Data privacy and security, stated precisely.
This page describes how PrimenAI approaches data privacy, access control, and security in AI engagements. It is not a security certification page, and it does not claim controls PrimenAI has not verified.
What PrimenAI can state today.
Philippine Data Privacy Act (RA 10173)
Engagements are run in line with the Philippine Data Privacy Act, with data handling, access, and retention terms documented per project.
Documented data handling per engagement
The data an engagement touches, where it is processed, who can access it, and how long it is retained are defined in the applicable proposal or statement of work.
Access control and least privilege
Access to client systems and data is limited to the people performing the work, for the duration of the work, using the client's own identity and access mechanisms where available.
Human oversight designed into AI systems
Escalation paths, review points, and restricted-topic handling are part of solution design rather than post-deployment additions.
Auditability and traceability
AI systems we build are designed so that inputs, retrieved sources, and returned outputs can be traced, subject to the logging and retention terms agreed with the client.
Version-controlled source and named delivery leads
Work is version-controlled with documented handover, so delivery continues without single-person dependency.
Detailed technical architecture, data handling, access controls, hosting model, and security responsibilities are defined during solution design and confirmed during enterprise evaluation. Where a specific control is not documented above, it is because it is engagement-specific — not because it is assumed.
No certification or compliance claims are made on this site.
PrimenAI does not hold, and does not claim to hold, SOC 2 attestation, ISO 27001 certification, ISO/IEC 42001 certification, HIPAA compliance, PCI certification, or any other security or compliance certification or audit. PrimenAI does not claim certifications, accreditations, or insurance that have not been formally obtained.
External standards referenced as frameworks only
- NIST AI Risk Management Framework (AI RMF 1.0)
- Referenced as a risk-management vocabulary when structuring AI governance discussions.
- OECD AI Principles
- Referenced as responsible-AI principles informing our approach.
- ISO/IEC 42001 — AI management systems
- Referenced as a structural guide for AI management practices.
Referencing a framework is not a claim of certification, conformance, or audit against it.
Available during vendor evaluation rather than published publicly.
The following may be provided, as applicable, during a formal evaluation or procurement process, subject to authorization and confidentiality requirements.
- Corporate registration documentation
- Tax and corporate information
- Security questionnaire responses against your standard vendor template
- Detailed data-processing information for the proposed solution
- Contractual documentation
- Commercial proposal
- Statement of work
- References, subject to availability and permissions
References may be provided when verified references are available and appropriate permissions have been obtained. PrimenAI's public privacy commitments are set out in the privacy policy.
Let's identify where AI can create the greatest value in your organization.
Have an AI opportunity or operational challenge in mind? Book a 30-minute introductory conversation — no preparation required and no obligation to proceed. Already have a defined project or requirement? Send a detailed inquiry instead.
Speak with PrimenAI about your objectives, operational challenges, and transformation priorities. We will help you identify a practical and responsible path forward.
