Security by architecture.
Privacy by design.
Trust isn't a marketing claim โ it's a technical commitment embedded in every layer of the Prava platform. Here's how we secure what we build.
Secure-by-design infrastructure.
Ephemeral Compute
GCP e2-standard-4 instances destroyed after each task. No cross-session data persistence. gVisor sandbox with strace syscall logging.
Encryption
AES-256 in transit and at rest. Cryptographic erasure on deletion. NIST SP 800-88 Clear/Purge/Destroy standards.
Network Isolation
VPC firewall with restricted egress. Non-root service accounts. Strace syscall logging. Zero-trust internal architecture.
Annual Pen Testing
Independent third-party security assessment conducted annually. Bug bounty program via responsible disclosure.
AI you can verify, trust, and govern.
Prava is built with AI governance at the core โ not as an afterthought.
Human Oversight
AI outputs require human review before any enforcement action. Source attribution mandatory on all AI reasoning chains.
ISO 42001 Aligned
AI governance framework aligned with ISO/IEC 42001 AI Management System. Documented AI risk management policies.
Hallucination Mitigation
GraphRAG knowledge graphs ground every AI output in verifiable sources. Confidence scoring on all security findings.
Compliant. Documented. Continuous.
Where we stand. Where we're going.
Working with the security community.
Prava is committed to working with security researchers and the broader security community to identify and fix vulnerabilities responsibly. We treat researchers as partners.
How to report
Email privacy@swiftsafe.com with subject prefix [SECURITY] or [PLACEHOLDER: security@prava.ai when established]. Provide reproduction steps, impact assessment, and any proof-of-concept artifacts.
Our commitment
- โ Acknowledgement within 24 hours
- โ Regular updates throughout investigation
- โ No legal action for good-faith research
- โ Public credit for researchers (with permission)
In scope
- โข prava.ai and all subdomains
- โข Prava platform functionality
- โข API endpoints
- โข Authentication flows
Out of scope
- โข Social engineering attacks
- โข Physical attacks
- โข Denial of service testing
- โข Issues in third-party services
Cookie Policy
We use the following categories of cookies:
- Strictly necessary: session authentication, security tokens, CSRF protection. Cannot be disabled.
- Analytics (with consent): anonymised platform usage analytics to improve the product. Opt-out anytime.
- No advertising cookies: we do not use third-party advertising cookies.