Make Your Agent Catalog Security-Review Ready

Governance Evidence in One Place

Show who owns each agent, who can use it, what systems it touches, and which approvals or reviews are attached.

DLP Where It Matters

Use Pristan's built-in DLP controls where they fit, and connect external DLP, proxy, SIEM, and compliance signals where customers already rely on them.

Clear Runtime Boundaries

Pristan catalogs, governs, and exports evidence. Runtime inspection is represented when integrated with the customer's security path.

DLP

DLP Capabilities, Kept Pragmatic

Built-In Controls

Apply DLP policies to prompts, responses, files, and agent usage with block, warn, mask, and audit actions.

External Signals

Connect findings from DLP, CASB, proxy, SIEM, and API gateway tools when the customer already has those controls in place.

Demand-Led Depth

Keep the core DLP layer focused today, then expand deeper inspection paths when a customer requirement makes it worth doing.

🛡️

Policy Scanning

  • Scan prompts and responses against active DLP policies
  • Support regex, keyword, exact data match, file, and external provider checks
  • Apply allow, warn, mask, redact, or block actions based on policy
  • Record DLP events for audit and investigation workflows
⚡

Provider & File Coverage

  • Connect Google Cloud DLP, AWS Comprehend, Azure AI, or customer-defined providers
  • Scan uploaded documents and extracted text where enabled
  • Detect registered sensitive document leakage with fingerprint matching
  • Use imported findings to guide owner review and access decisions
⚙️

Policy Evidence

  • Track required DLP controls per agent, environment, owner, or group
  • Record exceptions, approvals, review dates, and remediation owners
  • Export evidence for security reviews and compliance checks
  • Escalate deeper enforcement to customer security systems where needed
Identity & Access

Identity & Access Management

Connect supported identity providers, role-based permissions, and administrative access policy to the way your organization operates.

🔐

Single Sign-On (SSO)

  • OAuth 2.0 support (Google, Microsoft, GitHub, custom)
  • SAML 2.0 for enterprise identity providers
  • Just-in-Time (JIT) user provisioning
  • Multi-provider support with priority ordering
  • Session management with configurable timeouts
👥

SCIM & Directory Sync

  • SCIM 2.0: Azure AD, Okta, OneLogin auto-provisioning
  • Directory sync: Azure AD, Google Workspace, LDAP
  • Real-time user lifecycle management
  • Group membership and attribute mapping
🎯

Role-Based Access Control

  • Pre-defined roles: super_admin, admin, user, read_only
  • Custom role creation with granular permissions
  • Permission domains: agents, users, groups, security, evidence, and observability
  • Per-agent access controls for fine-grained governance
  • Group-based permission inheritance
Encryption

Encryption & Data Protection

Pristan separates application-level encryption from hosting-level data protection so customers can choose hosted or self-managed deployment models clearly.

🔒

Pristan-Hosted Data Protection

  • Database and object-storage encryption handled at the hosting infrastructure layer
  • Relevant when customers use Pristan-hosted environments
  • Backup, volume, and storage policies aligned to the selected cloud or managed database provider
  • Self-hosted customers can apply their own cloud, Kubernetes, disk, and database encryption controls
🌐

Encryption in Transit

  • HTTPS/TLS for browser, API, and mobile traffic in production deployments
  • Secure WebSocket transport when real-time chat runs behind HTTPS
  • HTTP-only secure cookies and origin checks for browser sessions
  • Customer-managed deployments can keep internal services on private network paths
  • Database or Redis TLS can be added where the customer or hosting provider requires it
🔑

Application-Level Encryption

  • Encrypt integration credentials, provider keys, and stored secrets with configurable keys
  • Support key rotation for encrypted secrets
  • Optional customer-managed encryption keys for sensitive message and knowledge content
  • AWS KMS, Azure Key Vault, GCP Cloud KMS, and HashiCorp Vault adapters are available for CMEK paths
🌍

Compliance Exports

  • Export agent inventory, owner, access, risk, and review data
  • Provide evidence for GDPR, SOC 2, ISO 42001, EU AI Act, and NIST AI RMF reviews
  • Show gaps in catalog metadata and control coverage
  • Support compliance teams without replacing their GRC platform
GDPR Evidence Support
SOC 2 Evidence Export
EU AI Act Inventory Support
ISO 42001 Mapping Support
Infrastructure

Deployment and Platform Security Boundaries

Pristan provides application controls and Docker-based deployment building blocks. The customer or managed-service design still owns the surrounding network, storage, availability, and infrastructure controls.

Customer-Managed Deployment

  • Docker images and Compose-based deployment paths
  • Customer-selected cloud, datacenter, region, and storage services
  • Network and offline requirements confirmed during solution design
  • Customer-owned TLS termination, firewall, and service topology

Identity and API Boundaries

  • Browser sessions, CSRF and origin validation, and configurable session policy
  • Scoped API keys for approved service access
  • Role and permission checks on administrative APIs
  • Token and key revocation workflows

Rate and Abuse Controls

  • Rate limiting on sensitive and high-volume paths
  • Authentication lockout and brute-force protections
  • Request-size and input validation boundaries
  • Deployment-level edge protection remains environment-owned

Secrets and Connector Credentials

  • Encrypted storage for provider, integration, and per-user connector secrets
  • Managed-secret references and controlled reveal behavior
  • Key rotation and invalidation workflows where supported
  • Optional customer-managed encryption paths for sensitive content

Validation and Recovery

  • Platform health checks for schema, migrations, extensions, indexes, and enums
  • Configuration backup and restore workflows
  • Deployment validation and operational event history
  • Recovery responsibilities matched to the chosen deployment model

External Security and Telemetry

  • Webhooks and ITSM connections for operational workflows
  • OpenTelemetry and Prometheus-compatible telemetry paths
  • Audit, security, and compliance exports for downstream review
  • Customer-selected SIEM, GRC, APM, and network controls stay authoritative
Authentication

MFA & Conditional Access

Multi-layered authentication with adaptive access policies.

TOTP Two-Factor Auth

Time-based one-time passwords with any authenticator app. Backup codes for recovery. Enforce per group or platform-wide.

Conditional Access Policies

IP range restrictions, SSO-only login enforcement, group-based rules. Multiple policies evaluated in order with deny-by-default fallback.

Policy-Based Enforcement

Combine MFA, SSO-only login, IP ranges, group rules, and time-limited access according to the policies configured for each population.

Prompt Security

Prompt-Injection Detection and Evidence

Apply the platform's configured prompt-injection checks in Pristan-controlled chat paths and import external runtime findings when another gateway remains authoritative.

Configured Runtime Checks

Run enabled detectors before or after provider invocation and apply the configured allow, warn, or block behavior.

Per-Agent Policy

Review prompt templates, tools, data access, detector settings, exceptions, and owner decisions before wider access.

Evidence and Observability

Record detections and policy outcomes for dashboards, audit trails, false-positive review, and security follow-up.

Compliance

Compliance Evidence Mapping

Map agent catalog evidence to frameworks so compliance teams can see what exists, what is missing, and what needs owner review.

Framework Coverage

Map catalog fields and review evidence to ISO 42001, EU AI Act, SOC 2, GDPR, and NIST AI RMF control areas.

Gap Visibility

Show missing owners, missing approvals, incomplete access rules, and absent DLP or security evidence per agent.

Exportable Reports

Export control-to-evidence mappings for teams to review in their existing audit, compliance, and GRC workflows.

Bring AI Agent Evidence to the Security Review

Agent Inventory

Show which agents are available, who owns them, who can use them, and what business purpose they serve.

Control Coverage

Review identity, access, DLP, prompt-injection, approval, encryption, retention, and exception evidence.

Exportable Evidence

Move agent, access, risk, audit, and framework-mapping evidence into the customer's existing review process.

Plan a Security Review