How Phronimos handles reliability, security, and your data.
The pillars we hold ourselves to. Each links to the page or document that explains the details.
Reliability
Detection targets, escalation, response times, and automatic SLA credits for managed workflows. Published as real commitments with real numbers, not as adjectives.
Security posture
Per-customer isolation, credential handling through a broker (never in committed files or LLM prompts), agent runtime in dedicated cloud computers per customer where required, and a documented incident-response process.
Detailed security summary (SOC 2 posture, penetration test cadence, third-party audits): available under NDA.
Data handling
Customer data stays in customer-owned tools by default. Data pulled into Phronimos's runtime is scoped to the workflow, retained only as long as needed for that workflow, and never used to train models. Data-processing addenda available on request.
Data Processing Addendum (DPA): available on request.
Governance
Written AI program, validation testing per workflow, record retention on runs and decisions, third-party vendor diligence with audit rights where the customer requires it. Modeled on ISO 42001 shape without the certification cost — appropriate for SMB scale.
Detailed governance framework: ISO-42001-shaped governance at SMB scale.
Incident response
Every Critical or High incident on a managed workflow ships a written report within 24 hours of resolution, in the same format as the redacted sample. Clients receive plain-English notifications during the incident, not after.
Missing something? Email hello@phronimos.io. We'd rather add it than have you guess.