Certifications
- SOC 2 Type I: An independent auditor issued a SOC 2 Type I report for Prem. The report is available on request. Contact us at support@premai.io.
Independent verification
Prem API does not ask you to trust a report alone. The core security properties are verifiable:Attestation
Hardware-signed proof of the code and the hardware that process your data. Verify it with the SDK or with the open reticle library.
Encryption
End-to-end encryption with post-quantum algorithms. You hold the keys.
Data Retention
Zero retention of inference content, and the metadata list that we do keep.
Security Model
The full threat model, the trust boundaries, and the limitations.
- TypeScript SDK: premAI-io/api-sdk-ts
- Attestation library:
@premai/reticleon npm, for browser and Node.js use, with Rust crates for independent verification. See Attestation.
Planned audits
An independent audit of the platform is planned. We track it on the Platform Status page and we will publish the results when the audit completes.Resources
- Whitepaper: Prem Enclave Whitepaper (PDF). The technical design of the enclave platform.
- Status page: status.premai.io. Live platform availability.
- Infrastructure locations: Owned hardware in Switzerland and rented hardware in Europe and the United States, all with identical TEE guarantees. See the Security Model.
Enterprise requirements, agreements, or security questionnaires? Contact us at support@premai.io.

