Skip to main content
This page collects the trust resources for the Prem API platform: certifications, planned audits, and the security properties that you can verify yourself.

Certifications

  • SOC 2 Type I: An independent auditor issued a SOC 2 Type I report for Prem. The report is available on request. Contact us at support@premai.io.

Independent verification

Prem API does not ask you to trust a report alone. The core security properties are verifiable:

Attestation

Hardware-signed proof of the code and the hardware that process your data. Verify it with the SDK or with the open reticle library.

Encryption

End-to-end encryption with post-quantum algorithms. You hold the keys.

Data Retention

Zero retention of inference content, and the metadata list that we do keep.

Security Model

The full threat model, the trust boundaries, and the limitations.
The verification tools are open:
  • TypeScript SDK: premAI-io/api-sdk-ts
  • Attestation library: @premai/reticle on npm, for browser and Node.js use, with Rust crates for independent verification. See Attestation.

Planned audits

An independent audit of the platform is planned. We track it on the Platform Status page and we will publish the results when the audit completes.

Resources

  • Whitepaper: Prem Enclave Whitepaper (PDF). The technical design of the enclave platform.
  • Status page: status.premai.io. Live platform availability.
  • Infrastructure locations: Owned hardware in Switzerland and rented hardware in Europe and the United States, all with identical TEE guarantees. See the Security Model.
Enterprise requirements, agreements, or security questionnaires? Contact us at support@premai.io.