Security and Trust

Trust and security sit at the core of what Pirros does

We hold your firm’s details, families, and specifications — the work your practice is built on. The bar has to be the same one you hold your other enterprise software to. Here is where we are certified and where we comply, what we commit to, and the answers your IT team asks for most.

  • SOC 2TYPE II
  • GDPRCOMPLIANT
  • CCPACOMPLIANT

Our SOC 2 Type II certification is issued and audited by an outside firm.

Standards and compliance

Verified by outside auditors

Not a list of intentions. Everything in this first group is something an outside auditor, an independent penetration tester, or a named sub-processor stands behind. What we attest ourselves is listed separately below.

  • SOC 2 Type II

    Certified and audited against the same standard your other enterprise vendors are held to, with controls monitored continuously through Drata.

  • Hosted on AWS in the United States

    Serverless, across multiple availability zones. AWS is a named sub-processor on our published list.

  • Authentication managed by Auth0 by Okta

    SAML single sign-on and role-based access control. Pirros never stores or handles your passwords.

  • Encrypted at rest and in transit

    AES-256 at rest, TLS 1.2 or higher in transit, with key management for production encryption keys. Insecure HTTP requests are redirected to HTTPS.

  • Independently penetration tested

    November 2025, against the OWASP Top 10, across the full production application. Zero critical, zero high, and zero medium findings; three low, all addressed.

  • 21 security policies, reviewed annually

    Reviewed under our SOC 2 program, covering access control, encryption, incident response, and business continuity.

  • SOC 2 Type II
  • Drata continuous monitoring
  • AWS United States
  • Auth0 by Okta
  • AES-256 at rest
  • TLS 1.2+ in transit

And what we attest ourselves

These are our own record, our own testing, and our own compliance positions — not an outside body’s findings. We will put any of them in writing for your assessment.

  • No security incident to date
  • 99.9% monthly uptime target, excluding scheduled maintenance
  • Multi-AZ failover, tested
  • GDPR compliant
  • CCPA compliant
What that means for your firm

Four commitments, in plain language

Standards and audits describe how we run. The four below describe what you get, and what we are on the hook for.

  1. Your content stays yours

    Firm data is isolated. No other firm can see, search, or retrieve your details, families, or specifications — and inside your firm, your admins decide who can reach what.

  2. Your data never trains the model

    Nothing your firm puts into Pirros changes the engine another firm uses. Where Mira draws on your content, that context stays in your workspace and is deleted when you leave.

  3. A person always decides

    Mira suggests and flags. It does not issue, stamp, or seal anything, and professional responsibility stays with your licensed staff.

  4. You can leave with everything

    Full export at any time, in native formats, at no cost. On termination we delete your data within 60 days of a written request.

How we handle personal data — what we collect, who we share it with, and the rights you can exercise — is covered in our privacy policy, alongside the full sub-processor list.

Mira and your data

Only what a question needs reaches the AI

Mira partners with you across Pirros, working where your content already sits. Here is exactly what that means, and exactly where the boundaries are.

  • Mira reads your content in place.

    When Mira inspects your firm’s content — details, families, specifications, parameters — it reads it where it already lives in Pirros. Only the specific information needed to answer the question at hand goes to the AI model, and nothing else is sent.

  • Mira can’t reach files you haven’t approved.

    File access is restricted to an approved-folder list. The first time Mira needs a new folder, the user gets an Allow or Deny prompt, and only what they approve is remembered. Anything outside that list is refused.

  • No other firm can see your data.

    Each Mira session is bound to the user who created it and no other user can see it.

  • Pirros does not train AI models on your data.

    We don’t use your conversations or your content as training material.

  • Mira does build context about your firm.

    So it answers the way your firm works rather than the way a generic tool would. That context is scoped to your workspace and visible only to your people.

  • Firm context leaves when you do.

    If you stop working with Pirros, that context is deleted with the rest of your data. The AI model is left exactly as it was.

  • A person approves every output.

    Mira suggests and flags. It does not issue, stamp, or seal anything. Your licensed staff make the call.

Questions reviewers ask

What your IT team will want to know

No. Firm data is isolated. No other firm can see, search, or retrieve your details, families, or specifications, and nothing leaves your firm’s workspace.

No. The Mira model is never trained on your content, and nothing your firm puts into Pirros changes the model any other firm uses.

Yes, and this is worth being precise about. Mira can draw on your firm’s own content so it answers questions the way your firm would. That context is scoped to your workspace, is available only to your people, and never becomes part of the shared model. If you leave Pirros, it is deleted along with the rest of your data.

Only engineering and customer support, and only when the work requires it. Every employee signs an NDA, clears a background check, and completes security training.

Yes. The most recent test was November 2025, run by an independent firm against the OWASP Top 10 across the full production web application. Zero critical, zero high, and zero medium findings, with three low findings addressed.

No. Pirros has not experienced a security incident to date. We maintain a formal incident response plan under our SOC 2 Type II program, led by the CEO, with customer notification as quickly as possible and no later than the law requires.

You export everything first, in native formats, at no cost, and our team walks your people through it before any account closes. We then delete your data within 60 days of a written request, with written certification of deletion on request.

Our sub-processor list is published at pirros.com/privacy/subprocessors, and we provide model provider detail on request as part of a security review.

We share our SOC 2 Type II report with firms evaluating Pirros, under NDA. Get in touch with our security team at privacy@pirros.com and we will walk through what your assessment needs.

Reviewing Pirros for your firm?

Get in touch with our security team and we will work through your assessment with you. Our privacy policy covers how we handle personal data and lists our Data Protection Officer.

privacy@pirros.com

Now see what your firm already knows

You have read how we protect your firm’s content. Next is the part that makes it worth protecting — everything your practice has already solved, ready to reuse.