Evaluate the controls your workflow needs
Public information reviewed 2026-09-11. This page identifies implemented product boundaries and questions for procurement. It is not a penetration-test report or an assurance opinion.
Start with the data you intend to use, the people who can access it, the providers that will process it and the retention you require. Confirm requirements with Prompeteer before adopting a workflow for sensitive or regulated data.
Security controls and evidence
Availability depends on the feature and agreed plan. The responsible team and a public reference accompany each entry; a reference describes the scope and does not establish an independent audit.
Scroll the table to review all 5 columns.
| Control | Status | Scope and limitations | Review owner | Public reference |
|---|---|---|---|---|
| Identity and SSO | Account sign-in; MCP OAuth | OAuth consent controls connected access. Organization SSO requirements need an agreed scope; this page does not certify SSO coverage. | Platform | /connect |
| Permissions | Authenticated operations | Private prompts, Memory and reports require authorization. An OAuth grant does not make private content publicly discoverable. | Platform | /connect |
| Tenant data | Public and private surfaces are separate | Published skill metadata and product pages are public. Evaluate the requested workspace roles and sharing boundaries before importing sensitive material. | Product | /privacy |
| Subprocessors | Feature-dependent processing | Configured AI providers process context needed for a requested operation. Confirm the current provider list, region and contractual terms for your workflow. | Privacy | /privacy |
| Retention | Saved and transient data have different lifecycles | Memory sources and saved prompts persist for reuse until deletion. Transient context, provider records, security logs and backups have separate retention rules. | Privacy | /privacy |
| Deletion | User and account deletion paths | Review deletion scope and exceptions in the Privacy Policy. Do not assume an immediate purge of backups or provider-side records. | Privacy | /privacy |
| Auditability | Inspectable outputs and scan evidence | Review generated instructions, skill provenance and available scan results. Customer-exportable organization audit logs require a separate scope review. | Product | /skill-security-scanner |
| Certification and compliance | Contract review required | A scan, Prompt Score or product description is not a certification. Ask for any independent assurance, DPA or regulatory terms required by your organization before approval. | Privacy and commercial | /enterprise |
| Support and service levels | Contract review required | Self-serve features and account quotas are described in pricing. Response times, uptime commitments and enterprise support terms must be confirmed in an agreement. | Commercial | /pricing |
Bring these questions to a procurement review
Use synthetic or redacted material during evaluation. Request written answers for requirements that are not established by the public documentation.
- Which identity provider, roles and sharing boundaries are required?
- Which source systems and classes of data will the workflow process?
- Which processing regions, providers, retention periods and deletion exceptions are acceptable?
- Do you require a DPA, independent assurance evidence, audit-log exports or contractual service levels?
Review the product before sharing production data
Inspect a generated prompt and its source context, read a skill before installing it, and approve only the tool permissions the task needs. Automated screening can miss threats. Prompt-quality feedback does not verify every fact in an answer.