Skip to main content
Procesario

Security

Control over data, access and every action.

How Procesario is designed to handle enterprise data, identity, governed execution, audit and AI model use. Written for CIOs, security and risk teams — and kept honest: nothing here claims a certification that has not been achieved.

Design commitments

Six areas, stated plainly.

  • Data handling

    • Read broadly, write narrowly: Procesario reads event data from your systems and data platform; it writes back only through typed, permissioned, logged actions.
    • Designed to compute against the customer's data platform where possible rather than duplicating it into another warehouse.
    • Individual identifiers are intended to be pseudonymized by default in analytics; the platform models work, not workers.
  • Identity and access

    • Role-based access with attribute-based data scopes for people.
    • Agents and automations act under their own identities with explicit scopes, like service accounts.
    • Enterprise single sign-on and user provisioning are planned for the productized platform.
  • Governed actions

    • Every action type runs at an explicit autonomy level (A0–A5) with an approval requirement, value and volume limits and a reversibility class.
    • Policies such as approval limits and segregation of duties are machine-checkable rules.
    • A kill switch stops execution globally, per playbook or per executor.
  • Audit and evidence

    • An append-only record of every prediction, recommendation, decision, action and result, linked to its case.
    • Human decisions are logged for accountability of actions, not for evaluation of people; access to per-user decision logs is restricted to audit roles.
    • Export of the record to the customer's own systems is part of the design intent — the record is the customer's data.
  • AI model use

    • Model providers are interchangeable services; bring your own keys.
    • Agent steps receive bounded context and a permitted tool set, and produce a schema-checked output.
    • Cost budgets per playbook and executor are planned; model versions and calibration are tracked.
  • Certifications

    • Procesario does not currently claim SOC 2, ISO 27001 or ISO/IEC 42001 certification. Independent assurance is part of the productization roadmap and will be stated here only when achieved.
    • Security questionnaires can be requested through the contact page.

This page describes design principles and roadmap intent. Contractual security terms are agreed per engagement. For a security review, request a conversation and mention security in your message.

Start a security conversation early.

Tell us which process, which systems and which data classes are involved. We would rather answer the hard questions before a Sprint than during one.