PrimenAI logoPrimenAI
Enterprise · Security & data

Data privacy and security, stated precisely.

This page describes how PrimenAI approaches data privacy, access control, and security in AI engagements. It is not a security certification page, and it does not claim controls PrimenAI has not verified.

Current practices

What PrimenAI can state today.

Philippine Data Privacy Act (RA 10173)

Engagements are run in line with the Philippine Data Privacy Act, with data handling, access, and retention terms documented per project.

Documented data handling per engagement

The data an engagement touches, where it is processed, who can access it, and how long it is retained are defined in the applicable proposal or statement of work.

Access control and least privilege

Access to client systems and data is limited to the people performing the work, for the duration of the work, using the client's own identity and access mechanisms where available.

Human oversight designed into AI systems

Escalation paths, review points, and restricted-topic handling are part of solution design rather than post-deployment additions.

Auditability and traceability

AI systems we build are designed so that inputs, retrieved sources, and returned outputs can be traced, subject to the logging and retention terms agreed with the client.

Version-controlled source and named delivery leads

Work is version-controlled with documented handover, so delivery continues without single-person dependency.

Detailed technical architecture, data handling, access controls, hosting model, and security responsibilities are defined during solution design and confirmed during enterprise evaluation. Where a specific control is not documented above, it is because it is engagement-specific — not because it is assumed.

What we do not claim

No certification or compliance claims are made on this site.

PrimenAI does not hold, and does not claim to hold, SOC 2 attestation, ISO 27001 certification, ISO/IEC 42001 certification, HIPAA compliance, PCI certification, or any other security or compliance certification or audit. PrimenAI does not claim certifications, accreditations, or insurance that have not been formally obtained.

External standards referenced as frameworks only

NIST AI Risk Management Framework (AI RMF 1.0)
Referenced as a risk-management vocabulary when structuring AI governance discussions.
OECD AI Principles
Referenced as responsible-AI principles informing our approach.
ISO/IEC 42001 — AI management systems
Referenced as a structural guide for AI management practices.

Referencing a framework is not a claim of certification, conformance, or audit against it.

Formal evaluation

Available during vendor evaluation rather than published publicly.

The following may be provided, as applicable, during a formal evaluation or procurement process, subject to authorization and confidentiality requirements.

  • Corporate registration documentation
  • Tax and corporate information
  • Security questionnaire responses against your standard vendor template
  • Detailed data-processing information for the proposed solution
  • Contractual documentation
  • Commercial proposal
  • Statement of work
  • References, subject to availability and permissions

References may be provided when verified references are available and appropriate permissions have been obtained. PrimenAI's public privacy commitments are set out in the privacy policy.

Start the conversation

Let's identify where AI can create the greatest value in your organization.

Have an AI opportunity or operational challenge in mind? Book a 30-minute introductory conversation — no preparation required and no obligation to proceed. Already have a defined project or requirement? Send a detailed inquiry instead.

Speak with PrimenAI about your objectives, operational challenges, and transformation priorities. We will help you identify a practical and responsible path forward.