Security & Trust Center
Your AI billing data.
Protected from day one.
PromptKing is operated by PromptKing Inc., an Ontario Business Corporation (Corp. No. 1001622155). We connect to your AI vendor accounts using read-only, least-privilege credentials — we never store your API keys in plaintext, never write to vendor accounts, and never share data across tenants. This page answers the questions your security team will ask.
Legal Entity
PromptKing Inc. · Ontario Business Corporation · Corp. No. 1001622155 · Incorporated May 25, 2026 · Registered address: Ontario, Canada · NAICS 5112 · Contact: info@promptking32.com
Infrastructure Security
Credential Handling — How We Store Vendor API Keys
This is typically the first question from enterprise security teams. Here is exactly how PromptKing handles the credentials you provide to connect your AI vendor accounts.
Read-Only Permission Scopes — Per Vendor
These are the exact permissions PromptKing requests from each vendor, and why.
Application Security
SOC 2 Type II — Roadmap & Current Controls
PromptKing's application-layer SOC 2 Type II audit is in progress. Our infrastructure subprocessors (Vercel, Supabase) are already SOC 2 Type II certified. Here is our milestone timeline.
Subprocessor List
PromptKing uses the following subprocessors. All are contractually bound to equivalent data protection obligations.
Last updated: June 2026. Changes to this list are announced at least 30 days in advance via email to account admins.
Compliance & Standards
Enterprise Procurement
If your security or procurement team has specific requirements, contact us at info@promptking32.com. We can provide the following on request:
- ✓Vercel and Supabase SOC 2 Type II certificates
- ✓Architecture and data-flow diagrams
- ✓Penetration test results (under NDA, available Q3 2026)
- ✓Completed security questionnaires (SIG, CAIQ, VSAQ)
- ✓Data Processing Agreement (DPA) — download at /legal/dpa
- ✓Master Service Agreement (MSA) — contact us for enterprise MSA
- ✓Subprocessor DPAs on request
- ✓Read-only sandbox pilot with non-production or exported billing data
Incident Response & Data Retention
PromptKing maintains a documented incident response plan. The following commitments apply to all customers.
Data Retention & Deletion
Responsible Disclosure
If you discover a security vulnerability, please contact us before public disclosure. We commit to acknowledging all reports within 24 hours and resolving critical findings within 72 hours.
Report a vulnerability →