Security & governance

Built for the people who answer to regulators

Compliance tooling has to be defensible. ARGOS is engineered so you can show your data is protected, your sources are clean, and every decision is on the record.

Independently certified

Prymera Consulting Private Limited holds ISO/IEC 27001:2022 (Information Security) and ISO 9001:2015 (Quality Management), certified by KVQA Certification Services Pvt. Ltd..

View the Trust centre →

Your data stays yours

  • Compliance queries go direct to the model provider — no aggregator or proxy in the data path — with an automatic fallback to a secondary provider only if the primary is unavailable (see Sub-processors).
  • No client data is used to train models.
  • Per-tenant isolation: every case, watchlist, audit row and session is scoped to your firm.

Tamper-evident audit trail

  • Every query, source, screening verdict and case action is hash-chained with SHA-256.
  • Any later edit breaks the chain — integrity is verifiable on demand.
  • Reviewable in-app today; self-service export is on our roadmap.

Authentication & access

  • Invite-only, multi-tenant access with admin / viewer / super-admin roles.
  • Passwords hashed with PBKDF2-SHA256; short-lived access tokens with silent refresh.
  • Token revocation & single-use refresh rotation; persistent login lockout.

Commercial-safe sourcing

  • Only licence-clean official sources enter the corpus and the screening lists.
  • A commercial-safe gate blocks any source that cannot be used in a paid product.
  • The Source Lists page shows the licence and status of every list, transparently.

Hardened by default

  • Content-Security-Policy and the full security-header set, HSTS in production.
  • Per-IP and per-route rate limiting; prompt-injection scanning on inputs.
  • Production API docs disabled; secrets kept in the deploy environment only.

Deployment options

  • Cloud-native SaaS on managed infrastructure.
  • Designed to support an air-gapped / self-hosted deployment for the most sensitive environments.
  • Runtime model registry means provider choice can change without a code change.

Need the security detail for procurement?

We're happy to walk your security and compliance teams through the architecture, data flows and governance.