Security

Agents get access. You keep control.

Prinvia is built so that opening your business to agents never means losing the guardrails. Authorization is explicit, access is scoped, and everything is auditable.

Least privilege by default

Agents can only do what your policy file allows. Everything else is refused and logged. There is no implicit access.

Provable authorization

Every purchase carries a signed AP2-style mandate tying it to explicit user intent. Orders without a valid mandate never settle.

Data minimization

We store the order metadata needed to run and audit transactions, and nothing more. We do not sell or share your data.

Encrypted end to end

TLS in transit and encryption at rest. Secrets live in a managed store, never in code or logs.

Payment isolation

Card data flows through your existing PCI-compliant processor. Prinvia never stores raw card numbers.

Full auditability

Every request is traceable from the originating query to the settled payment, exportable to your systems.

Compliance

Where we are.

  • SOC 2 Type II: audit in progress
  • GDPR and CCPA aligned data practices
  • PCI handled by your payment processor, not stored by us
  • Data processing agreement available for design partners

Responsible disclosure

Found something?

We welcome reports from security researchers. Email us with details and steps to reproduce, and we will acknowledge within two business days. Please give us reasonable time to fix before disclosing.

security@prinvia.com

Get a demo

The next customer walking into your store is an agent.

Be ready before your competitors are. Design partners ship in weeks, not quarters.