Security & data handling
How we handle your pack.
Prospero Tools (Brief and Minutes) is built for regulated environments. The points below summarise the controls relevant to a compliance officer or MLRO reviewing the tools for director or company-secretarial use.
Workspace isolation
Each corporate workspace is a separate tenant. All director, pack, briefing and audit records are tagged with the workspace ID and protected by database-level row security policies. A user in one workspace cannot read, list or modify data belonging to another workspace, even by guessing IDs. Storage objects are scoped to the workspace and only retrievable via short-lived, signed URLs.
60-minute deletion
Uploaded packs, audio recordings, extracted text, generated briefings, minutes drafts and transcripts are deleted from our servers within 60 minutes of generation by default. Corporate workspace administrators may configure a longer retention window for their workspace, in which case that window applies. Original filenames are cleared at the same time so nothing pack-derived remains past the applicable window. Runs that fail are purged more aggressively — within 15 minutes of the failure. After deletion we retain only a tamper-evident audit hash (SHA-256), the file size in bytes, the model identifier used, and the workspace and user ID — never the document content, transcript, briefing or minutes text.
Support access to live records
A named super-admin may open a live record inside the 60-minute processing window to help resolve a support issue. Opening a record shows shell metadata only (status, timestamps, model, error present). Revealing pack-derived content requires fresh multi-factor verification and a written reason; both the open and the reveal are written to the workspace's audit log. Expired records contain no pack-derived content.
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest. Storage objects are encrypted server-side by the underlying object store. Database backups are encrypted at rest.
No training on customer content
Customer packs, briefings, prompts and generated outputs are never used by us to train, fine-tune or evaluate any model. All LLM inference for Brief and Minutes runs on Google Vertex AI under the Google Cloud Data Processing Addendum (DPA), which prohibits retention and training on customer data. Audio transcription for Minutes is handled by Speechmatics under the terms described on our sub-processors page; transcription jobs are deleted via API on completion.
PII redaction before AI processing
For Brief, and for Minutes' narrative drafting, fact-mining and template-conversion steps, an in-house redactor on our server replaces personal data with opaque tokens such as {{person_1}} before the model is called. Names known to the system — your profile display name, other members of your workspace, recorded meeting attendees and directors/officers captured against your entities — plus detected name patterns are tokenised, alongside all detected email addresses, phone numbers, IBANs and UK National Insurance numbers. The reverse map never leaves our server and is used to restore the original values into the model's output. Minutes' initial board-pack fact-extraction step is the one exception: to preserve the fidelity of scanned pages, images, charts and financial tables, the raw PDF is sent to Google Vertex AI in the EU under the existing Google Cloud DPA (no training, no retention), and no other processor sees it.
EU / UK data residency
Application, database, file storage and audit logs run in a single EU/UK cloud region. All AI inference for Brief and for Minutes — including board-pack fact extraction (multimodal PDF), narrative drafting, fact-mining and template conversion — is routed through Google Vertex AI in the EU under the Google Cloud DPA. There is no fallback to a non-EU provider for LLM work. Audio transcription for Minutes runs on Speechmatics, a UK-headquartered provider, in its EU region, and is noted in the UI before use — see the sub-processors page. Email relay runs on Mailgun's EU region.
Audit log
Every upload, briefing generation, public-domain scan, delivery, deletion and deletion-verification event is recorded with timestamp, user, event type, content SHA-256 and model identifier. Workspace admins can review their workspace's log; individual directors can review their own.
Authentication
Individual directors sign in with email and password, Google, or Apple. Corporate workspaces sign in via SAML single sign-on against their own identity provider (Okta, Entra ID, OneLogin and similar). Password reuse against known-breached passwords is blocked. New accounts are gated by manual admin approval during the beta.
Hosting & jurisdiction
Prospero Advisory Limited is incorporated in Jersey, Channel Islands (company number 166208). Application, database, storage and LLM inference all run in EU/UK cloud regions. See the sub-processors page for the full list.
This page summarises operational controls in plain English. It is not a contract. Corporate workspaces receive a written processor agreement before go-live.