Security & Deployment

Security and control by design.

PRATIMUS is built on the assumption that security information is among the most sensitive data an organisation holds. Its architecture follows Zero Trust principles: never trust, always verify.

Zero Trust Architecture

Never trust. Always verify.

No user, device, service or AI component is trusted by default. Each access request is verified against identity, role and context, and granted only to the extent required. These principles protect organisational assets, sensitive information and AI-driven operations alike.

Identity-based security

Available

Every request is tied to an authenticated identity. Access decisions depend on who is asking and in what role, not on network location.

Least-privilege access

Available

Role-based permissions grant only the access a task requires. Viewing, editing and approving are separated so no single role holds more than it needs.

Strict access controls

Available

Defined authorisation boundaries protect assets, risks, evidence and policies. Approvals are documented and attributable.

Continuous verification

In development

Session and context checks are intended to re-evaluate access throughout use, rather than trusting a user once at sign-in.

Continuous monitoring

In development

Logged actions already provide a full audit trail. Active monitoring of access patterns and anomalies is being developed on top of it.

Zero Trust for AI operations

Planned

AI agents will be treated as distinct identities with their own scoped permissions, verified on every action and subject to human approval for consequential operations.

Architecture principles

How the platform is built.

Private deployment

In development

PRATIMUS is designed to run inside customer-controlled infrastructure. The intent is that organisational security information remains within an environment the organisation already governs, under its own operational and legal controls.

AI architecture

In development

The architecture is designed around locally deployed models and specialist AI components coordinated by a model-independent orchestration layer, so that individual models can be replaced without rebuilding the platform.

Data sovereignty

In development

The design principle is to minimise unnecessary external data transfers. Where an external service is used, it should be explicitly authorised and consistent with the organisation's data policies.

Access control

Available

Role-based permissions, strong authentication and clearly defined authorisation boundaries govern who can view, change and approve information in the ISMS.

AI execution security

Planned

Autonomous actions are intended to be governed through permission controls, explicitly approved execution scopes and human oversight for consequential operations.

Auditability

Available

Evidence provenance, traceable changes, logged actions and documented approvals allow security decisions to be reconstructed and reviewed after the fact.

Deployment model

Where PRATIMUS runs.

The core platform is designed to operate without a mandatory dependency on external AI APIs. External services form a separate layer that an organisation can choose to enable.

Customer environment

  • Organisational systems and data sources
  • Private PRATIMUS deployment
  • Local AI models

Governance layer

  • Role-based permissions
  • Approved execution scopes
  • Human approval gates
  • Immutable audit trail

Optional external layer

  • External AI providers
  • Threat intelligence feeds
  • Third-party integrations

Enabled only where explicitly authorised by the organisation.

This page describes architectural principles and intended behaviour. It does not describe confidential system architecture, and it does not constitute an absolute security guarantee.

The future of cybersecurity management starts here.

Discover how PRATIMUS can help your organisation implement and operate an intelligent Information Security Management System.