---
title: Enterprise Security and Compliance for AI Prompt Workflows
canonical_url: https://prompeteer.ai/enterprise-security-compliance
markdown_url: https://prompeteer.ai/enterprise-security-compliance.md
content_type: seo-article
category: Enterprise security
page_type: enterprise
primary_keyword: enterprise AI prompt security compliance
author: Ashley Ganz
author_same_as: https://www.linkedin.com/in/ashleyganz
date_published: 2026-06-29T00:00:00-07:00
date_modified: 2026-09-11T00:00:00-07:00
last_updated: 2026-09-11
last_updated_iso: 2026-09-11T00:00:00-07:00
content_usage: search=yes, ai-input=yes, ai-train=yes
---

# Enterprise security and data handling

Review identity, permissions, data handling and service commitments before bringing AI into a business workflow. See what the public documentation establishes and what needs a contract review.

Published by [Prompeteer](https://prompeteer.ai/about). Original byline: [Ashley Ganz](https://www.linkedin.com/in/ashleyganz). Updated Sep 11, 2026.

## Evaluate the controls your workflow needs

Public information reviewed 2026-09-11. This page identifies implemented product boundaries and questions for procurement. It is not a penetration-test report or an assurance opinion.

Start with the data you intend to use, the people who can access it, the providers that will process it and the retention you require. Confirm requirements with Prompeteer before adopting a workflow for sensitive or regulated data.

## Security controls and evidence

Availability depends on the feature and agreed plan. The responsible team and a public reference accompany each entry; a reference describes the scope and does not establish an independent audit.

| Control | Status | Scope and limitations | Review owner | Public reference |
| --- | --- | --- | --- | --- |
| Identity and SSO | Account sign-in; MCP OAuth | OAuth consent controls connected access. Organization SSO requirements need an agreed scope; this page does not certify SSO coverage. | Platform | /connect |
| Permissions | Authenticated operations | Private prompts, Memory and reports require authorization. An OAuth grant does not make private content publicly discoverable. | Platform | /connect |
| Tenant data | Public and private surfaces are separate | Published skill metadata and product pages are public. Evaluate the requested workspace roles and sharing boundaries before importing sensitive material. | Product | /privacy |
| Subprocessors | Feature-dependent processing | Configured AI providers process context needed for a requested operation. Confirm the current provider list, region and contractual terms for your workflow. | Privacy | /privacy |
| Retention | Saved and transient data have different lifecycles | Memory sources and saved prompts persist for reuse until deletion. Transient context, provider records, security logs and backups have separate retention rules. | Privacy | /privacy |
| Deletion | User and account deletion paths | Review deletion scope and exceptions in the Privacy Policy. Do not assume an immediate purge of backups or provider-side records. | Privacy | /privacy |
| Auditability | Inspectable outputs and scan evidence | Review generated instructions, skill provenance and available scan results. Customer-exportable organization audit logs require a separate scope review. | Product | /skill-security-scanner |
| Certification and compliance | Contract review required | A scan, Prompt Score or product description is not a certification. Ask for any independent assurance, DPA or regulatory terms required by your organization before approval. | Privacy and commercial | /enterprise |
| Support and service levels | Contract review required | Self-serve features and account quotas are described in pricing. Response times, uptime commitments and enterprise support terms must be confirmed in an agreement. | Commercial | /pricing |

## Bring these questions to a procurement review

Use synthetic or redacted material during evaluation. Request written answers for requirements that are not established by the public documentation.

- Which identity provider, roles and sharing boundaries are required?
- Which source systems and classes of data will the workflow process?
- Which processing regions, providers, retention periods and deletion exceptions are acceptable?
- Do you require a DPA, independent assurance evidence, audit-log exports or contractual service levels?

## Review the product before sharing production data

Inspect a generated prompt and its source context, read a skill before installing it, and approve only the tool permissions the task needs. Automated screening can miss threats. Prompt-quality feedback does not verify every fact in an answer.

- [Data handling and deletion](https://prompeteer.ai/privacy)
- [Connected access and OAuth](https://prompeteer.ai/connect)
- [Skill screening evidence](https://prompeteer.ai/skill-security-scanner)
- [Discuss enterprise requirements](https://prompeteer.ai/enterprise)

## FAQs

### Does Prompt Score certify security or factual accuracy?

No. Prompt Score is automated quality feedback. Skill screening is an aid to review. Neither is a certification or a guarantee of safe execution or factual accuracy.

### Where are data handling and deletion described?

The Privacy Policy describes data handling and deletion. Confirm provider, backup, security-log and contractual retention requirements for your intended workflow.

## Links

- Prompeteer homepage: https://prompeteer.ai/
- Pricing: https://prompeteer.ai/pricing
- Enterprise: https://prompeteer.ai/enterprise
- Agent content index: https://prompeteer.ai/.well-known/agent-content/index.json
