Last updated: November 30, 2025
Security is a core part of PromptMan.dev.
We operate as prompt infrastructure for production AI systems, and we take the protection of your data and workloads seriously.
This page summarizes our current security practices.
PromptMan.dev is hosted on Amazon Web Services (AWS) in the European Union (eu-central-1, Frankfurt).
All data remains within the EU unless explicitly configured otherwise.
Each workspace's data is logically isolated.
Runtime API keys are scoped at the workspace level.
We plan to support additional EU-only hosting environments (e.g., Hetzner, Ionos) for organizations requiring strict digital sovereignty.
We do not store:
Runtime usage logs contain only the metadata required for billing, debugging, and system stability.
A tenant's API key can never access:
This is enforced at the database and application levels.
All sensitive configuration is stored encrypted using AWS Secrets Manager or environment injection during deploy
No secrets are stored in source code
We log only what is necessary for:
We do not log prompt contents fetched by your app.
We follow a standard incident response process:
If an incident impacts your workspace, we will notify you promptly via email.
If you discover a vulnerability, please report it responsibly.
Security contact: security@promptman.dev
We will acknowledge and investigate all legitimate reports.
Do not test vulnerabilities on other customers' data or attempt to access other workspaces.
While PromptMan.dev is not yet formally certified under frameworks (e.g., ISO 27001, SOC2), our architecture and operational approach follow common best practices.
We are committed to supporting:
A formal DPA (Data Processing Agreement) is available upon request.
PromptMan.dev does not send your prompts or any runtime content to third-party AI providers.
Your application interacts with LLMs directly.
PromptMan.dev exists as an infrastructure layer between your code and your prompts.
We do not:
For security questions, disclosures, or requests:
Email: security@promptman.dev