Skip to main content
Prophecy is SOC 2 compliant and safeguards data at every level across the product stack. Whether you use our multi-tenant SaaS platform or a Dedicated SaaS deployment, Prophecy is designed to meet the rigorous security requirements that are standard for enterprises.
Read more details on Prophecy’s security and compliance posture at our Security Portal.

Framework

The following is the framework we employ to ensure security with Prophecy.

Product

Prophecy incorporates robust product security features to safeguard user access, data integrity, and compliance.
  • Authentication. Authentication methods, including Single Sign-On (SSO) and Multi-Factor Authentication (MFA), ensure only authorized individuals can access the platform.
  • Authorization. Role-Based Access Control (RBAC) enforces a “least privilege” model, granting users only the permissions they need.
  • Auditing. Detailed auditing capabilities log all user and admin activities for complete transparency and accountability.
  • Data protection. Data is protected through encryption at rest and in motion, with compliant key management practices to safeguard sensitive information. While Prophecy code is stored in Git repositories, your data is not.

AI and LLMs

Prophecy takes a thoughtful approach to AI Large Language Model (LLM) security. Prophecy ensures that AI functionality remains transparent, secure, and trustworthy.
  • While AI is used to make suggestions, it is never used to directly transform data or make business decisions.
  • Prophecy does not store or send your data to any third-party large language model (LLM) providers. Instead, Prophecy uses rich metadata to construct its knowledge graph. As a result, Prophecy can interface with LLM providers while keeping your data private.
  • Prophecy Data Transformation Copilot is classified as a “minimal risk” AI application, in accordance with the EU Artificial Intelligence Act.
Using an LLM with Prophecy is optional.

Deployments

Here’s the full range of deployment options:
  • SaaS. Our highly secure and scalable default offering that employs multi-tenant architecture with multiple layers of logical isolation. Runs on Prophecy’s AWS VPC.
  • Dedicated SaaS. A single-tenant deployment option for organizations that prefer more isolated infrastructure deployed on a dedicated Prophecy AWS or Azure VPC.
With these flexible options, Prophecy ensures every organization can adopt the deployment model that best suits their security and operational requirements.

Operations

Operational security is a key pillar of Prophecy’s approach. The platform is built on hardened infrastructure designed to withstand external threats. Regular penetration testing ensures that vulnerabilities are identified and addressed promptly, while continuous vulnerability scanning and management further strengthen defenses. These practices ensure that Prophecy remains secure, reliable, and resilient against emerging threats.

Network configuration

If you or your organization uses a firewall, VPN, or proxy, Prophecy might not work as expected. Review the following table to help you troubleshoot any issues.