    The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.

Risk Assessment

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

Monitoring Activities

  • Critical system review performed quarterly

    For service providers, the company performs reviews at least quarterly to confirm personnel comply with security policies and operational procedures.

  • Board oversight briefings conducted

    Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.

Control Activities

  • Development lifecycle established

    The company has a formal systems development life cycle (SDLC) methodology that governs the development, acquisition, implementation, maintenance, and changes (including emergency changes) of information systems and related technology requirements.

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

Logical and Physical Access Controls

  • Data transmission encrypted

    The company uses secure transmission protocols to encrypt confidential and sensitive data when it is transmitted over public networks.

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • Password policy enforced

    The company requires passwords for in-scope system components to be configured in accordance with its policy.

  • Data encryption utilized

    The company encrypts datastores containing sensitive customer data at rest.

  • Security patches installed within one month

    The company installs critical security patches within one month of their release, as determined by the risk ranking process defined in VPM-4.

  • Securely dispose of data

    The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.

  • Access reviews conducted

    The company performs access reviews at least quarterly for in-scope system components to ensure access is appropriately restricted. Required changes are tracked to completion.

  • Remote access encrypted enforced

    The company restricts remote access to production systems to authorized employees using an approved encrypted connection.

  • Data center access reviewed

    The company reviews data center access at least once a year.

  • Malicious software protection implemented

    The company has implemented procedures to guard against, detect, and report malicious software.

System Operations

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Vulnerability and system monitoring procedures established

    The company’s formal policies define requirements for the following IT and engineering functions: 1. Vulnerability management 2. System monitoring

  • Security vulnerabilities identification process exists

    The company maintains a process for identifying security vulnerabilities that includes: 1. Using reputable external sources to obtain current vulnerability information 2. Assigning risk rankings to identified vulnerabilities, clearly highlighting all high-risk and critical issues Risk rankings follow industry best practices and consider factors such as CVSS base scores, vendor classifications, and the affected system types. The risk assessment strategy ensures that all high-risk vulnerabilities are identified and that critical vulnerabilities, including those impacting public-facing systems, security infrastructure, or systems processing cardholder data, are addressed promptly.

  • Incident management procedures followed

    The company’s security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management in accordance with its security incident response policy and procedures.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

Change Management

  • Production deployment access restricted

    The company restricts production change migrations to authorized personnel only.

  • Development lifecycle established

    The company has a formal systems development life cycle (SDLC) methodology that governs the development, acquisition, implementation, maintenance, and changes (including emergency changes) of information systems and related technology requirements.

Risk Mitigation

  • Vendor management program established

    The company has a vendor management program in place that includes: 1. Critical third-party vendor inventory 2. Vendor security and privacy requirements 3. Review of critical third-party vendors at least annually

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Third-party agreements established

    The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.

Additional Criteria for Availability

  • Critical system review performed quarterly

    For service providers, the company performs reviews at least quarterly to confirm personnel comply with security policies and operational procedures.

  • Production data backups conducted

    The company performs periodic backups of production data, storing the backups in a separate location from the production environment.

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Production multi-availability zones established

    The company employs a multi-location strategy for production environments to enable operations to resume at alternate data centers if a facility becomes unavailable.

  • Database replication utilized

    The company’s databases are replicated in real time to a secondary data center, with alerts set up to notify administrators of any replication failures.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Environmental monitoring devices implemented

    The company uses environmental monitoring devices configured to automatically alert management in the event of environmental incidents.

Additional Criteria for Confidentiality

  • Data encryption utilized

    The company encrypts datastores containing sensitive customer data at rest.

  • Securely dispose of data

    The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.

Additional Criteria for Processing integrity

  • Production data backups conducted

    The company performs periodic backups of production data, storing the backups in a separate location from the production environment.

  • Establish and maintain a data management process

    The organization establishes and maintains a documented data management process that addresses, at a minimum: 1. Data sensitivity 2. Data owner 3. Data handling 4. Data retention limits 5. Data disposal requirements The organization aligns these elements with enterprise sensitivity and retention standards and reviews and updates the documentation annually or upon significant changes that could impact this control.

  • Data integrity maintained

    The company has implemented policies and procedures to safeguard electronic Protected Health Information (ePHI) against unauthorized alteration or destruction.

  • Processing data inputs validated

    The company’s system evaluates data inputs for compliance with input requirements and generates on-screen alerts when issues with transaction inputs or processing are detected.

  • Customer data retained

    The company retains customer transaction data for the duration of the customer account. Historical transaction data is not purged until the account is deleted.