PuReAIpureAi
Free scan

Security and trust

What we collect, and what we never touch

This page states how the platform handles data. It describes the product as it is built, and it does not claim certifications or audit outcomes that have not been issued.

The facts

Collection is outside-in only

PuReAI collects publicly reachable data about domains you nominate. No agents are installed, and no access to your internal systems or credentials is requested.

Deployment is your choice

EU-hosted SaaS, your own cloud tenancy, or fully on-premise with an air-gapped option. In self-hosted models the data never leaves your environment.

Access control

Role-based access inside the tenant. In private cloud and on-premise deployments, authentication runs through your identity provider and your access policy.

Evidence retention

Findings are stored with the observation and the date that produced them, so a result can be reproduced and reviewed later.

Reporting a vulnerability

If you believe you have found a security issue in the platform or this website, contact us and describe it. We will confirm receipt and keep you informed of the outcome.

Methodology is public

The scoring methodology, including what each module collects, is published on this site so a reviewer can read it without an NDA.

What this page does not claim

No certification, audit report or regulatory approval is asserted here. Where a procurement process needs formal assurance documentation, ask for it directly through contact and you will get what actually exists, not a badge.

For residency and sovereignty questions, the deployment models page sets out where data resides in each option, and the accessibility statement covers this website.

Bring your security review