Identity-based security
AvailableEvery request is tied to an authenticated identity. Access decisions depend on who is asking and in what role, not on network location.
Security & Deployment
PRATIMUS is built on the assumption that security information is among the most sensitive data an organisation holds. Its architecture follows Zero Trust principles: never trust, always verify.
Zero Trust Architecture
No user, device, service or AI component is trusted by default. Each access request is verified against identity, role and context, and granted only to the extent required. These principles protect organisational assets, sensitive information and AI-driven operations alike.
Every request is tied to an authenticated identity. Access decisions depend on who is asking and in what role, not on network location.
Role-based permissions grant only the access a task requires. Viewing, editing and approving are separated so no single role holds more than it needs.
Defined authorisation boundaries protect assets, risks, evidence and policies. Approvals are documented and attributable.
Session and context checks are intended to re-evaluate access throughout use, rather than trusting a user once at sign-in.
Logged actions already provide a full audit trail. Active monitoring of access patterns and anomalies is being developed on top of it.
AI agents will be treated as distinct identities with their own scoped permissions, verified on every action and subject to human approval for consequential operations.
Architecture principles
PRATIMUS is designed to run inside customer-controlled infrastructure. The intent is that organisational security information remains within an environment the organisation already governs, under its own operational and legal controls.
The architecture is designed around locally deployed models and specialist AI components coordinated by a model-independent orchestration layer, so that individual models can be replaced without rebuilding the platform.
The design principle is to minimise unnecessary external data transfers. Where an external service is used, it should be explicitly authorised and consistent with the organisation's data policies.
Role-based permissions, strong authentication and clearly defined authorisation boundaries govern who can view, change and approve information in the ISMS.
Autonomous actions are intended to be governed through permission controls, explicitly approved execution scopes and human oversight for consequential operations.
Evidence provenance, traceable changes, logged actions and documented approvals allow security decisions to be reconstructed and reviewed after the fact.
Deployment model
The core platform is designed to operate without a mandatory dependency on external AI APIs. External services form a separate layer that an organisation can choose to enable.
Customer environment
Governance layer
Optional external layer
Enabled only where explicitly authorised by the organisation.
This page describes architectural principles and intended behaviour. It does not describe confidential system architecture, and it does not constitute an absolute security guarantee.
Discover how PRATIMUS can help your organisation implement and operate an intelligent Information Security Management System.